Domain Health Audit: DNS, WHOIS, SSL, SPF, DKIM & DMARC
Audit a whole portfolio of domains and get back the exact DNS records to publish to fix every problem found.
In plain language.
Point it at a list of domains — one, or five thousand — and it reads everything those domains publish about themselves: DNS records, who they are registered to and when that lapses, the website certificate, how the site handles insecure connections, and the whole email-authentication stack.
Each domain comes back with a score out of 100, a letter grade, and a verdict on whether it meets what the big mailbox providers now require from bulk senders. The grade is not a black box: the full scoring rubric is published, and it is returned with every run, so you can show a client exactly why a domain scored what it scored.
Every problem arrives with the fix attached — the record type, the name, the TTL and the value, written for the actual defect rather than copied from a template. Where an SPF record has grown past the ten-lookup limit that mail servers enforce, you get a rewritten record that fits, a list of which suppliers were expanded to make it fit, and a plain warning about what you take on by hard-coding their addresses.
It names the senders. Every entry in an SPF record and every mail server is resolved to the actual service behind it, so an entry a client cannot account for becomes a conversation rather than a mystery hostname in a text file.
DMARC is validated against the revision published in May 2026, which removed three settings that older records still carry and replaced the public-suffix lookup with a tree walk. Records written against the previous version are flagged as no longer conformant — including on some very well-known domains.
Then it writes the report: a cover, a one-page summary a non-technical client can read, a ranked list of what to fix first across the whole portfolio, a page per domain, and an appendix carrying the scoring rubric and an honest statement of what was not measured. Add your own logo and company name and the cover becomes entirely yours.
Where something cannot be proven, it says so. DKIM signing keys are published under a name only you and your provider know, and that name cannot be discovered from public records — so a negative result reads “no key found at any of the names we tested”, never “DKIM is not configured”. Supply your selector names and the answer becomes definitive.
Who it's for
- For managed service providers. Audit a client's whole estate before onboarding, hand over a branded report on day one, then run it monthly and get told only what changed.
- For digital agencies. When you inherit a client's domains, find out what you have taken on — including the certificate expiring in nine days and the domain registration lapsing next month.
- For in-house IT and security. Answer “are we ready for the bulk-sender requirements?” across forty domains in one run, with the blockers listed per domain and the record to publish for each.
- For developers and AI agents. Every finding is structured — a machine code, a human explanation, the evidence and the fix — with an explicit confidence signal so an agent never reports a failure that was only ever unproven.
Pricing
$0.012 per domain audited.
$0.08 per report, however many domains it covers.
No subscription, and the per-domain price drops as volume rises. Domains that do not exist or cannot be checked are never charged. Sender inventory, subdomain discovery, white-label reporting and change monitoring are all included rather than sold separately.
Fewer knobs. Better defaults.
One dropdown, not fifteen switches
Paste domains, press Start. Choosing how deep to go is a single choice, and every other field already has a sensible default.
The scoring is published
Every component, its points and how they are awarded, printed in the report and returned with every run. A score you cannot explain to a client is worth nothing.
Unknown is not a failure
Where something genuinely cannot be proven from public records, it is reported as unproven rather than guessed. Nothing is marked as failing on the strength of missing data.
The fix, not just the finding
A copy-paste record for every problem, including a rewritten SPF record when yours has outgrown the lookup limit, and a four-stage DMARC rollout plan with the exact value at each step.
Ground truth, not a cached answer
Records are read from each domain's own nameservers rather than a shared cache, so you see what is published right now — and a negative answer is confirmed before it is believed.
Built for a portfolio
Repeated problems collapse into one entry listing the affected hosts, the queue is ranked by what is worth fixing rather than alphabetically, and scheduled runs report only what moved.
What it does not do.
DKIM cannot be proven absent. Signing keys sit under a name only you and your provider know, and public records cannot be listed. A negative result always says how many names were tested. Supply yours and it becomes definitive.
No blocklist checks. The major blocklist operators forbid commercial use of their free query services. Rather than breach those terms or pass the cost on, the check is left out entirely and said so.
No live mail conversation. Nothing connects to your mail servers, so there is no banner check and no inspection of the certificate a mail server actually presents. Everything about mail transport comes from published records.
Reverse DNS is measured on receiving servers. The servers you send from are not published anywhere and cannot be assessed from outside, so a passing result is not a certification that you meet every bulk-sender requirement.
BIMI is a draft. It is not a finished internet standard and support varies by provider. The record and logo format are validated and the certificate's issuer and expiry are read; chain validation needs a trust store that is not bundled.
Call it as a tool.
Three tools over the same engine: audit a set of domains, produce a full report, or run a fast readiness check. Every finding carries a machine-readable code alongside a human explanation and the record to publish.
Readiness answers are four-valued, not two: true, false, unknown where it could not be proven, and not-applicable where the domain publishes that it handles no mail at all. An agent should never treat unknown as a failure.
- audit_domain — full audit of up to 25 domains, with every finding and its fix.
- generate_report — a complete client-ready report for up to 50 domains.
- check_mandate_compliance — fast readiness check across up to 100 domains.
Batch sizes are bounded deliberately and stated in each tool description. Larger portfolios belong on the Apify actor, which is built for them.
Checking a single domain?
Email Domain Checker is the simpler sibling: one domain, its SPF, DKIM and DMARC records, and whether they are set up correctly. This tool exists for the other job — auditing many domains at once, scoring them against each other, and producing something you can hand to a client.