NERDTOOLS / DOMAIN DIAGNOSTICS

WORKFLOW / COMPLETE DOMAIN DIAGNOSTIC

Read the domain as one connected system.

DNS, email, HTTPS, security, availability, reputation, and search signals fail in different ways but often share the same underlying domain configuration.

01 /

Start with dependencies.

Resolve the domain and inspect delegation before interpreting services built on top of it.

  • Confirm public DNS and authoritative nameservers.
  • Inspect registration and expiry signals.
  • Validate DNSSEC where deployed.
  • Review the resolved public network context.

02 /

Follow each public service.

Continue through web transport, browser protections, mail authentication, reputation, availability, and crawler-facing signals.

  • Check certificate validity, TLS support, redirects, and headers.
  • Review MX, SPF, DKIM, and DMARC together.
  • Treat blacklist and port findings as context, not proof of compromise.
  • Inspect robots, sitemaps, metadata, schema, links, and indexation evidence.

03 /

Choose the signal you need.

FAQ /

Operational detail.

What does the domain health score mean?

It summarizes selected public findings so investigations can be prioritized. It is not a certification, vulnerability assessment, search ranking score, or guarantee.

Does a low-risk result prove the site is secure?

No. Public diagnostics cannot inspect private configuration, application code, access controls, logs, or every possible service.

Why can results change between scans?

DNS caches, CDNs, certificate deployments, reputation sources, remote availability, and the target configuration can all change over time.