NERDTOOLS / DOMAIN DIAGNOSTICS

TRUST / METHODS + LIMITATIONS

Evidence with boundaries.

NerdTools observes publicly reachable domain, DNS, email, web, TLS, IP, reputation, and network signals. The platform is designed to make those observations reproducible without presenting them as guarantees.

01 /

How checks are performed.

Requests are normalized and resolved before execution. Private and reserved destinations are rejected, and redirect destinations are validated again before a supported tool follows them.

  • DNS and WHOIS checks query public infrastructure.
  • Web checks fetch bounded public responses with time and size limits.
  • TLS checks inspect the certificate and protocol behavior presented publicly.
  • Tool failures remain isolated so one unavailable signal does not invalidate the rest of a scan.

02 /

How summaries should be read.

A summary prioritizes selected findings from a time-bounded scan. Results can differ across resolvers, networks, edge locations, caches, providers, and time.

  • Scores organize investigation; they are not certifications or warranties.
  • Absence of a public finding does not prove absence of a private vulnerability.
  • Deliverability and indexation require provider-owned evidence in addition to public configuration.
  • Consequential changes should be verified with the responsible provider or system owner.

03 /

Freshness, indexing, and corrections.

Public scan summaries are cached for a limited period and only higher-coverage summaries are eligible for search indexing. Hidden scans and shared snapshots are excluded from indexing.

  • Sitemap inclusion is limited by freshness, quality, popularity, and configured scope.
  • Expired or incomplete summaries are not treated as indexable reports.
  • Public results can be refreshed as infrastructure changes.
  • Report reproducible errors through the contact page so the parser or explanation can be corrected.

FAQ /

Operational detail.

Does NerdTools perform penetration testing?

No. It performs bounded, read-only checks of public signals and selected public TCP services.

Why might another checker disagree?

Resolvers, geographic edges, caches, timing, trust stores, data sources, request headers, and parser behavior can all differ.

Does a passing result guarantee compliance?

No. Compliance depends on scope, policy, evidence, operations, and controls that a public diagnostic cannot fully observe.