Security tests by topic

Want to focus on one area? Each of these free tests goes deep on a single topic, with the checks explained and the sources named — or run the full domain security check to cover everything in one pass. Eight of these pages explain one topic each and hand you straight to the scan that measures it — the DMARC page is a reference rather than a test, and the DNS lookup queries live on its own page. Everything here reads live data, and none of it needs an account.

DMARC explained (RFC 9989)

The full reference on the current standard: every tag with its real default, the DNS tree walk worked through, ten annotated example records, the rollout plan, how to read the reports & a troubleshooting tree.

How we grade it →

DMARC report viewer

Drop or paste the aggregate reports receivers send to your rua address: every sending source with its DMARC, DKIM and SPF results, a red/orange/green light, override reasons and every RFC 9990 field explained – read in your browser, nothing uploaded.

How to read a report →

DNSSEC test

Zone signing, the DS record at the registrar, recommended algorithms (RFC 9904), signature lifetimes, NSEC3 and automatic DS maintenance.

How we grade it →

SSL/TLS certificate test

The website's HTTPS: certificate chain & trust, validity and hostname, key strength, TLS versions (1.0–1.3), cipher suites & forward secrecy, HSTS and the HTTP→HTTPS redirect.

How we grade it →

MTA-STS test

The _mta-sts record and the HTTPS policy file, its mode and max_age, whether the mx list matches your real MX hosts, and TLS-RPT failure reporting.

How we grade it →

BIMI check

The BIMI record at default._bimi: the l= logo (SVG Tiny P/S), the optional a= VMC and the avp= avatar preference – plus the DMARC-enforcement prerequisite.

How we grade it →

Which test do you need?

If you arrived with a symptom rather than a protocol name, start here. The right-hand column is the page that explains the mechanism behind the symptom and shows you what a correct configuration looks like.

What you are seeingStart here
Your mail is landing in recipients' spam foldersSPF, DKIM & DMARC check
Someone is sending mail that looks like it comes from your domainDMARC explained (RFC 9989)
You published DMARC and legitimate mail started being rejectedDMARC explained (RFC 9989)
You receive DMARC reports as XML attachments and cannot make sense of themDMARC report viewer
Your brand logo does not show up in the inboxBIMI check
Mail sent to you should be encrypted in transit, and you want it enforcedMTA-STS test
You want the certificate of your mail servers pinned in DNSDANE mailserver test
Browsers warn visitors about your certificate, or the grade is poorSSL/TLS certificate test
A header scanner gave your site a bad scoreSecurity headers test
You want your zone cryptographically signed, or the chain is brokenDNSSEC test
A DNS change is not taking effect, or resolvers disagreeDNS lookup & propagation

One scan for everything

Eight of the topics above are graded by the complete domain security check, which covers your whole domain — website TLS, mail server, DNS, DNSSEC, email authentication and HTTP security headers — in a single run, from A+ to F, with a per-check explanation and remediation tips. One page stands apart on purpose: the DNS lookup adds an ungraded comparison across 11 public resolvers and 7 blocklist resolvers that the full scan does not run — the zone's own name servers are checked in both. Otherwise the topic pages and the full scan use the same engine, so a finding you see on one you will see on the other.

How the grading works

Nearly every check is documented: what it looks at, how it is scored, what weight it carries and how to fix a failure. The reference is split by module — website TLS, mail server TLS & DANE, email authentication, DNS, DNSSEC and HTTP security headers — with the rating caps and the scoring model explained on the checks & scoring page.

Need to publish a record first?

Testing tells you what is wrong; the Record Studio writes the record that fixes it — SPF, DKIM, DMARC, BIMI, TLSA, SMIMEA, MTA-STS, TLS-RPT, CAA, security.txt and Null MX, all generated in your browser. For a message you actually send or receive, the live email test goes further than DNS can: it measures a real message end to end.