METHODS & PRIVACY
Useful answers.
Clear boundaries.
These tools make live, bounded checks of public DNS and web endpoints. A report shows the evidence available at the time of the request.
DNS
DNS queries use public recursive resolvers. TXT verification compares Google and Cloudflare from the same server; this is not a worldwide propagation test. TTLs are the resolver’s remaining cached lifetimes. A resolver error is kept separate from a missing record.
SSL & HTTP
Certificate checks use SNI and the server’s CA trust store on port 443. HTTP checks use GET, do not run JavaScript and stop after ten responses. Only standard ports and public addresses are supported. The results describe one network vantage point.
Email policy
SPF is a static dependency audit, not a sender-IP evaluation. DMARC inspects the exact _dmarc name under RFC 9989, without organizational-domain fallback. These tools do not send email or establish inbox placement. CAA follows DNS issuer authorization; other CA requirements still apply.
What gets sent
The target and checking options are sent to this server. Hostnames go to public DNS resolvers; HTTP and TLS targets see connections from our server. Network ownership lookup may query Team Cymru DNS. Do not enter private URLs, credentials or confidential tokens.
Storage & reports
There are no accounts, tracking scripts or saved report database in this section. Check inputs and results are processed in memory and are not intentionally stored by this application. Hosting, CDN and DNS providers may retain their own operational logs. CSV files are generated in your browser. CAA and DMARC generator values stay in your browser.
Limits & interpretation
Up to 10 certificates or 5 redirect inputs per request. A single-domain variant comparison checks four URL forms. Requests have time, query and concurrency limits. Partial and failed checks do not imply a clean result. No monitoring or notifications run in the background.