This domain health checker runs twelve checks in one go and scores the result out of 100, so you can see at a glance whether a domain is set up properly for the web and for email. Each failed or weak check comes with a short fix and a link to the tool or guide that goes deeper. It is useful before a launch, after a DNS or hosting move, and when mail suddenly starts landing in spam.
Short answer: Enter a domain and the checker tests name servers, DNSSEC, CAA, the HTTPS certificate, the HTTP to HTTPS redirect, six security headers, MX, SPF, DKIM (common selectors), DMARC, MTA-STS and the blacklist status of the mail server IPs. A score of 90 or more (grade A) means nothing important is missing; anything below 80 has at least one fix that affects security or deliverability.
Table of Contents
What the score measures
| Check | Weight | Passes when |
|---|---|---|
| HTTPS certificate | 15 | Trusted chain, name matches, more than 14 days left |
| DMARC | 12 | Policy is quarantine or reject |
| SPF | 10 | Exactly one record ending in ~all or -all |
| Security headers | 10 | At least 5 of HSTS, CSP, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy |
| Mail server blacklists | 10 | MX IPs not listed on major blocklists |
| Name servers | 8 | Two or more name servers answer |
| MX records | 8 | At least one MX record |
| DNSSEC, CAA, DKIM | 6 each | Signed zone, CAA published, DKIM key found |
| HTTP to HTTPS redirect | 5 | http:// answers with a redirect to https:// |
| MTA-STS | 4 | Policy record published |
Optional hardening such as DNSSEC, CAA and MTA-STS counts half when missing, so a domain is not punished heavily for skipping them, but it cannot reach 100 without them.
How to use the results
Work through the “How to fix” list from the top: certificate and DMARC problems affect the most people. Each fix links to the matching srvScripts tool, such as the SPF record generator or the DMARC report analyzer, so you can change a record and re-check straight away. Use Copy share link to send the exact result to a colleague or client; the link stays valid for 30 days.
Limits of an outside check
The checker sees what the internet sees. It cannot tell whether DKIM is signing with a custom selector, whether internal mail flows are authenticated, or whether a WAF blocks our requests. DKIM is tested against common selectors only; use the DKIM checker with your own selector for a definite answer.
Domain health checker at a glance



Official documentation: RFC 7489: DMARC, RFC 8659: CAA.
Related tools: SPF record checker · DMARC checker · SSL certificate checker.
Frequently asked questions
What is a good domain health score?
90 or more (grade A) means the essentials are in place. 80 to 89 usually means one optional item or one warning. Below 80, at least one check affects security or email delivery and should be fixed.
Why does my domain lose points for DKIM when I have it set up?
The checker only tries common selectors such as default, google, selector1 and k1. If your provider uses another selector, the key exists but is not found. Confirm it with the DKIM checker and your own selector.
How often should I run a domain health check?
After any DNS, hosting or email provider change, before a launch, and monthly as routine. Certificates expiring and new blacklist listings are the most common changes between checks.