DNS • EMAIL • SECURITY • WEB

DNS Health Checker

Deeply check your domain’s DNS health, DNSSEC, email security, nameservers, HTTPS, TLS, blacklists and more with a comprehensive DNS health check.

What is DNS Health Checker?

DNS Health Checker is denlook networking that helps you to check your domain's DNS configuration, email security, DNSSEC, nameservers, HTTPS, TLS, blacklists, and other important DNS health and security settings from one place.

The DNS Health Checker performs multiple checks and provides a clear health score, status indicators, detected records, warnings, failures, and recommended fixes.

How to use DNS Health Checker?

Enter your domain in the search box and click the Scan button to start an automatic deep scan. The tool analyzes your domain for email security, DNSSEC, nameserver health, web security, DNS configuration, and other important security and infrastructure signals all in a single comprehensive report. Once the scan reaches 100%, you’ll receive an overall security score and grade, helping you quickly understand how secure and well-configured your domain is.

What Does the DNS Health Checker Check?

The checker audits the main DNS, email, security, infrastructure, and web configuration areas that can affect your domain's reliability and security.

  • DNS Records: Checks records such as A, AAAA, CNAME, NS, SOA, MX, TXT, CAA, and SRV.
  • DNS Configuration: Checks DNS syntax, duplicate records, TTL, caching, response codes, and response behavior.
  • Nameservers: Checks nameserver health, consistency, availability, and failure tolerance.
  • Email Security: Checks SPF, DKIM, DMARC, MX health, and related email configuration.
  • DNSSEC: Checks DNSSEC deployment, delegation, keys, signatures, and chain-related indicators.
  • DNS Security: Checks AXFR zone transfers, open recursive resolvers, wildcard DNS, dangling DNS, and potential takeover signals.
  • Web Security: Checks HTTPS, TLS certificates, protocols, ciphers, and certificate-chain indicators.
  • Additional Security: Checks security.txt, MTA-STS, TLS-RPT, TLSA/DANE, CAA, reverse DNS, and blacklist-related signals.
  • Operational Health: Checks DNS availability, latency, stability, propagation-related signals, changes, anomalies, and risk indicators.

DNS Records Explained

DNS records tell the internet how your domain should resolve and which services are associated with it.

  • A: Points a domain to an IPv4 address.
  • AAAA: Points a domain to an IPv6 address.
  • CNAME: Creates an alias to another hostname.
  • NS: Identifies the authoritative nameservers for a domain.
  • SOA: Contains important zone, authority, and DNS timing information.
  • MX: Defines the mail servers responsible for receiving email.
  • TXT: Stores verification and security-related information.
  • CAA: Controls which certificate authorities may issue certificates for the domain.
  • SRV: Defines service locations for supported applications.

Email Security Checks

DNS plays an important role in protecting domain-based email. The checker examines common email authentication and mail-delivery settings.

  • SPF: Checks the domain's sender authorization policy.
  • DKIM: Looks for common DKIM selectors and signing records.
  • DMARC: Checks the DMARC policy and important tags such as policy and reporting.
  • MX Health: Checks mail-server resolution, priority, IPv6, reverse DNS, and related signals.
  • SMTP Security: Checks TLS support, banners, and related mail-server security indicators.

DNSSEC and Domain Security

DNSSEC helps protect DNS responses against certain forms of DNS spoofing and tampering. The checker looks for DS, DNSKEY, and RRSIG records and identifies missing or potentially inconsistent DNSSEC material.

Security checks also look for exposed zone transfers, open recursion, wildcard behavior, dangling DNS records, possible takeover signals, DNS rebinding risks, and other configuration weaknesses.

HTTPS, TLS and Web Security

DNS health is closely connected with the web services behind a domain. The checker also examines HTTPS availability, TLS certificates, certificate expiration, protocol support, cipher information, and certificate-chain indicators.

Additional checks can identify security.txt, MTA-STS, TLS-RPT, TLSA/DANE, CAA, reverse DNS, and blacklist-related configuration signals.

How the Health Score Works

After the scan, results are grouped into categories and combined into an overall health score. Individual checks can be marked as passed, warning, failed, informational, not applicable, or error depending on the result.

A lower score does not necessarily mean that your website is offline. It can indicate missing security controls, configuration weaknesses, or areas that should be reviewed.

What Do the Results Mean?

  • Pass: The check met the expected condition.
  • Warning: The configuration works but may need improvement.
  • Fail: A significant configuration or security issue was detected.
  • Info: Useful information was found or a feature was not detected.
  • Not Applicable: The check does not apply to the scanned configuration.
  • Error: The checker could not complete the check normally.

How to Improve Your DNS Health

  • Keep at least two reliable authoritative nameservers.
  • Review SPF, DKIM, and DMARC configuration for your email services.
  • Deploy and correctly maintain DNSSEC where appropriate.
  • Restrict unauthorized AXFR zone transfers.
  • Avoid unnecessary wildcard and dangling DNS records.
  • Keep HTTPS certificates valid and properly configured.
  • Review CAA, reverse DNS, SMTP TLS, and other security settings.
  • Monitor important DNS changes and investigate unexpected anomalies.

Frequently Asked Questions

What is a DNS Health Checker?

A DNS Health Checker is a diagnostic tool that examines a domain's DNS, nameservers, email authentication, DNSSEC, security, web, and infrastructure-related configuration.

Why should I check my DNS configuration?

DNS problems can affect website availability, email delivery, security, and service reliability. Regular checks can help identify configuration issues before they become larger problems.

Does the checker only test DNS records?

No. In addition to DNS records, the checker evaluates areas such as DNSSEC, email security, nameservers, SMTP, HTTPS/TLS, blacklists, reverse DNS, and operational security signals.

What does a failed check mean?

A failed check means the scanner detected a condition that should be reviewed. The result normally includes additional information explaining the detected issue and what can be done about it.

Does a high score guarantee that my domain is completely secure?

No. A health score is a diagnostic indicator based on the checks performed by the scanner. It should be used as a starting point for reviewing your DNS and security configuration rather than as a guarantee of complete security.