Domain Overview
Aggregate DNS, mail, web, registration, and exposure posture for any domain
This web edition shows the DD sections that run safely in the browser. Deeper sections stay visible below and are marked clearly when they need the broader online run.
Web edition coverage Partial browser support The GitHub Pages edition runs the DD checks that are safe through browser DNS and keeps deeper network sections visible as deeper-run work.
- DNS inventory, provider hints, and DNS application fingerprints
- Core mail authentication and transport DNS controls
- Browser-safe evidence ledger and posture notes
- HTTP headers, security.txt, and TLS certificate handshake details
- RDAP registration data and DNSBL/exposure checks
- Certificate Transparency subdomain discovery
Install-Module DomainDetective -Scope CurrentUser
Import-Module DomainDetective
$check = Get-DomainHealthCheck -Domain "primus-design.com"This view uses the DD checks that run cleanly in the browser. Sections that need deeper online validation stay visible below and are marked clearly.
DD merged mail, web, registration, and exposure findings into the overview assessment count shown here.
- DNS Inventory: TXT verification/service tokens present: Google Site Verification
- DNS Inventory: Apex AAAA record missing (A is present).
- DNS Inventory: Incomplete IPv6 support detected: apex AAAA missing; no AAAA for NS hosts (checked 2).
The mail and DNS posture combines SPF, DKIM, DMARC, MX, transport policy, and DNS infrastructure into one DD control surface.
- SPF: ~all
- DKIM: Missing
- DMARC: Missing
DD blends HTTP reachability, certificate posture, and disclosure metadata to summarize the exposed web surface.
- Security.txt: Missing
Mail routing, authoritative DNS, and detected DNS application fingerprints shape the provider footprint DD reports here.
- GoogleWorkspace: MxRecord
- Google Site Verification: TxtRecord
DD uses subdomain discovery and external application clues to outline the domain’s visible exposure surface.
Registration timing, registrar context, and DD hinting combine here to summarize the registration and lifecycle posture.
- Publish a valid DMARC record.
- Ensure DKIM selectors have valid keys.
- Mail provider: GoogleWorkspace
- SPF: ~all (2/10 lookups)
- DKIM: Missing (No selectors were discovered.)
- DMARC: Missing (No DMARC policy published.)
- MX: 5 record(s) (Google Workspace)
DD found this mail authentication control, but it still needs follow-up in the current overview run.
- 2/10 lookups
DD marked this mail authentication control for remediation in the current overview run.
- No selectors were discovered.
DD marked this mail authentication control for remediation in the current overview run.
- No DMARC policy published.
DD found this mail transport control, but it still needs follow-up in the current overview run.
- Google Workspace
DD marked this mail transport control for remediation in the current overview run.
- No MTA-STS policy published.
DD marked this mail transport control for remediation in the current overview run.
- No TLS reporting record published.
DD marked this mail authentication control for remediation in the current overview run.
- No BIMI record published.
DD marked this trust and dns hardening control for remediation in the current overview run.
- No CAA restrictions published.
DD marked this dns infrastructure control as healthy in the current overview run.
- ASN diversity: 1
DD marked this dns infrastructure control as healthy in the current overview run.
- ns1.value-domain.com / refresh 3600s
DD marked this exposure control as healthy in the current overview run.
- 6 target(s), 0 listing(s)
Softfail/neutral (~all/?all) do not enforce rejection and allow spoof attempts to be accepted more easily.
- How: After validating legitimate senders, switch to '-all' for enforcement. Coordinate with DMARC so alignment continues to pass.
- Verify: Mail from authorized IPs passes; unauthorized sources fail with -all.
- Reference: https://www.rfc-editor.org/rfc/rfc7208#section-5.1
Misordered priorities can confuse troubleshooting and automated tooling.
- How: Use ascending MX preference values; duplicates are allowed to load-balance.
Without MTA-STS, SMTP TLS remains opportunistic and subject to downgrade.
- How: Publish a DNS TXT at _mta-sts.<domain> and host https://mta-sts.<domain>/.well-known/mta-sts.txt with valid mode/max_age/mx.
- Reference: https://www.rfc-editor.org/rfc/rfc8461
Without DANE, SMTP/HTTPS clients cannot pin certificates via DNSSEC.
- How: Publish TLSA records at _<port>._<proto>.<host> with correct usage/selector/matching values.
- Verify: dig _25._tcp.mail.example.com TLSA and validate fields.
Without authenticated DNSKEY, validators cannot build a trust chain for your zone.
- How: Ensure authoritative servers sign DNSKEY RRset and provide valid RRSIGs; check key publishing and rolling procedures.
Without a DS record in the parent zone, DNSSEC validation cannot succeed.
- How: Publish a DS record for your zone at the parent registry; coordinate with your registrar.
The queried host or domain was not listed by any checked DNSBL provider.
- How: Monitor periodically to ensure continued clean reputation.
- Verify: Repeat the check; expect NXDOMAIN or not listed responses.
Aggregated outcome of DNSBL checks across providers and inputs.
- How: Use as a high-level metric; investigate 'listed' details if any providers reported a listing.
- Verify: Re-run checks or inspect per-host DNSBLRecords in raw results.
Multiple MX hosts improve resilience and availability of inbound mail.
- How: Maintain at least two MX records with differing preferences hosted on separate infrastructure.
2/10 lookups
No selectors were discovered.
No DMARC policy published.
Google Workspace
No MTA-STS policy published.
No TLS reporting record published.
No BIMI record published.
No CAA restrictions published.
No TLSA records published.
0 DS, 0 DNSKEY
ASN diversity: 1
ns1.value-domain.com / refresh 3600s
Web headers, certificates, security.txt, and registration data need the deeper online run.
DD matched 1 provider or application signal(s) in this category. Expand to review the detailed evidence cards.
Show analytics matches (1)
TXT matched Google Site Verification across 1 observation.
- TXT: google-site-verification=Lvvvcptgd-ctYbtwEIEQMf_CbxBxen3bEq7CyFEiLKY
DD matched 1 provider or application signal(s) in this category. Expand to review the detailed evidence cards.
Show other matches (1)
MX matched GoogleWorkspace across 1 observation.
- MX: MX alt3.aspmx.l.google.com matches alt3.aspmx.l.google.com
DD combined mail, DNS, web, registration, and exposure checks into the domain posture shown on this page. This card summarizes how broad that evidence set was.
- SPF: ~all
- DKIM: Missing
- HTTP: Offline
- Certificate: Missing
Provider, routing, and third-party application evidence all contributed to DD's view of the domain's public operating surface.
- Mail provider: GoogleWorkspace
- Google Site Verification via TXT
- GoogleWorkspace via DnsInventory.MailProvider
DD blended HTTP, certificate, disclosure, DNSBL, and RDAP sources to judge the outward-facing web and registration surface for this domain.
- HTTP: Unknown / No HSTS
- Certificate: review needed
- DNSBL: clear
Show evidence details (5 cards)
DD correlated DNS inventory, mail routing, and application fingerprints to infer provider posture for this domain.
- Mail provider: GoogleWorkspace
DD combined SPF, DKIM, DMARC, MX, transport policy, and authoritative DNS checks into the mail-security posture shown on this page.
- SPF: ~all (2/10 lookups)
- DKIM: Missing (No selectors were discovered.)
- DMARC: Missing (No DMARC policy published.)
- MX: 5 record(s) (Google Workspace)
DD used DNS application fingerprints to infer third-party services and provider overlap across the domain.
- Google Site Verification via TXT
- GoogleWorkspace via DnsInventory.MailProvider
HTTP response behavior, TLS certificate posture, and disclosure controls contribute to the web-facing DD assessment for the domain.
Registration evidence was not available during the DD run.
DD combined DNS inventory, routing, and application fingerprints to summarize the provider footprint behind this domain.
- GoogleWorkspace: MxRecord
- Google Site Verification: TxtRecord
- Mail provider: GoogleWorkspace
DD blended web reachability, certificate/security metadata, and registration timing into these posture notes.
- Publish a valid DMARC record.
- Ensure DKIM selectors have valid keys.
- Sign zones and publish DS records.
DD used subdomain discovery, naming sensitivity, and certificate context to summarize the external exposure profile.
DD assessments are grouped here by severity so the overview shows how much of the current result is error-driven, warning-driven, or informational.
- DANE: No DANE records found.
- DNSSEC: DNSKEY for primus-design.com not authenticated
- DNSSEC: No DS record for primus-design.com
These categories produced the most DD findings in the current overview and usually point to the main posture themes worth reviewing first.
- DNSBL: 7 finding(s)
- SPF: 6 finding(s)
- DNS Inventory: 4 finding(s)
- SOA: 4 finding(s)
This shows how broadly the DD findings are distributed across concrete sources and targets instead of appearing only as generic summary messages.
- Target: 142.250.101.27
- Target: 172.217.216.27
- DANE: No DANE records found.
- DNSSEC: DNSKEY for primus-design.com not authenticated
- DNSSEC: No DS record for primus-design.com
- General: MX priorities are not in ascending stable order
- MTASTS: No MTA-STS DNS bootstrap record published.
Show findings (28)
- Warning DANE.NoRecords — No DANE records found.
- Warning DNSSEC.DNSKEY.NotAuthenticated — DNSKEY for primus-design.com not authenticated
- Warning DNSSEC.DS.Missing — No DS record for primus-design.com
- Warning MTASTS.Record.Missing — No MTA-STS DNS bootstrap record published.
- Warning MX.Priority.OutOfOrder — MX priorities are not in ascending stable order
- Warning SPF.All.Soft — SPF ends with '~all'. Consider '-all' once senders are validated.
- Info DNSBL.NotListed — Not listed on any DNSBL
- Info DNSBL.NotListed — Not listed on any DNSBL
- Info DNSBL.NotListed — Not listed on any DNSBL
- Info DNSBL.NotListed — Not listed on any DNSBL
- Info DNSBL.NotListed — Not listed on any DNSBL
- Info DNSBL.NotListed — Not listed on any DNSBL
- Info DNSBL.Summary — Checked 123 providers across 6 hosts; listed 0/6.
- Info DNSINV.Apex.AAAA.Missing — Apex AAAA record missing (A is present).
- Info DNSINV.IPv6.Incomplete — Incomplete IPv6 support detected: apex AAAA missing; no AAAA for NS hosts (checked 2).
- Info DNSINV.ResultsPresent — Captured 14 DNS record(s) across 8 record type(s).
- Info DNSINV.TXT.Signals.Exposed — TXT verification/service tokens present: Google Site Verification
- Info MX.Success.RedundantHosts — Multiple MX preferences detected
- Info NS.Diversity.High — Authoritative NS are diverse across networks/providers (ASNs: 1)
- Info SOA.Expire.Sane — SOA Expire value is within recommended range: 604800
- Info SOA.MNAME.MatchesNS — SOA MNAME matches published NS records
- Info SOA.Refresh.Sane — SOA Refresh value is within recommended range: 3600
- Info SOA.Retry.Sane — SOA Retry value is within recommended range: 900
- Info SPF.Flattened.IpSetOptimized — Flattened SPF IP set has no duplicates
- Info SPF.Include.ChainValid — SPF include/redirect chain resolves without loops
- Info SPF.Lookups.WithinLimit — DNS lookups within limit: 2/10
- Info SPF.Record.Present — SPF record present
- Info SPF.Record.StartsV1 — SPF starts with v=spf1
Run with CLI, PowerShell, or C#
$ dotnet tool install -g DomainDetective.CLI
$ domaindetective check 'example.com'