One Click Answers

OCAInternet

Share tool
FacebookPinterestEmail

Domain Health Check

Is my domain set up correctly?

Enter your domain. You get one report on its website, secure connection, DNS and email records, and a short list of what to fix first.

About this tool & how to use it

What it does

Checks a domain's website, secure connection, redirects, DNS and email records in one report and lists what to fix first, in plain English.

How to use it

  1. Type your domain, such as example.com, and press Check my domain.
  2. Read the summary, then "What should I fix?": it lists only things that were actually found, worst first.
  3. Read each area below it. Open the linked tool for any area to see the full detail.

Enter your domain, like example.com. We check the website, the secure connection, DNS and the email records in one go.

One click answer

Your answer will appear here.

Enter the address and your answer will appear here.

The domain you enter is sent to our server, which checks it with public DNS and registry services and by requesting the website from our server, and discards what the website returns. We do not keep the domain or a history. Nothing you enter is sent to analytics.

How it works

The page sends your domain to our server, which runs the independent checks at the same time: it looks up the domain's address and name server records, requests the website over https and over http, follows the redirects, reads the mail server (MX), SPF and DMARC records through the public DNS service, and asks the domain's registry when the registration expires. Each check can fail on its own: a check that could not finish is marked "Could not check" and the rest of the report is still shown.

The report has a section for each area: Domain, DNS, Website, SSL, Redirects, Email and Registration. Each line shows what was seen with a mark (OK, Info, Check or Fix). "What should I fix?" is made only of the lines that need attention, in plain English, worst first. There is no score: a number would hide what is actually wrong.

Some things it cannot know, and says so. Our server cannot read a certificate's own dates, so the SSL section says what the connection proved (the certificate was accepted for that name) and that the expiry date is not available. DKIM needs a selector, so it is never reported missing: use the DKIM Checker. And every website result is what our server saw, once.

Assumptions

  • The results are what public DNS, the registry and our server returned once. A change you made recently can take time to appear.
  • A missing SPF or DMARC record is only raised when the domain has mail servers, because a domain that does not handle email does not need them.
  • DKIM is not checked here because it needs a selector.
  • The certificate's expiry date is not available from our server.
  • The domain you enter is sent to our server, which checks it with public DNS and registry services and by requesting the website from our server. We do not keep it and keep no history.

Example

Input: example.com, with a working website on https, http redirecting to https, mail servers, SPF and DMARC records, and a registration that runs for months

Result: Everything important that we could check for example.com looks good.

Questions

Does it give my domain a score?

No. A score would hide what is wrong. You get a list of what was found, worst first.

Why does it say "Could not check"?

One of the services it asked did not answer in time. That says nothing about your domain; the other checks are still valid. Try again in a moment.

Why is there no SSL expiry date?

Our server can tell that a secure connection to your domain works and that its certificate was accepted for that name, but it cannot read the certificate's own dates.

Why is DKIM not checked?

A DKIM key is published at a name that contains a "selector" chosen by whoever sends your email, so it cannot be found from the domain alone. Use the DKIM Checker with your selector.

Last reviewed 2026-10-03.

Related tools

Try another answer