Free tool

Check a vendor without asking them anything

Enter a domain and get a posture snapshot in about three seconds. Built only from public DNS. No account, no scanning, and no request of any kind reaches the domain you are checking.

Try your own domain first. Then try a supplier you have a questionnaire on file for, and see whether the two agree.

This tool is passive and non-intrusive. Every lookup goes to a public DNS resolver, never to the domain being checked. No packet reaches that organisation's infrastructure, nothing is scanned, no port is probed and no login is attempted. It reads the same public records any recipient mail server reads before accepting a message.

What it checks, and why each one matters

DMARC
Whether mail claiming to come from this domain gets rejected. A domain at p=none is publishing a policy that instructs recipients to do nothing, which is the most common gap we find.
SPF
Who is authorised to send on the domain's behalf, and whether unlisted senders hard fail or merely get a shrug.
CAA
Which certificate authorities may issue for the domain. With no CAA record, any public CA can.
DNSSEC
Whether DNS answers are signed, which makes tampering detectable.
Mail provider
Who actually handles their mail. That provider is one of their sub-processors, and by extension usually one of yours.

What it deliberately does not do

Worth being explicit, because a security company caught scanning without authorisation would deserve everything that followed.

  • No port scanning and no service fingerprinting.
  • No authentication attempts of any kind.
  • No crawling, and nothing that ignores robots.txt.
  • No requests to the checked domain at all, rate limited or otherwise.
  • No storage of the domains you check beyond your own browser session.

A clean result is not a clean bill of health

Five green rows mean five specific public records are configured well today. It says nothing about what happens inside that vendor, and this tool does not pretend otherwise. What it is good for is the opposite signal: a domain that cannot get DMARC right is unlikely to have the harder things right either, and now you know to ask.

Run it across every vendor, every day

One domain is a snapshot. The value is in re-checking your whole supplier register on a schedule and being told the day an answer changes.

Talk to us about your register