Domain Health Audit: DNS, WHOIS, SSL, SPF, DKIM & DMARC logo

Domain Health Audit: DNS, WHOIS, SSL, SPF, DKIM & DMARC

by Howth Technology FactoryOfficialWebsiteUpdated Jul 31, 2026

Domain Health Audit as an MCP server: DNS, WHOIS, SSL, SPF, DKIM and DMARC posture with copy-paste fixes.

dmarc
spf
dkim
+7
|

How to pay

Pick whichever fits your workflow — you can switch any time.

Subscribe

Monthly billing

$19/month

Predictable monthly cost with included usage. Best for steady, high-volume traffic.

  • Unlimited tools within plan limits
  • One API key, billed once a month
  • Cancel any time

Pay-per-call

Agent-native

$0.01 – $0.10 per call

Charge agents in USDC the moment they call a tool. No subscriptions, no signup — pay only for what you use.

  • 3 priced tools available
  • Settled in USDC on Base
  • No account or API key required

Audit a domain's full published posture in one call — DNS records, WHOIS registration and expiry, SSL certificate validity, HTTP security headers, and the complete email authentication stack: SPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT, BIMI, DNSSEC and DANE.

Every finding comes back with the exact DNS record to publish. Not advice — the record itself: host, type, TTL and value, correct for the defect actually found. SPF records that breach the ten-lookup limit come back flattened, with a diff showing what changed and what the new record authorises.

Built for the bulk-sender mandates. Google and Yahoo since February 2024, and Microsoft since May 2025, all require SPF, DKIM and DMARC with alignment from anyone sending 5,000 or more messages a day — enforced by rejection, not filtering. check_mandate_compliance answers the only question that matters: will this domain's mail be accepted today?

Validated against RFC 9989, the DMARC standard published in May 2026 that obsoleted RFC 7489. The pct tag was removed, the Public Suffix List was replaced by a DNS tree walk, and np, psd and t were added. Records still carrying pct= are no longer conformant, and this server reports it.

Honest about its limits. DKIM selectors cannot be enumerated from DNS, so a negative result states how many names were tested rather than claiming DKIM is absent. No blocklist checks, because the major blocklist operators prohibit commercial use of their free query services. No live SMTP conversation. Every limit is stated in the output rather than buried.

Scoring uses a published, versioned rubric — every point traces to a named check and an RFC.

Three tools: audit_domain, generate_report, check_mandate_compliance.