SPF Record Checker
Resolve the full include and redirect chain, count DNS lookups against the 10-lookup limit, and find duplicate mechanisms, void lookups and weak terminal policies.
Free domain tools
Every public CloudSpex checker in one place, grouped by the question it answers — from who may send email as your domain to whether a validating resolver still accepts your DNSSEC chain.
Each tool applies deterministic scoring to real measurements and says plainly when something could not be assessed. No signup required.
Who may send mail as your domain, and what receivers do when a message fails.
Resolve the full include and redirect chain, count DNS lookups against the 10-lookup limit, and find duplicate mechanisms, void lookups and weak terminal policies.
Fetch the DKIM record for a selector you know, interpret its tags, and see whether the public key is present, revoked or malformed.
Inspect the published policy, see how none, quarantine and reject differ in practice, and find records receivers cannot interpret.
The combined view: MX, SPF and DMARC measured together with one score, so you can see which part of the mail setup needs attention first.
Read the BIMI record, see whether a logo and verified mark certificate are declared, and whether DMARC enforcement is strong enough for the logo to show.
Whether mail to your domain travels over TLS, and how delivery problems get reported.
Read the _mta-sts record, fetch the actual policy file, and report the real mode — a published record alone enforces nothing.
Check the _smtp._tls record, list the reporting destinations, and find records that are published but cannot receive a single report.
The layer everything else stands on: resolution, delegation, signing and issuance control.
Test whether the domain resolves at all and separate DNS root causes from the SSL and HTTP failures they masquerade as.
Check whether the zone is signed and whether a validating resolver accepts the chain — including the broken state that makes a domain unreachable for most users.
Ask every delegated nameserver directly, find lame delegation, and see when servers disagree about the same zone.
See which certificate authorities may issue for the domain, and find CAA policies that accidentally block all issuance.
What a visitor's browser actually gets: the certificate, the protocols and the response headers.
One read-only handshake: certificate validity and expiry, SAN coverage, chain state, negotiated cipher and which TLS versions the server accepts.
Review CSP, HSTS, framing protection, cookie flags, CORS and the rest of the response-header allowlist, with what's missing stated plainly.
One-time checks answer today's question; monitoring catches tomorrow's change.
DNS, SSL and HTTPS measured together with a single score and the failing layer identified — the widest one-time view of a domain.
The quickest entry point: a limited public scan of SSL, DNS and HTTPS health, with a path to continuous monitoring when you need history.
Yes. Every checker on this page runs without an account. Rate limits apply per visitor so the tools stay available for everyone.
Each checker applies a fixed, deterministic rule set, so the same configuration always produces the same score. Components that could not be measured are excluded from the score instead of being counted as failures.
When a lookup times out or a signal cannot be verified, CloudSpex reports 'not assessed' rather than guessing. An unmeasured component is not the same as a failing one, and the reports keep that distinction visible.
A checker answers today's question: how is this domain configured right now? CloudSpex monitoring re-measures your domains continuously and alerts you when the configuration drifts, so the next change does not go unnoticed.
These checkers show a domain as it is right now. CloudSpex monitoring re-measures your domains continuously — SSL expiry, DNS changes and email security signals — and alerts you when the configuration drifts.