Domain Analyzer

Discover the free domain analyzer tool that provides measured technical facts about any domain, including HTTP response, TLS certificate, security headers.

Quick answer

A domain analyzer is a tool that reports configuration, security, and registration facts measured directly from a domain. It provides HTTP status, TLS details, security headers, DNS records, registration data, server location, and homepage analysis without offering traffic estimates or ranking figures.

This tool contacts our server. A browser cannot resolve DNS or read another host's certificate, so the domain you enter is sent to our server for analysis. Our server then queries the domain itself, its registry (RDAP) and an IP geolocation service. The result is published as a public report page.

Enter a domain such as example.com. Reports are public and cached for 14 days.

What does the domain analyzer check?

The domain analyzer examines a variety of technical aspects of a domain to provide a comprehensive report. Here are the key areas it covers:

  • HTTP Status and Performance: It checks the HTTP status code returned by the domain and measures the response time.
  • TLS Certificate Details: The tool retrieves information about the TLS certificate, including its issuer, expiry date, and any subdomains listed on it.
  • Security Headers: It identifies the presence of six common security headers: HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.
  • DNS Records and Security: The analyzer collects DNS records such as A, AAAA, nameservers, and MX records. It also checks for mail and DNS security measures like DMARC, CAA, and DNSSEC.
  • Domain Registration Information: It provides details on the domain’s registration date, registrar, expiry date, and registry status using RDAP.
  • IP Geolocation and Hosting: The tool identifies the IP location, hosting provider, and network (ASN) of the domain. Note that for sites behind a CDN, the location shown is that of the CDN edge server.
  • Webpage Structure and Metadata: It analyzes the homepage’s title, meta description, word count, and heading structure.
  • Platform and Framework Detection: The analyzer detects platform and framework fingerprints, such as WordPress, Angular, or Cloudflare.
  • Structured Data: It lists the schema.org structured data types published by the page.
  • Robots.txt and AI Crawlers: The tool checks the robots.txt rules, including whether named AI crawlers like GPTBot and ClaudeBot are allowed or blocked.
  • Sitemap Presence and Size: It verifies the presence of a sitemap and notes its size.
  • Redirects and Canonicalisation: The analyzer examines redirect behaviour and how the domain handles www and HTTPS canonicalisation.
  • Error Handling: It reports what the domain returns for a URL that does not exist.
  • Third-Party Resources: The tool identifies third-party hosts, cookies, and trackers loaded by the domain.
  • Common Trust Pages: It checks for the existence of common trust pages (about, contact, privacy, terms) at their usual paths.

How do I read the domain analyzer report?

The report is designed to be straightforward and easy to understand. Each section of the report corresponds to one of the areas listed above. For example, under “TLS Certificate Details,” you will find information about the certificate’s issuer and expiry date. Under “Security Headers,” you will see which of the six common security headers are set. The report also includes a summary of the domain’s DNS records and security measures, registration information, and IP geolocation.

What will the domain analyzer not tell me?

It’s important to note that the domain analyzer does not provide certain types of information. Specifically, it does not offer:

  • Traffic Estimates: The tool does not estimate the amount of traffic a domain receives.
  • Authority or Ranking Scores: It does not provide any authority or ranking scores, such as DA, DR, or SEO scores.
  • Keyword Data: The analyzer does not report on keyword rankings or keyword data.

These metrics cannot be determined by inspecting a domain directly. They require modelling or access to additional data sources, which are beyond the scope of this tool.

What does it mean if a site blocks the check?

When a site blocks automated checks, it responds with a challenge page or an HTTP error code like 401, 403, or 429 instead of the homepage. The report generated is labeled as blocked and does not include content from the challenge page, as it would describe the bot wall rather than the site itself. Despite this, the report still accurately reflects facts available to all visitors, including the TLS certificate, DNS records, registry registration data, and robots.txt rules.

Who finds the domain analyzer useful and for what?

The domain analyzer is useful for a variety of users and purposes:

  • Checking a Site That Emailed You: If you receive an email from a site and want to verify its legitimacy, you can use the analyzer to check its technical details.
  • Auditing Your Own Setup: You can use the tool to audit your own website’s configuration, ensuring that security headers are in place and that your DNS records are correctly set.
  • Checking if a Domain is Newly Registered: The analyzer provides registration information, which can help you determine if a domain has recently been registered.
  • Seeing if AI Crawlers are Blocked: If you are concerned about AI crawlers accessing your site, you can use the tool to check if your robots.txt rules block them.

What is the privacy position of the domain analyzer?

The tool only analyzes publicly available data that any visitor to the domain can access. It does not access any login-protected or private information. While building a report, the domain name is sent to an external domain registry via RDAP and an IP geolocation service for lookups. Reports are public and cached for 14 days. Domain owners can request report removal by emailing from their domain address.

What is the caching policy?

The reports generated by the domain analyzer are public and cached for 14 days. This means that the information in the report may not reflect the most current state of the domain if changes have been made within the last 14 days. After 14 days, the report is refreshed to ensure it contains the latest data.

Table: What is Measured vs. What is Not Provided

Measured Directly Not Provided
HTTP status code and response time Traffic estimates
TLS certificate details Authority or ranking scores
Security headers Keyword data
DNS records and security
Domain registration information
IP geolocation and hosting
Webpage structure and metadata
Platform and framework detection
Structured data
Robots.txt and AI crawlers
Sitemap presence and size
Redirects and canonicalisation
Error handling
Third-party resources
Common trust pages

Frequently asked questions

What does the tool check for a given domain?

The tool checks the HTTP status and response time, TLS certificate details, security headers, DNS and mail records, domain registration information, server location, homepage content analysis, platform fingerprints, schema.org types, robots.txt rules, sitemap size, redirect and canonicalisation, third-party hosts and cookies, and the existence of about/contact/privacy/terms pages.

What information does the tool NOT provide?

The tool does not provide traffic estimates, domain authority or ranking scores, or keyword data.

How long are the reports cached?

The reports are cached for 14 days.

What happens when a site blocks the check?

The report is still produced and labelled as blocked. Nothing is derived from the page content. The certificate, DNS, registration, and robots.txt facts are still shown because those are served to everyone.

What does the report contain about people?

The report only contains what the domain already serves publicly. No private or logged-in data is read. Building it involves querying the domain registry and an IP geolocation service.

Does building a report involve third-party services?

Yes, building a report involves contacting the domain registry over RDAP and an IP geolocation service, but it only retrieves information that is publicly available.

How does the tool handle redirects and canonicalisation?

The tool analyzes the redirect and canonicalisation behaviour of the domain, including how it handles different URL variations and whether it properly implements canonical tags.

Browse all 14 domains analysed →