One lookup,the whole domain picture

Certificate, registration, DNS, email posture, server speed, hosting, history and public subdomains — every clock a domain runs on and every signal it gives off, checked in one pass. See what lapses first.

5 free checks a day. No signup, no key.

Try one:

Certificate & registration

TLS expiry and WHOIS registration in one glance.

DNS, email & server

Records, SPF/DKIM/DMARC, and a live response check.

Hosting, history & subdomains

IP, ASN, archive history, and public certificate names.

§ 01 — The checks

What each check tells you

Eight different systems, eight different failure modes, and usually eight different people who forgot they own one of them.

Clause 01

TLS certificate

Read straight off the live handshake on port 443: who issued it, when it expires, and how many days remain. An expired certificate does not degrade gracefully — browsers refuse the connection outright.

Renew at 30 days remaining. Automated renewals fail quietly more often than anyone expects.

Clause 02

Registration (WHOIS)

The registrar of record and the registration expiry date. This is the clock that ends the domain itself, not just the encryption, and it usually renews on a card someone replaced two years ago.

Some registries hide or rate-limit this data. A blank result means "not published", not "not registered".

Clause 03

DNS records

The A and AAAA addresses the domain resolves to, any CNAME alias, the MX records mail is routed through, and the authoritative NS records — plus TXT, CAA and SOA for the full zone picture.

Useful right after a migration: it shows what the world sees, not what your control panel claims.

Clause 04

Email security

Whether SPF, DKIM and DMARC are set up — the three records receiving mail servers check before trusting anything sent from the domain.

Missing DMARC means anyone can send mail that claims to be you, and inboxes have no instruction to reject it.

Clause 05

Server

A live request to the site itself: how fast it answers, what status it returns, which HTTP version it speaks, and what software it admits to running.

Slow here is slow everywhere — this is the floor under every page load the site will ever do.

Clause 06

Hosting

The public IP the domain resolves to, the country and city it sits in, and the network (ASN) that actually operates it.

Answers the "who do we even call" question when a site is down and the owner has long moved on.

Clause 07

History

The first and most recent captures of the site in the Internet Archive, next to the registration date from the registry itself.

A domain registered last month claiming ten years of business is a red flag you can check in one glance.

Clause 08

Subdomains

Public hostnames collected passively from Certificate Transparency logs, without probing the target.

Useful for finding forgotten dashboards, mail hosts and old environments still covered by public certificates.

§ 02 — Why trust the numbers

Built on live sources, not guesses

Live RDAP & Certificate Transparency

Registration and certificate data come from real-time RDAP and CT lookups — not a cached WHOIS scrape.

SSRF-guarded by design

Every server check, including redirects, is re-validated against a public-IP guard before it's contacted.

Typed failures, not silence

A 5-second upstream timeout and typed errors mean a slow registry shows up as a timeout, not a blank 500.

§ 03 — Pricing

Same checks, as an API

This page is one call to a public API. If you watch more than a few domains, wire it into whatever already pages you.

Start hereFree tier
$0
  • Certificate, registration, DNS and more
  • One call returns every check
  • Enough for a personal portfolio
Paid tiers
Usage-based
  • Higher monthly quotas
  • Same endpoints, same JSON
  • Billing handled by RapidAPI
Built in
Sane defaults
  • 12-hour result cache
  • 5-second upstream timeout
  • Typed errors, not blanket 500s
See plans on RapidAPI →
§ 04 — Questions

Questions

Is this really free?

The page is. You get 5 checks per day from your IP address, with no account and no key. Past that, the API's own free tier picks up where this leaves off.

Why does the registration section sometimes come back empty?

Registries differ. Some publish full WHOIS data, some redact it under GDPR, and some rate-limit queries. An empty registration block means the registry did not return data — it does not mean the domain is available.

Does it check subdomains and internal hosts?

Subdomains, yes. Hosts that resolve to private or loopback addresses are refused on purpose, so this cannot be used to probe networks it has no business touching.

How fresh are the results?

Results are cached for 12 hours per domain. Certificate and registration dates move on the order of months, so a same-day cache costs you nothing and keeps upstream registries from rate-limiting everyone.

What counts as "expiring soon"?

Under 14 days is flagged amber, and anything already past its date is red. Certificates are the usual culprit: most automated renewals fire at 30 days, so 14 days remaining means a renewal has already failed twice.

Check the next domain before it lapses

Same certificate, registration, DNS, email, server, hosting, history and subdomain checks — free, no signup, results in seconds.