Domain registration and DNS
domain_checkCheck domain registration expiry, registrar, DNS records, nameservers, DNSSEC, SPF and DMARC to see if a domain is lapsing, misdirected, or spoofable.
Instructions
Reports when a domain registration expires, who the registrar is, and how the domain is configured in DNS — nameservers, address records, mail exchangers, TXT and CAA records, whether the delegation is signed with DNSSEC, and what its SPF and DMARC records say about who may send email as it.
Use it to answer "is this domain about to lapse?", "who do we renew this with?", "where does this domain point?" or "why does the apex not work when www does?". It is the right first call when a site has gone dark for no obvious reason.
Use it too for "why is this client's email going to spam?" or "can someone spoof this domain?" — SPF and DMARC are read from the domain's own DNS.
It also asks each of the domain's own nameservers, directly, whether they agree about the zone. That answers "why does this site work for some people and not others?" and "is this old nameserver still in the delegation?" — a question no recursive resolver can answer, because it replies with whatever one server told it and does not say which. Pass checkNameservers: false to skip it.
Do not use it to check whether a website responds — that is uptime_check — or to inspect an SSL certificate, which is ssl_check. It reads only what registries and DNS publish. It reports no DKIM: finding a DKIM key needs its selector, and a selector cannot be discovered without guessing at names, which this project will not do.
Registration data comes from RDAP. Some country registries (.de, .nl, .no, .au, .fi) publish no expiry date at all; the result says so explicitly rather than reporting a gap as if it were an unknown. An expiry inside 30 days is reported as a warning and inside seven days as critical — a manual renewal needs that much lead time. Returns findings ordered by how much attention they need, worst first.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| domain | Yes | The domain to check, e.g. "example.com" — no scheme, no trailing slash. A full URL such as "https://example.com/pricing" is also accepted and reduced to its hostname. Internationalised names ("café.pt") are accepted and converted automatically. Registration is a property of the registrable domain, so "www.shop.example.co.uk" is checked as "example.co.uk". | |
| checkNameservers | No | Whether to ask the domain's own nameservers whether they agree about it, which no recursive resolver can answer. Costs one DNS query over TCP to each nameserver the domain publishes, in parallel, and finds a server left in the delegation that no longer serves the zone and a zone edited on one server and never transferred to the others. Defaults to true. Set false to skip it — the rest of the check is unaffected. Example: false |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| dns | Yes | DNS records for the registrable domain. | |
| Yes | Email authentication, read from the domain's own TXT records. DKIM is not reported: finding a DKIM key needs its selector, which cannot be discovered without guessing. | ||
| dnssec | Yes | Whether the delegation is signed. This is not a validation of the DNSSEC chain. | |
| domain | Yes | The hostname that was checked, in ASCII (punycode) form. | |
| findings | Yes | What needs attention, worst first. | |
| severity | Yes | How much attention this needs. "critical" means act now; "warning" means act this month; "unknown" means the check could not establish the fact, which is not the same as it being fine. | |
| checkedAt | Yes | When the check ran, ISO 8601 in UTC. | |
| dnsResolved | Yes | Whether the DNS lookup answered at all. When false every field under "dns" is empty because nothing could be read, not because the domain has no records. | |
| nameservers | Yes | What the domain's own nameservers said when each was asked directly, over TCP port 53 with recursion off. This is the only way to see a nameserver left in the delegation after a migration, or a zone edited on one server and never transferred to the others; a recursive resolver answers with whatever one server told it and hides which. | |
| registration | Yes | What the registry publishes about this registration. | |
| unicodeDomain | Yes | The Unicode form when the domain is internationalised, otherwise null. | |
| registrableDomain | Yes | The domain registration was checked against, e.g. "example.co.uk". |