All Tools

Website Health Check

Find out if a website is safe, set up correctly, and working well — one free report covering security, email, speed, and more.

Free · No account needed · Results in about 5 seconds

Not sure if a website is safe to visit or ready to launch? Enter any website address and we'll run a structured health check — the same kinds of tests an IT consultant would run — and explain the results in plain English.

You'll learn whether the secure connection is valid, email is configured properly, the site loads at a reasonable speed, and other essentials that affect trust and reliability. Useful for business owners, bloggers, and anyone evaluating a domain before purchase or launch.

Run a quick check before go-live, after a migration, or as a routine checkup. For a deeper look, switch to a full check to include network routing and open-port tests. Read our domain health guide →

11 checks · about 5 sec

example.com github.com cloudflare.com

Ready when you are — enter a website address above to see if it's safe and set up correctly.

Common questions

Enter any domain in the box above and run a quick check. You get a plain-English report covering SSL, DNS, email setup, security headers, and page speed — usually in about 5 seconds. No account needed.

Quick check runs 11 tests: HTTPS certificate, DNS records, email authentication (SPF/DKIM/DMARC), security headers, robots.txt, ads.txt, page speed, and more. Full check adds network routing and open-port tests.

Yes. No signup, no credit card, no usage limits beyond a fair rate limit (20 checks per minute). Results are generated in real time and not stored on our servers.

Yes. After a check completes, use the share button to copy a link with the domain pre-filled — useful when sending results to a client or colleague.

What the Website Health Check covers

Unlike a single-purpose tool, the Website Health Check runs a coordinated audit across multiple layers of your site: HTTPS certificate validity, DNS configuration, email authentication (SPF, DKIM, DMARC), security response headers, robots.txt presence, ads.txt if applicable, and page load performance. A full check adds network routing and open-port visibility for deeper infrastructure review.

Each finding is explained in plain English — not just raw technical output — so business owners, freelancers, and IT teams can act on the report without decoding jargon first. We built this because real outages rarely sit in one silo: DNS can look fine while MX is broken; SSL can be valid while HSTS is missing; the homepage can load while email is silently failing SPF.

How we grade findings (our methodology)

Every module returns evidence from a live probe — not a scraped third-party scoreboard. Severity is assigned by impact on visitors or mail flow:

  • Priority / critical — visitors cannot trust the site (expired or mismatched SSL), or mail cannot route (missing/broken MX), or authentication is absent where the domain sends mail (no SPF when MX exists).
  • Warning — configuration drifts that raise risk soon: certificates under ~30 days, incomplete DMARC, weak TLS versions still offered, contradictory DNS across common resolvers.
  • Info / recommendation — hardening and polish (extra security headers, robots clarity, performance headroom) that do not take the site offline today.

We deliberately avoid a single vanity “score out of 100” that hides what broke. A brochure site and a payment portal have different risk profiles; the report lists what failed, why it matters for your use case, and what to change. For the full grading rationale, read How We Grade Website Health.

When to run a health check

  • Before launch — confirm SSL, DNS, and email are configured before you announce the site publicly.
  • After a migration — hosting or CDN changes often break MX records, redirects, or certificate chains while the HTML still looks fine.
  • After buying a domain — verify the seller transferred clean DNS and no stale records remain.
  • After agency handoff — get an independent snapshot before you pay the final invoice.
  • Quarterly maintenance — certificates expire, headers drift, and email auth policies change over time.

How to read your report

The report opens with an overall assessment and priority issues ranked by severity. Priority issues affect security, email deliverability, or availability now. Other findings are improvements worth scheduling but not emergencies. The action checklist at the end summarizes concrete next steps you can assign to a developer or handle yourself if you manage DNS.

Technical evidence is available for each module if you need to share raw data with a hosting provider or registrar. Re-run after changes — DNS TTL and CDN cache mean the public view can lag your edits by minutes to hours. See How to Read a Website Health Report for a section-by-section walkthrough.

Common problems we see

  • Expired or mis-matched SSL certificates after a CDN switch (edge valid, origin expired — or the reverse)
  • Missing DMARC record leaving the domain open to spoofing
  • SPF records that include too many senders and fail the 10-lookup limit
  • No HSTS header, leaving users vulnerable to protocol downgrade on first visit
  • A records updated to the new host while MX still points at the old mailbox server
  • Slow TTFB from an unoptimized origin that looks “fine” on Wi‑Fi near the data center

Example scenario

A small business moved from shared hosting to Cloudflare. Their site loaded fine in a browser, but email stopped working. A health check revealed the MX records still pointed to the old host while A records already pointed to Cloudflare. Fixing MX in the DNS panel restored mail within an hour — something a single SSL check would never have caught. Similar “split brain” failures show up after registrar transfers and after agencies flip only the web records.

For a step-by-step recovery playbook when mail breaks after DNS changes, see Fix Email After a DNS Migration.

Quick vs Full check

Quick covers the layers most site owners need day to day: TLS, DNS, email auth signals, security headers, robots/ads.txt, and basic performance. Full adds traceroute-style path insight and common-port visibility from our infrastructure — useful when you suspect firewall or routing issues, not when you only need to know if HTTPS and MX are sane.

Limitations

Results reflect a point-in-time snapshot from our servers. Some checks depend on public DNS and remote endpoints responding normally. We do not store your domain or results. Port and traceroute checks in full mode only scan common ports from our infrastructure — not a substitute for authenticated penetration testing. Always verify critical changes with your hosting provider and re-check after TTL expiry.

Related resources

Read How We Grade Website Health, How to Read a Website Health Report, How to Audit a Website Before Launch, or run individual checks: SSL Checker, DNS Lookup, MX Validator, Security Headers.