Rejuvenate IT Logo

Find out what your domain is telling the world

Your domain does more than point at your website. It decides whether an email claiming to be from you reaches a customer’s inbox, whether your certificate is still valid, and whether somebody could move the whole thing to another registrar without asking you first.

Most businesses have never looked. Put your domain in below and we will read the public records, then tell you plainly what is right, what is worth tightening up, and what needs attention today.

Check your domain

Type your domain on its own — the part after the @ in your email address. If you paste a full web address we will trim it down for you.

Run a health check

Enter your domain and we will read its public records. Your report appears below in a few seconds.

We only read public records. Nothing is changed, and we do not need any access to your domain.

What the report tells you

Ten checks, in plain English, with a score out of 100 and a letter grade so you can see at a glance where you stand. Anything broken is listed first.

Can somebody send email pretending to be you? We read your SPF and DMARC records, the two that decide whether a forged email from your domain is delivered. A DMARC record set to “none” is the common trap: it looks like protection and does nothing at all, and the report says so rather than ticking a box.

Is your mail signed, and where does it go? We look for DKIM signing keys on the selectors the common mail providers use, name the provider handling your mail, and check whether anything requires mail to your domain to travel encrypted.

Could you lose the domain itself? We ask the registry when it expires, whether the transfer lock is on, and whether DNSSEC is signing your DNS answers. A domain with the lock off can be moved to another registrar without your involvement, which is how domains get stolen.

Is your certificate valid? We open the same connection a browser would and read the certificate your site serves — who issued it, when it expires, and whether it actually covers your domain.

Has your business been in a known breach? We match your domain against the public record of breached organisations, so you know whether your company is on a list your team should have heard about.

Why any of this matters

Because the damage does not look like a hack. It looks like an invoice.

With nothing stopping it, anyone can send an email that appears to come from your domain — to your customers, your suppliers, or your own finance team. It arrives looking entirely normal, because as far as the receiving server is concerned it is normal. Nothing on your network has been touched, so nothing on your network raises an alarm.

The rest of the list is quieter and no less expensive. An expired certificate replaces your website with a browser warning. A domain that lapses can be suspended, and then registered by somebody else. IT interruption costs UK businesses an average of £3,500 an hour, and none of these need an attacker to set them off. A card that expired on a renewal is enough.

None of it appears on a cyber insurance proposal form by name, but it is the same class of question: can you say, with evidence, that the basics are done? Our guides on what insurers now ask about your IT and what Cyber Essentials actually is cover the ones that do.

What happens if you want it fixed

We fix the records, not just list them

Moving DMARC from monitoring to enforcement without stopping the mail you actually send. That is the order the job has to be done in, and it is where most attempts come unstuck.

We watch it once it is right

150+ automated checks every hour, round the clock. A certificate that quietly fails to renew, or a record edited during a migration, is the kind of thing we would rather catch on a Tuesday than on a Monday morning.

You get a human on the phone

A 15-minute average response time, and engineers based in Bournemouth who are out on site across Dorset and Hampshire. No menu tree, no account number read to a stranger.

We will tell you if it is already fine

Plenty of domains come back with nothing that needs doing. If yours is one of them we will say so, point out the line or two worth tightening at some point, and leave it there.

What this check cannot tell you

It reads public records. That is a real limit, and it is worth knowing where it sits.

It cannot tell you whether anyone’s password has leaked. The breach line asks whether your company’s own domain appears in the public record of breached organisations. It does not ask whether your team’s addresses turn up in somebody else’s breach. Those are different questions, and only the first can be answered without proving you own the domain.

A blank on DKIM does not mean you have none. DKIM keys live at names that cannot be listed, so all anyone can do is try the common ones. The report says it found nothing on the usual selectors rather than saying DKIM is missing, because the second would be a claim we cannot make.

It does not name your domain’s owner. UK and .com registries stopped publishing that, so only your registrar can confirm who holds it — which is worth finding out, and a surprising number of businesses cannot.

And it says nothing about your website, your network or your mailboxes. It looks at your domain from the outside, in the same way anybody else on the internet could.

Questions people ask

Do I have to give you my details to run the check?

No. Type a domain, read the report, close the tab. The form further down is there if you want help with what it found — it is not a gate in front of the results.

Can I check a domain that is not mine?

Yes. Everything the check reads is published for anyone to look up, so there is nothing to authorise, nothing is changed and nobody is notified. There is a limit of ten checks an hour from one visitor, which is more than anybody needs in a sitting.

It says our DMARC is set to "none". Is that bad?

It means your DMARC record is monitoring and doing nothing else. Forged email claiming to be from your domain is still delivered as normal. Moving to “quarantine” and then to “reject” is what actually stops it, and it needs doing in that order so you do not block your own mail on the way.

Nothing was found for DKIM. Have we got a problem?

Probably not. DKIM keys are published at names that cannot be listed, so the check tries the seventeen selectors the common mail providers use. A custom selector is invisible to it. Treat a blank as “we could not tell” rather than as a fault.

There is no registry information in our report.

Some registries publish lookup data and some do not. Where yours does not, the expiry, transfer lock and DNSSEC lines come back as unknown and the rest of the report runs as normal. The email findings, which are the ones that matter most, do not depend on the registry at all.

How current is the result?

It is checked live, then held for six hours so a second look at the same domain does not go back to the registries. If you have just changed a record, give it that long before expecting the report to agree with you — DNS changes take their own time to spread regardless.

Tell us what the report said

Send us your domain and the lines you want explaining — or just the grade, if the report raised more questions than it answered.

We will come back within one working day with what each finding means for your business, what it would take to put right, and which of them genuinely matter for a business your size. If your domain is already in good shape, we will tell you that instead.

"*" indicates required fields