Free Network Tool
What's really published in your DNS?
Enter any domain and get a full report: registration and whois details, nameservers, the records that run your website and email, and how hardened it all is — straight from your browser.
Interactive Report
Look up any domain. Right now.
The report queries the public DNS for every common record type and hostname, pulls the domain's registration data through RDAP (the modern whois), and checks the email-authentication and DNSSEC posture. Full zone transfers are restricted by design, so the zone overview below is the reconstructed view the rest of the internet actually sees.
DNS Report
Enter a domain to begin.
Registration via RDAP / whois
Email security
Zone overview reconstructed from public DNS
| Name | Type | TTL | Data |
|---|
Lookups run from your browser against Cloudflare and Google public resolvers and the registry's RDAP service. Nothing you look up is stored or sent to ETTE.
Reading the Report
Three layers decide whether your domain is safe.
Registration
Who the registrar is, when the domain expires, and whether the transfer lock is on. An expired or hijacked domain takes email and the website down with it — the lock and the renewal date are your first line of defense.
The working records
Nameservers delegate the zone, A and AAAA point the website, MX routes the mail, and TXT carries the policies. One stale record here — an old server IP, a forgotten vendor — is the classic cause of "it just stopped working."
The hardening
SPF, DKIM, and DMARC stop others from sending mail as you; DNSSEC signs your zone so answers can't be forged; CAA limits who can issue certificates for your name. Most domains are missing at least one of these.
Common Questions
DNS and whois, explained plainly.
What does a DNS report show?
It pulls a domain's registration details through RDAP, the modern replacement for whois, including the registrar, key dates, and lock status. Then it queries the public DNS for the records that run the website and email, checks the email authentication and DNSSEC posture, and assembles everything into one zone overview.
Can I see the full zone file?
Not from the outside. Complete zone transfers are restricted to a domain's own DNS servers, and that is a good thing. This report reconstructs the view the rest of the internet actually sees by querying every common record type and hostname. For a true zone export, pull it from your DNS provider's control panel.
What are SPF, DKIM, and DMARC?
They are DNS records that prove email claiming to come from your domain really did. SPF lists the servers allowed to send for you, DKIM signs each message cryptographically, and DMARC tells receiving servers what to do when a message fails both. Without all three, your domain is easier to spoof and your legitimate mail lands in spam more often.
What happens when a domain expires?
Email and the website stop working, usually within days, and after a short grace period the domain can be auctioned or released to anyone. Renewing early, enabling auto-renew, and keeping the registrar transfer lock on are the cheap insurance. This report shows the expiration date and lock status so nothing sneaks up on you.
Next Step
Found gaps in the report? We close them for a living.
ETTE manages DNS, email security, and domain portfolios for nonprofits, associations, and small businesses across the DC area. SPF, DKIM, DMARC, DNSSEC, registrar locks — we set them up, monitor them, and keep them from breaking your mail.