SSL Certificate Check: Verify Any Website's Security in Seconds
An SSL certificate check tells you whether a website's HTTPS connection is properly configured.
Try a product, outcome, endpoint path, or API topic.
DomScan
Guides, product updates, domain research, DNS explainers, and technical breakdowns from DomScan.
An SSL certificate check tells you whether a website's HTTPS connection is properly configured.
IP reputation determines whether your email reaches the inbox or gets silently dropped. This guide explains how DNS-based blacklists work at the protocol level, which lists matter most, and how to check, delist, and prevent future listings.
DomScan's deprecated Reverse MX API searches a short-lived cache built from prior DNS lookups. Learn exactly what a result means, where gaps come from, and how to verify each lead.
Reverse IP lookup is a dataset query, not a PTR lookup. This guide explains what DomScan's deprecated seven-day observation index can and cannot show for IPv4 and IPv6 addresses.
The phrase "IP tracker" suggests you can follow someone's movements in real time. That is a movie myth. IP geolocation maps addresses to approximate locations using BGP routing data, active latency probing, and crowdsourced ground truth.
Every network interface has a 48-bit MAC address burned in at the factory. The first three bytes — the OUI — identify the manufacturer.
A domain's expiry date is not a universal drop date. This guide explains the gTLD baseline, registrar variation, ccTLD exceptions, recovery states, transfer risks, and practical renewal controls.
RDAP is now definitive for contracted gTLDs, but WHOIS still matters for three gTLD exceptions, many ccTLD workflows, and compatibility. This guide separates protocol, policy, coverage, and DomScan endpoint behavior.
DomScan's WHOIS API is RDAP-first, with traditional WHOIS and DNS fallbacks where coverage requires them. This guide documents the live endpoints, response sources, cache behavior, costs, privacy limits, and error handling.
ICANN's current policy separates public from nonpublic registration data. This guide explains redaction, privacy and proxy services, RDRS, RDAP, and the limits of domain lookups.
A sourced comparison of SecurityTrails, WhoisXML API, DomainTools, Shodan, and DomScan, with the limits of each product made explicit.
Historical registration snapshots can show when a registrar, nameserver, status, or expiry date changed. This guide explains what those observations prove, what they do not, and how DomScan coverage works.
A WHOIS domain search no longer means querying one plaintext directory for a website owner. For generic domains, RDAP is now the definitive source, and the public result usually describes registration state rather than personal identity.
IP registration data identifies the network holder and operational contacts for an address range. It does not identify a cloud customer, physical server, or individual user.
RDAP is now the definitive source for gTLD registration data, while WHOIS remains in a smaller legacy role. Learn to read dates, status codes, nameservers, DNSSEC, and privacy signals without treating them as proof of ownership.
TXT records started as a place for human-readable notes in DNS. They now carry the machine-critical data that decides whether your email arrives, your domain is verified, and your security policies are enforced.
A records map hostnames to IP addresses. CNAMEs alias one hostname to another. The choice between them determines how CDN routing, SSL issuance, email delivery, and DNS migrations actually behave in production.
NS records are the delegation chain of DNS. Get them wrong and your entire domain goes dark. Here is how to check, diagnose, and fix nameserver configuration problems before they become outages.
When you send an email, your mail server queries MX records to find which servers accept mail for the destination domain. This guide explains MX priority, fallback chains, common configurations, security implications, and troubleshooting.
DNS server means different things depending on context. This guide breaks down the four types, compares public resolvers, walks through configuration on every major OS, and covers troubleshooting and security.
A DNS leak exposes every domain you visit to your ISP, even when you think a VPN or encrypted resolver is protecting you. Learn what causes DNS leaks, how to test for them, and how to fix them permanently.
A deeper account of what an IP address can reveal through allocation records, BGP, RPKI, geolocation, and DNS, plus the effects of anycast, NAT, VPNs, and reassignment.
A DNS result is one observation, not proof of global propagation. Learn how to check authority, delegation, caches, DNSSEC, and real client paths without overclaiming.
Every URL you visit starts with a DNS lookup that finishes in under 100 milliseconds. This guide walks through the full resolution chain, record types, caching, common errors, and security signals.
A practical guide to DomScan IP results: geolocation estimates, ASN context, PTR and FCrDNS, security flags, raw RDAP follow-up, and the limits of reverse IP evidence.
Domain valuation is part language, part market context, and part buyer fit. This guide explains what actually drives domain value and how to interpret automated appraisals realistically.
Bulk WHOIS work is less about sending thousands of queries than about turning inconsistent registration data into something you can actually analyse. This guide explains how to do that well.
Good domain monitoring starts with clear ownership and reliable registration checks. Learn what to automate, what to review separately, and how DomScan fits.
Domain loss is usually an ownership and process failure long before it becomes a registrar-date problem. This guide explains how to monitor critical domains so they do not quietly slide toward lapse.
Cybersquatting is a legal and operational problem. This guide explains what actually counts as cybersquatting, when UDRP is the right path, and how to prepare stronger recovery evidence.
Domain reputation is the accumulated trust judgment attached to your domain identity. This guide explains what feeds it, how it degrades, and what operators can do to improve it without chasing myths.
Attack surface management is the work of turning forgotten internet-facing assets into observable, owned, and prioritised risk. This guide explains how domain-led discovery makes that possible.
Typosquatting is a trust-abuse problem disguised as a naming problem. This guide explains how attackers use typo variants, why they matter operationally, and how defenders can reduce the risk.
Wildcard and multi-domain certificates solve different trust-scope problems. This guide explains the coverage, operational tradeoffs, and blast-radius implications behind each model.
Certificate monitoring should cover trust drift, deployment mistakes, and unexpected issuance, not merely one date on a calendar. This guide explains how to build a monitoring routine that prevents outages.
Browsers trust chains, not isolated leaf certificates. This guide explains roots, intermediates, and why certificate trust fails in production even when a certificate looks “valid.”
DNS history can reveal changes in observed records, but only when you understand the dataset. Learn how to investigate timelines without treating clues as proof.
Reverse DNS is more than a curiosity in a mail header. This guide explains how PTR records work, why reverse lookups matter for mail and investigations, and where teams misread them.
DNS propagation is not one global timer. It is the practical effect of caches, TTLs, resolver behaviour, and where the change was made. This guide explains what actually determines visibility after a DNS update.
DNS records are easy to define and much harder to operate well together. This guide explains the major record types, what question each one answers, and where teams create avoidable confusion.
Business email security sits at the intersection of domain identity, workflow trust, and brand protection. This guide explains how to build controls that reduce spoofing, impersonation, and payment-risk exposure.
SPF becomes fragile when it turns into a dumping ground for vendors. This guide explains how to keep sender authorization records within limits and maintainable as the mail stack grows.
Deliverability is easier when domain identity is boringly coherent. This guide explains how SPF, DKIM, and DMARC influence receiver trust and why weak authentication makes inbox placement harder.
DMARC reports are useful only when they become operational decisions. This guide explains what aggregate reports actually show, how to triage them, and how to use them for policy rollout.
SPF, DKIM, and DMARC are not separate checkboxes. They form one operating system for mail identity, authorization, and policy. This guide explains how the stack works and how to deploy it safely.