@Mail Domain Check

Diagnostic help

Using the free checks

Run bounded public-DNS and HTTPS-policy checks without an account, mailbox access, or DNS credentials.

Open domain check

Use exact inputs

Domain
Enter a bare domain, full HTTP(S) URL, or mailbox; the scanner extracts only the normalized domain. Public IPs are routed to the PTR check.
DKIM selector
Optional. Use a real selector from the sender configuration or a delivered message header; the tool does not guess.
Sending IP
Optional. Use the actual public SMTP outbound IPv4 or IPv6 address for PTR and forward confirmation.
Data source
The service reads current public DNS and the fixed MTA-STS HTTPS policy path.

Interpret results conservatively

A pass means the observed public configuration met that check. It does not prove inbox placement, sender reputation, message safety, user consent, or future availability.

A DNS or HTTPS lookup error is reported as inconclusive instead of being treated as a missing record. Recheck later before changing production configuration.

Security and data boundaries

  • The tool and assisted-remediation case never need a mailbox password, DNS credential, private key, wallet recovery words, verification code, API key, or message body.
  • Free analytics retain irreversible hashes and aggregate metrics, not raw domains or sending IPs.
  • A pasted email header is analyzed locally in the browser by the separate header tool.
  • Results intentionally omit raw records, public-key material, and report destinations.

Paid report and delivery

The free check requires no payment. Scan results offer two one-time purchases: the 1 USDC self-service report includes complete evidence, prioritized actions, and 30 days of rechecks; the 29 USDC assisted-remediation option adds an independent provider-event or SMTP review, provider-specific DNS steps when relevant, a private in-app case, and one post-fix verification. Both accept only native USDC on Base Mainnet at contract 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913.

CSV, JSON, and JSONL analysis in the AI Agent Cost Leak Auditor also runs locally for free. Its optional 1 USDC private report adds a prioritized cost-remediation order plus Markdown and CSV exports. Checkout sends only aggregate usage after agent and feature names have been replaced with local aliases; raw logs, prompts, messages, and credentials are not submitted.

Assisted remediation does not take implementation ownership, log into, or take control of a customer's DNS account. The customer keeps every code and configuration decision and applies changes in their own console; the service supplies the evidence review, navigation, and public-result verification in the same case. Never submit credentials or secrets.

Each order has a unique receiving address. The service verifies the recipient, token contract, exact product amount, and transaction uniqueness, then delivers only after the transaction reaches Base finalized status. Pending sessions are retained for 7 days. For 30 days after payment, the private recovery link retrieves the report or assisted-remediation case. An email report reruns the same-domain check after DNS changes; a cost report does not read or refetch raw usage data. Keep the browser-fragment recovery link confidential.

Errors and limits

Invalid input returns a specific validation message. Rate limiting returns HTTP 429 and a Retry-After value. Temporary DNS, HTTPS, storage, or runtime failures should be retried later.