Domain infrastructure · resolver evidence

Inspect DNS, SPF, DMARC, mail, and CAA records

Query address, alias, nameserver, mail, TXT, certificate-authority, and DMARC records together. Review exact TTLs, resolver status, authenticated-data bits, policy records, and bounded syntax observations without a manufactured domain score.

QUERIESEIGHT RECORD SETSRESOLVERCLOUDFLARE 1.1.1.1EXPORTCSV + JSON

Runs encrypted public DNS queries only. OpenWebmaster does not connect to the domain’s mail server or change DNS.

DNS

Ready for a domain.

No example records, DNS grade, security score, or generated policy is shown. Results begin with the live resolver response.

Deployment practice

Treat DNS and mail policies as exact, versioned configuration

Verify every environment

Resolver caches, delegation changes, and staged rollouts can expose different answers over time. Save the timestamped export beside deployment records.

Keep one policy record

Multiple SPF or DMARC policy records are not combined into a stronger policy. Consolidate intentionally and retest before publishing.

Test downstream behavior

A syntactically reviewable record does not prove mail alignment, delivery, aggregate-report authorization, DNSSEC delegation, or certificate issuance behavior.