What does this report check?
Two things at once, and then the gap between them. On the registration side: registrar, dates, status codes, nameservers on record, and DNSSEC delegation. On the DNS side: the parent delegation and what the zone itself actually publishes.
Check which parts completed before reading the findings. A failed or skipped check remains unresolved rather than counting as a pass.
Why do nameservers differ between the registry and DNS?
The registration record, parent DNS zone, and domain's own zone can each publish nameserver information. They describe related parts of the same delegation.
registry record → parent delegation → the zone itself
A disagreement can send queries to an unintended or unprepared server, causing intermittent answers or failures. It usually means a nameserver change was made in one place and not the other, often during a migration that looked finished.
Does DNSSEC enabled mean DNSSEC is working?
No, and the difference matters more than most DNSSEC settings. The registration record tells you whether a DS record exists, which is a delegation fact. It says nothing about whether the signatures validate.
A domain with DNSSEC switched on and a broken chain does not degrade gracefully. It stops resolving completely for everyone behind a validating resolver, while continuing to work fine for anyone who is not. That is why this report flags a signed delegation and sends you to the DNSSEC chain checker, which runs a real validator rather than reading a flag.
Why is my domain registered but not resolving?
If a domain is registered but does not resolve, check its delegation and hold statuses. If DNS answers correctly but the website still fails, investigate the web service separately.
A client or server hold can remove the domain from the published zone while its registration record still exists. Cached DNS answers may persist for a while. Missing nameservers can also prevent resolution. DNS testing shows the effect; registration status can explain the administrative reason.
Why is there no score or grade?
Because there is no single correct configuration for every domain, so a total would be inventing a standard that does not exist. A perfectly healthy domain can show several findings, and a domain scoring well can still be badly broken in a way the score never looked at.
Each finding is an observation with the evidence behind it and a link to the tool that investigates it properly. This page is for locating a problem. The focused tools are for diagnosing it.
What this report does not cover
- Website security. No TLS certificates, open ports, blocklists, headers or content checks. This is not a security scanner.
- Email deliverability. The report does not validate an email setup or test message delivery.
- Monitoring. One point in time, no history view or alerts. Registration responses may be cached.
- Anything private. No registrar account state, no hosting, no billing.
Where the checks run
The domain is sent to stack127's server, which queries registration services and DNS. It does not inspect your private network or registrar account. Registered RDAP responses can be reused for up to 24 hours, so source timestamps can differ from the fresh DNS observations.
Related tools
The DNS side has much deeper tools of its own: nameserver delegation, SOA consistency and CAA policy. On the registration side, the domain registration lookup shows the complete record and status codes explains anything the report flagged.