dotvitals

About dotvitals

dotvitals is a free, no-login diagnostic tool for domains and websites: one input, a full report across DNS, email authentication, TLS, HTTP security headers, WHOIS/RDAP, ports, performance and SEO.

Last updated

What dotvitals does

You give dotvitals a domain, a URL or an IP address and it runs a set of read-only checks against it: DNS records and DNSSEC, email authentication (SPF, DKIM, DMARC, BIMI, MTA-STS, TLS-RPT), TLS certificate and protocol configuration, HTTP security headers and cookies, common open ports, WHOIS/RDAP registration data, page performance measured by loading the page in a real browser, and basic SEO signals.

Each finding is explained in plain language first, with a technical layer underneath for people who want the detail, and most findings link to a generator that produces the DNS record or header value needed to fix them.

Every individual check (SPF checker, DNSSEC checker, port checker, and so on) is also available on its own page under Tools, so you do not have to run a full report to look up one thing.

The email header analyzer is the one tool that works differently: it runs entirely inside your browser, and the headers you paste never reach a server of ours at all. The privacy policy explains what that means.

What it deliberately does not do

dotvitals only runs checks that are equivalent to things a browser, a mail server or a normal DNS client already does when they interact with a site: DNS lookups, an HTTP GET of the homepage, a TLS handshake, an SMTP EHLO, a connect-only probe of a short list of common ports.

  • It never attempts to exploit a vulnerability, brute-force credentials or directories, or send test emails to anyone.
  • It never scans arbitrary port ranges or crawls more than a handful of pages without the target owner verifying ownership first.
  • It never targets internal, private or cloud-metadata addresses; every resolved address is validated before any connection is made, and the probe host's own firewall refuses the same ranges a second time.

The full detail of what is probed, which addresses our traffic comes from, and how a server owner can ask about or opt out of being checked lives on the scanner policy page.

How dotvitals is funded

dotvitals is free to use, with no account required for the checks described above. Running the scanners, the edge infrastructure and the outbound probing has an ongoing cost, and the plan is to cover that cost with advertising rather than a paywall or a subscription.

At launch, no advertising is enabled. There are no ad scripts loaded, no ad network cookies set, and no consent banner shown, because there is nothing yet that needs consent. This is stated plainly here so it does not need to be taken on trust: you can verify it in your browser's network tab on any page today.

When advertising is enabled, it will be placed only around content — never between the input box and your first result, never on loading, error or empty-state screens, and never on the email header analyzer page. Ads targeted to visitors in the EU, UK and Switzerland will only load after a consent choice, through a consent dialog reachable at any time from the footer and described on the cookie policy page.

dotvitals does not sell access to scan data, does not sell the list of domains people check, and does not use the domain you submit as an advertising signal.

Who runs dotvitals

dotvitals is run as a single project rather than a large company. The people building it read every page you see here, and the abuse and contact addresses on the contact page reach a real person.

TODO (owner): this section needs the operator's legal identity filled in before launch — the legal entity or sole-trader name operating dotvitals, its registered address, its jurisdiction of incorporation or residence, and a company/VAT registration number if applicable. Until this paragraph is replaced with that information, this page must not claim any specific company name, address or registration status, and the site should not be treated as launch-ready in jurisdictions (for example Germany or Austria) that require an Impressum with this information.

Accuracy and scope

dotvitals reports what its checks observed at the time they ran. DNS, TLS and HTTP configurations change, propagation takes time, and some checks are served from a short-lived cache rather than a fresh probe — the result page always shows when a result was captured.

When a check could not run, dotvitals says so instead of reporting a pass. A module that failed is reported as untested, with the reason, and the rest of the report is still shown.

A clean report is not a security guarantee and a failing check is not proof of an active problem; both are inputs to your own judgment, not a substitute for it. See the terms of service for the full disclaimer.

Where to go next

  • Read the scanner policy before scanning a domain you do not control.
  • Read the privacy policy to see exactly what is stored about a scan and for how long.
  • Use the contact page for general questions, corrections, takedown requests or abuse reports.
  • Report a security issue in dotvitals itself through /.well-known/security.txt.