Domain Checker: DNS, HTTP, RDAP

DNS records from two resolvers, HTTP/HTTPS statuses, redirect chains, HSTS and registration data for any domain.

Loza CRM·Updated: October 3, 2026

Quick answer

Enter a domain — get DNS records from Google and Cloudflare with disagreement flags, HTTP/HTTPS and www statuses, the full redirect chain, HSTS and RDAP data: registrar, creation and expiry dates.

How to use

  1. Enter a domain (a full URL works too — the host is extracted)
  2. Complete Turnstile and run the check
  3. DNS: every record type from two independent resolvers — disagreements highlighted
  4. HTTP/HTTPS and www: statuses, redirects, HSTS, server header
  5. RDAP: registrar, age and expiry — a week-old domain in affiliate traffic is a flag

Why you need it

Before sending traffic to someone else's domain — a broker's landing, a redirect partner, a PBN — a quick technical health check pays off. This tool runs it in one request: seven DNS record types through DNS-over-HTTPS at both Google and Cloudflare (resolver disagreement signals a fresh migration or partial DNS failure), HTTP and HTTPS statuses, the whole redirect chain and HSTS.

The RDAP block shows the registrar, creation and expiry dates and nameservers: a domain registered last week deserves scrutiny, and one expiring next month deserves a question to the partner. The "expected IP/CNAME" field compares actual records to what you were told.

The check is built safe: the host is validated and resolved via DoH before any request to it, private-range addresses are rejected, and every redirect hop is revalidated. TLS certificate details are not available in this version — the report says so honestly instead of hiding it.

Loza CRM computes these metrics for your campaigns automatically — try it free.

Open Loza CRM

FAQ

What does "resolvers disagree" mean?
Google DNS and Cloudflare DNS returned different records — usually a fresh DNS change (caches update unevenly) or split-horizon config. For traffic that means partial availability across GEOs.
Why is there no TLS certificate data?
The backend runs on Cloudflare Workers, which has no direct TLS socket access — the certificate cannot be read honestly. It is flagged as unavailable rather than faked.
Are checked domains stored?
No. Domains are not logged or sent to analytics — only a per-IP rate-limit counter is kept.
Why was my domain rejected?
IP literals, localhost, internal .local/.internal/.lan suffixes and domains resolving to private IPs are all declined — checking those publicly is impossible and unsafe.

Other tools