Domain health report
A domain name is rented, delegated and sometimes signed, and any of those layers can let you down without warning the others. This report goes through them all and lists what needs attention, most urgent first.
Three parties stand behind one name
You never own a domain. You rent it by the year, and it takes three separate parties to keep it alive.
- The registry
- The operator of the ending: Verisign for
.com, Nominet for.uk, DENIC for.de. It holds the master list of who rents which name and until when. - The registrar
- The shop where you pay: Namecheap, GoDaddy, Gandi, Cloudflare. It writes your details into the registry on your behalf.
- The DNS host
- The company running your name servers, the machines that answer “what is the address of this name?”. It’s often the registrar again, but it doesn’t have to be.
When the rent lapses, or the name servers stop answering, the website and every mailbox on the domain vanish together. Nothing has changed on your web server, so from the inside this kind of outage is baffling.
What the report tests
If you enter a subdomain, the report moves up to the registered domain, because renewal and delegation happen at that level.
| Layer | How it is read | Flagged when |
|---|---|---|
| Expiry | The registry’s RDAP record, the structured successor of WHOIS | Red under 30 days or already expired, amber under 60 days |
| Transfer lock | The status codes in the same record | No transfer prohibited status is present |
| Name servers | Each server is asked directly for the zone’s SOA record | Fewer than two servers, a server that is silent or not authoritative, or serial numbers that differ |
| DNSSEC | DS record at the registry, DNSKEY in the zone, and a validated answer from the public resolver 1.1.1.1 | A DS exists but the zone is unsigned or fails validation |
| Basics | CAA, MX, A, AAAA and the www name | No MX, no A record, or www does not resolve |
A missing CAA or AAAA record shows as optional, not as a fault. The same goes for DNSSEC that’s simply switched off.
Reading the DNSSEC line
DNSSEC adds signatures to DNS answers so that a resolver can prove nobody altered them on the way. It works as a pair. The zone publishes its public keys (DNSKEY), and the registry publishes a fingerprint of one of them (DS). A resolver checks one against the other.
- Off: no DS at the registry. The domain works exactly like most of the internet.
- On and valid: DS and keys agree, and 1.1.1.1 marks the answer as authenticated.
- Broken or Invalid: the registry still announces a fingerprint, but the zone is unsigned or signed with a different key. Validating resolvers, including Google Public DNS, Cloudflare and Quad9, then return
SERVFAIL, and as far as their users can tell the domain doesn’t exist.
That last state almost always follows a move to a new DNS host while the old DS was left behind at the registrar. Half-enabled DNSSEC is worse than none, so treat it as an outage.
Fixing what turns up
- Expiry close. Renew now, turn on auto-renewal, then check that the card on file and the contact email still work. Most lost domains had a renewal reminder sent to a mailbox nobody reads anymore.
- Not locked. Look for “Transfer lock”, “Domain lock” or “Registrar lock” in the registrar panel. It sets
clientTransferProhibitedand costs nothing. - A silent name server. If it belongs to a previous host, remove it from the list at the registrar. Resolvers pick among the listed servers, so one dead entry makes a share of lookups slow or fail.
- Serial numbers out of sync. A gap of a few minutes after an edit is normal. If it lasts an hour, the secondary server has stopped copying the zone and it’s time to contact the DNS host. A domain deliberately split between two DNS providers shows two serials all the time, and that’s expected.
- Broken DNSSEC. Either delete the DS record at the registrar, or sign the zone at the new DNS host and paste its DS values in. Don’t leave the old fingerprint in place.
- No mail wanted. A domain that should receive nothing can say so with a null MX:
example.com. MX 0 .
Some registries, mostly country-code ones, publish no RDAP record or leave out the expiry date. The report says so when that happens, and the only reliable source is then your registrar account. It also can’t see whether auto-renewal is on or who can sign in to that account.
Questions people ask
How do I check when a domain expires?
Run the report. The expiry date comes straight from the registry’s RDAP record. If the registry doesn’t publish it, you’ll find the date in your registrar account under the domain’s details.
What happens when a domain expires?
The registrar first points the name at a parking page, so the site and email stop. For most endings you then have a grace period of several weeks to renew at the normal price, followed by a redemption period with a high fee. After that the name is released and anyone can register it.
Do I need DNSSEC?
It’s optional. It protects visitors against forged DNS answers, and many DNS hosts enable it with one switch. Only turn it on if you’ll remember to update the DS record whenever you change DNS host.
What is a CAA record and is it required?
A CAA record names the certificate authorities allowed to issue certificates for your domain, for example 0 issue "letsencrypt.org". It isn’t required. Without one, any authority may issue.
How many name servers should a domain have?
At least two, on different networks. Every DNS host gives you two to four by default. List all of them at the registrar.
What does clientTransferProhibited mean?
It’s the transfer lock. While that status is set, the registry refuses any request to move the domain to another registrar. You take it off yourself, for a few days, when you really want to transfer.