Audit module
DNS, TLS & Email Authentication (SPF/DKIM/DMARC) Audit
What DNS and email-authentication checks does Audityxe run?
Audityxe runs live DNS lookups for CAA records, DNSSEC, dangling CNAME subdomain-takeover risk, nameserver diversity, SOA and MX records, and checks SPF, DKIM, and DMARC — alongside a live TLS handshake that inspects the certificate chain.
These are external, read-only lookups of the audited domain. They do not require access to your DNS provider or mail server.
What is checked
DNS Security (CAA, DNSSEC, Subdomain Takeover & Zone Health)
Certificate-issuance restrictions, signing, and zone health.
- CAA record
- DNSSEC
- Dangling CNAME / subdomain takeover
- Nameserver provider diversity
- Nameserver records
- SOA record
- MX records
Email Authentication (SPF/DKIM/DMARC)
Spoofing protection for the domain.
- SPF record
- SPF lookup limit
- DMARC policy
- DKIM
SSL / TLS Certificate
Live handshake and chain inspection.
- Certificate expiration
- Certificate issuer
- Hostname / SAN match
- TLS protocol version
- Cipher suite
- Key strength
How to run it
Web app: Paste a URL; the DNS, TLS, and email checks appear as separate modules in the results.
Command line (see the CLI guide):
npx audityxe-cli https://example.comFrequently asked questions
Can Audityxe check my SPF, DKIM, and DMARC records?
Yes. Audityxe performs live DNS TXT lookups and reports the SPF record and its lookup limit, the DMARC policy, and DKIM.
Does Audityxe detect subdomain takeover risk?
Yes, for dangling CNAME records it can see through DNS lookups. It does not enumerate every subdomain of a domain.
Last reviewed against the Audityxe source code. Product names mentioned are trademarks of their respective owners; Audityxe is not affiliated with them.