Audit module

DNS, TLS & Email Authentication (SPF/DKIM/DMARC) Audit

What DNS and email-authentication checks does Audityxe run?

Audityxe runs live DNS lookups for CAA records, DNSSEC, dangling CNAME subdomain-takeover risk, nameserver diversity, SOA and MX records, and checks SPF, DKIM, and DMARC — alongside a live TLS handshake that inspects the certificate chain.

These are external, read-only lookups of the audited domain. They do not require access to your DNS provider or mail server.

What is checked

DNS Security (CAA, DNSSEC, Subdomain Takeover & Zone Health)

Certificate-issuance restrictions, signing, and zone health.

  • CAA record
  • DNSSEC
  • Dangling CNAME / subdomain takeover
  • Nameserver provider diversity
  • Nameserver records
  • SOA record
  • MX records

Email Authentication (SPF/DKIM/DMARC)

Spoofing protection for the domain.

  • SPF record
  • SPF lookup limit
  • DMARC policy
  • DKIM

SSL / TLS Certificate

Live handshake and chain inspection.

  • Certificate expiration
  • Certificate issuer
  • Hostname / SAN match
  • TLS protocol version
  • Cipher suite
  • Key strength

How to run it

Web app: Paste a URL; the DNS, TLS, and email checks appear as separate modules in the results.

Command line (see the CLI guide):

npx audityxe-cli https://example.com

Frequently asked questions

Can Audityxe check my SPF, DKIM, and DMARC records?

Yes. Audityxe performs live DNS TXT lookups and reports the SPF record and its lookup limit, the DMARC policy, and DKIM.

Does Audityxe detect subdomain takeover risk?

Yes, for dangling CNAME records it can see through DNS lookups. It does not enumerate every subdomain of a domain.

Last reviewed against the Audityxe source code. Product names mentioned are trademarks of their respective owners; Audityxe is not affiliated with them.