Free agency tools / Domain Inspector
Everything about a domain, in one scan
Hosting, SSL certificate, WHOIS, DNSSEC, blacklists, security headers, redirects and subdomains — the full due-diligence picture before you take on a site, with a report you can send to the client.
Results for
Hosting
The network that owns the site's IP.
Checking…
SSL certificate
Issuer and expiry, from Certificate Transparency logs.
Checking…
Domain registration
Registrar and key dates (WHOIS/RDAP).
Checking…
DNSSEC
Is the domain's DNS cryptographically signed?
Checking…
Blacklist
Is the IP on a DNS blocklist?
Checking…
Security headers
Which protective HTTP headers are set.
Checking…
Redirect chain
Where the URL ends up.
Checking…
Subdomains
Discovered from Certificate Transparency.
Checking…
How it works
- 1Enter a domain — we run every check in parallel.
- 2Hosting and ASN, SSL certificate, WHOIS, DNSSEC, blacklists, security headers, redirects and subdomains are gathered in one pass.
- 3Review the full picture or copy it as a Markdown report for the client.
Frequently asked
Where do the SSL and WHOIS details come from?
SSL comes from public Certificate Transparency logs; WHOIS from the registry's RDAP service. Both are authoritative, public sources.
Why is WHOIS sometimes 'unavailable'?
Some ccTLDs (like .co) don't expose a public RDAP endpoint, so registration dates can't be retrieved for those.
How are subdomains found?
From Certificate Transparency logs — subdomains that have ever been issued a TLS certificate. It won't find internal-only names.