Domain Infrastructure Audit
Audit a domain’s DNS, hosting, redirects, security and email configuration
Enter a registered domain or known subdomain to audit its publicly accessible domain infrastructure.
Zynith checks domain registration, DNS records, authoritative nameservers, hosting, redirects, SSL certificates, DNSSEC and email authentication, then explains each finding and shows the supporting evidence.

example.com
www.example.com
app.example.com
Enter only a domain or hostname. Do not include a page path, query string or login details.
The audit uses publicly accessible information and does not modify the domain, DNS, website or email configuration.
Public DNS cannot reveal unknown subdomains, every DKIM selector, forwarding rules or private provider settings. The report should not be treated as a complete backup of a domain's DNS configuration.
See how a domain’s infrastructure is configured
A website can appear to work normally while important DNS, registration, security or email settings are incomplete, inconsistent or difficult to trace.
Zynith DNS Audit brings the public infrastructure information connected to a domain into one report. It identifies potential issues, explains why each check matters and provides the technical evidence behind the result.

Domain registration
Identify the registered domain, registrar, registration dates, public status codes and transfer-lock status.

DNS records
Review nameservers, Start of Authority records, website addresses, mail records, TXT records and certificate-authority restrictions.

Authoritative DNS
Query each delegated nameserver directly to confirm that it resolves, responds authoritatively and serves consistent zone data.

Website and hosting
Identify website DNS records, common hosting providers and the infrastructure used by root and www hostnames.

HTTP and redirects
Test HTTP and HTTPS versions, follow redirect paths and identify unnecessary redirect chains or inconsistent preferred hostnames.

SSL certificates
Check certificate validity, expiry dates, hostname coverage, issuers and Subject Alternative Names.

DNSSEC
Confirm whether DNSSEC is enabled, whether DS and DNSKEY records exist and whether the chain validates successfully.

Email authentication
Review MX, SPF, DKIM and DMARC configuration, including SPF lookup counts and common email-provider evidence.

Provider detection
Identify likely registrars, DNS providers, hosting platforms, email providers and connected services from public infrastructure evidence.
Built for agencies, SEOs and web professionals
Use the audit when you need to understand a domain before changing, troubleshooting or taking responsibility for it.

New-client onboarding
Identify the registrar, DNS provider, website host, email platform and major configuration issues before requesting access.

Website migrations
Record the current infrastructure, check DNSSEC and email dependencies, and compare the domain before and after migration.

Technical SEO audits
Review preferred hostnames, HTTPS, redirects, availability and infrastructure alongside the broader website audit.

DNS troubleshooting
Confirm that nameservers resolve, respond authoritatively and return consistent NS and SOA data.

Email investigations
Identify mail providers and review SPF, DKIM and DMARC settings affecting authentication and deliverability.

Registrar and DNS transfers
Understand which provider controls each part of the infrastructure before changing the registrar or nameservers.
More than a list of DNS records
Most DNS lookup tools return raw records. Zynith DNS Audit is designed to help people understand what those records mean and what should be investigated next.

Plain-English findings
Each result explains what was checked, why it matters, what action to take and the relevant best practice.

Direct nameserver testing
The audit queries delegated nameservers directly rather than relying only on one recursive DNS response.

Supporting evidence
Open the relevant report section to inspect response codes, record values, certificate details, redirect chains and nameserver evidence.

Provider detection
Identify likely registrars, DNS providers, hosting platforms, email providers and connected services from public infrastructure evidence.

Exportable reports
Download the audit as JSON or HTML, print it as a PDF, or save it for technical documentation.

Audit comparison
Upload a previous JSON audit to identify changes in DNS, registration, redirects, SSL, DNSSEC and email configuration.
How the DNS Audit works
1
→
Enter a domain or hostname
Enter a registered domain such as example.com, or a known hostname such as app.example.com.
2
→
Zynith runs the infrastructure checks
The audit queries DNS, registration, website, certificate, redirect and email authentication data.
3
Review the findings and evidence
Start with errors and warnings, then open the detailed report sections or export the result for later use.
Maintained and improved
Built for real-world use and continuously improved
Zynith DNS Audit uses publicly accessible DNS, registration and network information to assess a domain’s infrastructure. Results should be verified before making critical registrar, DNS, hosting or email changes.
Found something inaccurate, unclear or missing?
Frequently Asked Questions
A DNS audit reviews the public records and infrastructure connected to a domain. It can reveal how the domain is delegated, where the website and email are hosted, whether security features are enabled and whether key systems appear consistent.
No. The audit reads publicly accessible information. It does not log in to the registrar, DNS provider, hosting account or email platform, and it does not modify any configuration.
No. Public DNS can reveal records for hostnames that are known and queried, but it cannot provide a complete list of every private or unknown subdomain. DKIM selectors and account-level forwarding rules may also be undiscoverable.
Yes. Enter a known hostname such as app.example.com. The report will distinguish the scanned hostname from its registered domain.
A registration service, nameserver, website or external resolver may time out, reject the request or temporarily be unavailable. An unavailable check is inconclusive rather than proof of a configuration problem.
Yes. Run an audit before the migration, save the JSON report, then run another audit afterwards and compare the two reports.
No. The audit records publicly accessible information, but it cannot guarantee discovery of every hostname, private record, forwarding rule or provider-specific setting. Export the complete zone directly from the DNS provider before major changes.