Free DotMoose tools
Free tools for domains, DNS, email, websites, SEO and infrastructure.
Diagnose domains, DNS, email, TLS and websites; review crawl and security signals; prepare migrations; and model networks, storage and infrastructure without an account.
Domain + infrastructure
Understand what exists before changing it.
Technical lookup tools are deliberately separated from sales. A result may suggest a next step, but it never creates a fake emergency or guarantees domain availability.
SuperTool
Enter a domain, hostname, IP or URL and choose the relevant checks.
RDAPWHOIS / RDAP lookup
See public registrar, status, dates, nameserver and DNSSEC registration data.
DNSDNS checker
Query common A, AAAA, MX, NS, TXT, CNAME and CAA records through a selected public DNS-over-HTTPS resolver.
PTRReverse DNS / PTR checker
Convert an IPv4 or IPv6 address to the reverse-DNS namespace and inspect its PTR answer through a selected public resolver.
MailEmail DNS checker
Inspect MX, SPF, DMARC, optional DKIM, CAA and resolver DNSSEC state before mail changes or deliverability work.
Planning + launch
Choose infrastructure from the workload, then verify the launch.
Hosting plan finder
Match websites, storage, mailboxes and developer needs to the current shared-hosting ladder.
WPWordPress hosting checklist
Turn site type, store needs, developer access and operational requirements into a practical launch checklist.
MoveMigration readiness checker
Find missing access, backups, DNS, email, runtime and rollback details before moving a website.
LaunchWebsite launch checklist
Check ownership, DNS, HTTPS, forms, email, backups, indexing, analytics, performance, security and rollback.
CADWebsite cost calculator
Model hosting, optional domain budget and build/maintenance assumptions in Canadian dollars.
FitHosting comparison centre
Compare shared hosting, VPS, WordPress hosting, domains, DNS and backup choices by the requirement you are trying to satisfy.
Server diagnostics
Web, DNS and network checks.
TLS certificate
Certificate chain details, names, expiry, protocol and cipher.
HTTPRedirect chain
Trace redirects from the first request to the final response.
HTTPResponse headers
Inspect the status and response headers returned by a site.
HSTSHSTS
Check the Strict-Transport-Security response header.
DNSResolver comparison
Compare answers from Cloudflare, Google and Quad9.
NSDelegation and glue
Inspect delegated nameservers and their published addresses.
DNSSECDNSSEC
Inspect DS, DNSKEY and validating-resolver state.
RDAPIP / network lookup
Resolve hosts and inspect public network registration data.
RouteNetwork Looking Glass
Run bounded ping, traceroute and repeated path checks from DotMoose infrastructure in Canada.
PTRForward-confirmed rDNS
Check that reverse DNS resolves back to the same address.
Website security
Inspect browser-facing security controls without exploiting the site.
Website security review
HTTPS, TLS, CSP, headers, cookies, CORS, mixed content, external scripts and security.txt in one passive check.
HeadersSecurity headers
HSTS, nosniff, framing, Referrer-Policy, Permissions-Policy, legacy headers and version disclosure.
CSPContent Security Policy
Review enforcing CSP, script allowances, frame-ancestors, object-src and base-uri.
CookieCookie attributes
Inspect Secure, HttpOnly, SameSite and cookie-prefix requirements without exposing cookie values.
CORSCORS / cross-origin policy
Inspect origin relaxation, credentials and COOP/COEP/CORP signals in context.
HTTPSMixed content / forms
Find captured HTTP references, insecure form actions and password fields served without HTTPS.
Contactsecurity.txt
Check the standard vulnerability-reporting contact location and expiry metadata.
Website + SEO
Check crawl signals, metadata and delivery behavior.
robots.txt viewer / tester
Read crawler groups and sitemap declarations and test a path against the matching Allow/Disallow rules.
XMLSitemap validator
Validate bounded XML, absolute locations, duplicates and cross-host entries.
CanonicalCanonical checker
Inspect final URL, HTML/HTTP canonical signals and robots directives.
SocialOpen Graph / social metadata
Read Open Graph, Twitter/X fields, title, canonical and icon declarations.
gzip/brCompression
Advertise gzip and Brotli and report the content encoding actually selected by the server.
IPv6IPv6 website connectivity
Check AAAA records and force the web request through IPv6 without IPv4 fallback.
HTTPHTTP status
Follow the bounded redirect chain and inspect final status, address and TLS details.
IconFavicon
Inspect declared icon links and verify the first available icon or root favicon.
Email diagnostics
Mail DNS and transport checks.
SPF
Read the policy and first-pass DNS lookup terms.
DMARCDMARC
Inspect the domain DMARC policy.
DKIMDKIM
Look up a public key by selector.
MXMX
Inspect exchangers, priorities and addresses.
SMTPSMTP STARTTLS
Test advertised STARTTLS and certificate details without sending mail.
STSMTA-STS
Inspect the DNS identifier and HTTPS policy.
TLS-RPTTLS-RPT
Read the SMTP TLS reporting policy.
BIMIBIMI
Look up the selected BIMI record.
HeadersEmail header analyzer
Parse common routing and authentication headers in the browser.
SPFSPF record generator
Build a starting SPF TXT value.
DMARCDMARC record generator
Build a DMARC TXT policy.
Calculators
Plan networks, transfer, storage and server capacity locally.
IPv4 subnet / CIDR
Network, netmask, wildcard, broadcast, usable range and exact address counts.
IPv6IPv6 prefix
Normalize a prefix and calculate network boundaries and exact BigInt address counts.
RangeIP range → CIDR
Count an IPv4/IPv6 range and decompose it into an exact aligned CIDR set.
MbpsBandwidth / transfer
Convert sustained Mbps into GB/TB/GiB/TiB or calculate the rate required for a transfer window.
DiskStorage growth
Project compound growth, headroom and multiple physical copies.
BackupBackup retention
Estimate retained capacity from full data, daily change, restore points and a stored-size factor.
VPSVPS sizing
Estimate a starting vCPU, RAM and disk baseline from workload and traffic assumptions.
Migration + operations
Final T8 tools: move, fix and verify production systems.
These tools combine existing hardened diagnostics into practical migration and operations workflows rather than duplicating low-level lookups.
Check a domain before you register it.
Check whether public RDAP currently shows a domain registration, then confirm live availability and current CAD pricing in DotMoose checkout.
T8Audit the DNS pieces that fail together.
Audit a domain across delegation, DNSSEC, public resolvers, MX, SPF and DMARC using the hardened DotMoose diagnostics platform.
T8Take a DNS snapshot before you move anything.
Capture A, AAAA, MX, NS, TXT, CNAME and CAA records before a DNS migration, then compare a later snapshot locally in your browser.
T8Inspect the modern TLS configuration, not just the certificate.
Check modern TLS protocol support, negotiated ciphers, ALPN, certificate details, HSTS and Alt-Svc observations for a public HTTPS host.
T8See where the first response time is going.
Measure DNS resolution, TCP connect, TLS handshake, TTFB, redirects and bounded response timing from a DotMoose diagnostics node.
T8See what the response tells browsers and caches to keep.
Inspect Cache-Control, Expires, Age, ETag, Last-Modified, Vary, compression and other public response headers that affect caching.
T8Check the redirect map before old URLs disappear.
Check up to 10 old or moved URLs at once and compare final status, redirect hop count and destination using bounded public HTTP diagnostics.
T8Turn aggregate XML into something a human can scan.
Paste a DMARC aggregate XML report and summarize source IPs, message counts, SPF alignment, DKIM alignment and disposition locally in your browser.
T8Build a CAA policy you can review before publishing.
Generate CAA issue, issuewild and optional iodef record values locally in your browser, with certificate authority identifier guidance.
T8Build the two pieces an MTA-STS deployment needs.
Generate an MTA-STS DNS TXT identifier and HTTPS policy template for testing, enforce or none mode locally in your browser.
T8Create the SMTP TLS reporting record.
Generate a TLS-RPT _smtp._tls TXT record with an aggregate report email address locally in your browser.
SEO + developer + capacity
Final T9 tools: crawl, protocol and infrastructure planning.
Distinct technical-search intents get their own useful page while local calculators keep private workload assumptions in the browser.
Check the JSON-LD the server actually sends.
Inspect bounded JSON-LD blocks found in public HTML and summarize syntax validity and schema @type signals without executing page JavaScript.
T9Inspect the hreflang links on the page response.
Inspect rel=alternate hreflang declarations in a bounded public HTML response and flag duplicate language codes.
T9Check the links a visitor can reach from one page.
Check up to 20 same-origin links found in one public HTML page for HTTP errors, redirect hops and final destinations without crawling the whole website.
T9Inspect the page signals a crawler receives before rendering.
Inspect page title, meta description, canonical URL, robots directives, headings, Open Graph and Twitter/X fields from bounded public HTML.
T9Check the crawl controls before asking for indexing.
Combine robots.txt, sitemap and page metadata checks to review whether a public website exposes coherent crawl and indexing signals.
T9Check the observable HSTS preload prerequisites.
Inspect HTTPS and Strict-Transport-Security signals relevant to HSTS preload readiness, including max-age, includeSubDomains and preload tokens.
T9See which HTTP protocol signals the HTTPS service exposes.
Inspect negotiated TLS ALPN for HTTP/2 support and public Alt-Svc signals that advertise HTTP/3, without claiming unobserved QUIC connectivity.
T9Follow the CNAME until it reaches an address — or loops.
Follow a bounded DNS CNAME chain, detect loops and show terminal A/AAAA answers for a public hostname.
T9Translate an uptime percentage into actual downtime.
Convert an availability percentage into allowed downtime over a month, custom period and year locally in your browser.
T9Read a five-field cron expression before you schedule it.
Parse common five-field cron wildcard, number, list, range and step syntax locally in your browser.
T9Build the ip6.arpa name without reversing nibbles by hand.
Convert an IPv6 address and nibble-aligned prefix into ip6.arpa reverse DNS names locally in your browser.
T9Estimate usable array capacity before buying the drives.
Estimate raw and usable capacity for mirrors, RAIDZ1, RAIDZ2, RAIDZ3 and RAID5/6-like layouts with spares and headroom.
T9Check whether file count can become the limit before disk space.
Estimate inode-style file-count capacity from filesystem size and a planning bytes-per-inode ratio, then compare it with expected average file size.
T9Separate logical objects from backend capacity and transfer cost.
Model logical object data growth, backend storage overhead, egress and optional monthly CAD storage rates locally in your browser.
T9Plan mailbox growth before quotas become an emergency.
Estimate mailbox storage growth, operational headroom and backup-copy capacity from mailbox count and average usage locally in your browser.
Monitoring
Turn a verified one-off target into an explicit recurring check.
Reputation
Check public reputation signals with their scope intact.
Blacklist / reputation checker
Check several permitted DNSBLs and keep IP, allocation and ASN-level findings separate.
ExplainBlacklist result explainer
Understand disagreements, scope, transient listings and sensible delisting steps.
MailMail reputation checklist
Work through server identity, authentication, public lists, feedback loops and sending behaviour.