DNS Intelligence
An SPF record that needs more than 10 DNS lookups fails, and nested includes hide the real count. So I built a scanner that counts the way mail servers do, then a watch that tells you before it breaks.
The problem
Email authentication fails quietly. An SPF record can include another, which includes another; past 10 DNS lookups the whole record fails for every receiver, and most checks only count the top level. A certificate expires on a Saturday. DMARC sits at p=none for years.
What it does
- 26 checks in one scan: DNS records, TLS and certificate, security headers, DNSSEC, SPF, DKIM, DMARC, MTA-STS and blocklists.
- SPF lookups counted through every nested include as RFC 7208 receivers do, including void lookups, with a hard query budget.
- Watch a domain and it emails you when the certificate, SPF, DMARC, MX or nameservers change, or when SPF crosses the limit. Pro and Team collect DMARC reports automatically.
How it is built
- Browser or APIrate limited, CORS allowlist
- Expressone process
- ProbesDNS, TLS, HTTP via an SSRF guard
- SQLitewatches, users, hashed tokens
- Schedulerdaily checks and email alerts
Hardening it
- 62 to 0
One triage pass took open code-scanning alerts from 62 to 0, every dismissal written down.
- SSRF
Every outbound hop checked against private, loopback and link-local ranges, including IPv4-mapped IPv6 in every written form.
- Secrets
Session and API tokens stored only as hashes, with a migration for existing rows. Sign-in links built only from the configured URL, never from request headers.
- Release bar
Signed commits, required checks, CodeQL and Scorecard on every change; Dependabot with a 7-day cooldown and every Action pinned to a commit.