Email and DNS toolkit limitationsResults are public-DNS observations, local parsers and bounded cryptographic checks—not proof of identity, delivery, reputation or compliance.
Message and DMARC inputs remain in the browser, but copying, forwarding or exporting can alter evidence. DKIM RSA-SHA256 verification depends on complete unmodified source and the currently published key; unsupported algorithms are labelled. DNSSEC uses public-resolver validation plus DS digest matching, while some TLSA selectors cannot be byte-matched in this runtime. No SMTP server is required or contacted. Monitoring stops when its page closes. Live delivery, mailbox acceptance, commercial reputation, inbox-placement and proprietary blacklist coverage are excluded.
Important: Do not rely on this result alone for purchasing, configuration, security, safety, compliance, contractual or fault-diagnosis decisions. Results can be incomplete, delayed, misleading or wrong. Verify important findings with the relevant provider, manufacturer documentation and an appropriate independent test or qualified professional.
Browser-local evidence
Diagnostic case workspace
Group exports from multiple tools with notes, correlate likely relationships, then create one portable case file without uploading its contents.
Stored only in this browser: the working case is saved on this device until you clear it. Imported content is not uploaded or included in analytics. Current size: 73 bytes.
Encrypted reusable projects
Client-side AES-256-GCM: project contents are encrypted before storage or export. The passphrase never leaves this page and cannot be recovered. Up to 10 encrypted projects are retained in this browser.
Add a tool export
Privacy reminder: review the case before sharing it. Tool exports can contain domains, IP addresses, email identities or operational details.