Vernax Documentation¶
Vernax checks your domain's infrastructure: mail delivery, TLS certificates, DNS configuration, Certificate Transparency logs, web security headers, registration data, reputation, exposure and data protection — all with real live queries, explained clearly.
The nine tools¶
| Tool | What it checks |
|---|---|
| Mail Health | MX, SPF, DKIM, DMARC, STARTTLS, DANE, blacklists — 15 checks around email |
| SSL/TLS | Certificate, expiry date, TLS version, HSTS, HTTPS redirect |
| DNS | Records, nameserver redundancy, DNSSEC, CAA, zone transfer |
| Certificate Transparency | Issued certificates, unknown CAs, forgotten subdomains |
| Web Security | Security headers, open ports, server version leaks |
| Domain | Expiry date, transfer lock, registrar, nameserver match |
| Reputation | IP/domain blacklists (Spamhaus, Barracuda, SpamCop, SURBL), Google Safe Browsing |
| Exposure | Accidentally published paths (.git, .env, backups, admin panels) — verified domains only |
| Privacy | Google Fonts, trackers, third-country requests, cookies before consent, consent banner |
How a check works¶
- Enter a domain — no account required.
- Vernax queries DNS servers, mail servers, web servers and public registries live. No stored or estimated values are shown.
- Each sub-check gets a status (ok / warn / fail / info) and an explanation of what the result means and how to fix problems.
- All sub-checks combine into a score from 0–100.
Explain mode
Every tool has an explain mode that shows step by step what happens technically during a DNS resolution, a TLS handshake or a mail delivery — with the real values of your domain.
Monitoring¶
With an account you can add domains to a workspace and have them checked automatically — hourly, daily or weekly, with email alerts on regressions and a score history over time.