// site check
One pass over the four ways of writing your address, the certificate behind them, the headers they return and the records that say who may send mail as you. Free, no signup, and the report is never stored.
// what gets checked
Every finding says what we observed and why it matters. Where we cannot prove something from outside, we say what we looked for instead of guessing.
01
There are four ways to write your address. All four should end up at exactly one of them.
02
The failure that gets discovered by a customer rather than by you.
03
What the server tells a browser it is allowed to do.
04
The records that decide whether someone else can send mail as your domain, and whether your own mail arrives.
05
A single sample from our probe, for context rather than as a verdict.
// bot etiquette
If you found relay19-sitecheck/1.0 in your logs, a person pasted your domain into the box above. It is a one-off, human-initiated check: at most eight requests to your homepage on ports 80 and 443, one TLS handshake, and a set of public DNS queries. Nothing is crawled, no form is submitted, no path other than the front page is requested, and the report is not stored or sent anywhere. It is rate limited per domain, so it cannot be used to generate traffic against you. We do keep a line recording that the request happened, which /privacy sets out in full.
If you would rather we did not, mail abuse@relay19.com and we will block the domain from the checker.
// monitoring
Everything above was true the second you pressed the button. Certificates expire on a Sunday, redirects get lost in a deploy, and DNS changes at the worst possible time. relay19 watches all of it from probes on three continents and tells you before your customers do.