Security Badge Beta
Generate a live security posture badge for any scanned domain. Embed it in your GitHub README, documentation, blog, or website.
A badge is a measurement, not a compliment.
Every DNS Tool badge describes what the instrument measured about your zone — declared policy, measured from a single vantage point across three independent public resolvers (Quad9, Cloudflare, Google) at one recorded instant. Single vantage is a stated limitation, not a footnote: split-horizon DNS, GeoDNS, and regional anycast can make your local view legitimately differ. (Multi-vantage DNS resolution is on the roadmap; this changes when it ships, not before.) Hardened means your published records met the strongest posture the measurement can establish. It does not mean "safe." No badge we issue says Safe, Secure, or Verified, because the instrument cannot measure those claims.
Why you can't game it — and why we won't help.
A badge renders only from a stored measurement row in the public database — keyed to its analysis id, carrying its measurement date. There is no parameter that makes a badge say something the instrument didn't measure, for you, for your robot, or for ours. If your posture is Exposed, the badge says Exposed until a new public measurement says otherwise. Every badge shows when it was measured; a green badge with an old date is an old reading, and says so on its face. The fix for a bad badge is fixing your zone.
Local is sovereign — and unbadgeable.
Badges read only the public database. That's not a policy; it's the construction — private, failed, and flagged scans are excluded at the query layer, so a local-only scan has nothing public for a badge to read. Publishing a scan (the publish toggle, default off, labeled with exactly what leaves your machine) is what creates the public measurement a badge can point at. While the program is in beta its vocabulary and rendering may evolve; the discipline — a badge only ever describes a stored public measurement, and never says Safe — is the stable API.
Live Preview
detailedGenerate Badge
Where to Find Your Scan Number
After running a scan, look at the URL in your browser address bar:
The number after id= is your scan number. Using a scan number pins the badge to that specific scan result.
Using a domain name always shows the most recent public scan.
Embed Code
Animated Badge
Full-color animated PNG. Crystal clear, lossless quality. Supported by all modern browsers, Apple Mail, Notion, and most platforms.
256-color animated GIF. Universal compatibility for legacy platforms. Use APNG for full quality.
This badge visualizes publicly available DNS records, certificate transparency logs, and protocol configurations —
the same data queryable via dig, nslookup, or any CT log search.
Domains missing SPF, DKIM, DMARC, or DNSSEC records are verifiably exposed to spoofing, impersonation, and interception.
That is not an opinion. It is what the protocol specifications require and what the absence of those records permits.
GitHub & Shields.io
Use the Shields.io endpoint for dynamic badges rendered by Shields.io. These always produce their standard compact format.
Private scans are excluded. Only public domain posture data is exposed. Badge data cached for 1 hour.
Where Each Badge Works
), any website, documentation, wikis. Our server renders the SVG — full control over the design.
We use two cookies, both essential:
_csrf— Prevents cross-site request forgery. Required for form submissions. Security-only._dns_session— Only exists if you choose to sign in. No account required to use DNS Tool.
We log your IP address for two reasons: rate limiting (so nobody abuses the service) and security (identifying malicious actors and complying with legal obligations). We check source geography for analysis accuracy — DNS responses vary by region, and knowing which resolver answered from where makes the science better.
No tracking cookies. No analytics cookies. No ad networks. No data brokers. Our code is open-core — the application framework is publicly available under BUSL-1.1 with timed Apache-2.0 conversion. Verify it yourself.
Public analyses are archived by a third party. When a scan is not marked private or run as /dev/null, its report URL is submitted to the Internet Archive, which creates a permanent public record outside our control. That is deliberate — it gives every published analysis tamper-evident provenance independent of us — but it is not reversible, so it is stated here before you scan rather than after.
If you create an account and want out, account deletion removes your login and scan history. Public domain analyses remain available because they contain only public DNS records, already hashed. Full details: Privacy Policy.
