The dns: audit: fourteen checks your nameservers wish you ran
Domains are wildly broken and most owners do not know it: delegation mismatches, stale glue, secondaries serving week-old serials, nameservers that answer third-party recursion and get abused in DDoS amplification.
Our audit walks the delegation the way a resolver does — asking the parent, then each authoritative server directly with recursion off — and grades what it finds against RFC 1912. Provider-aware: managed platforms (Cloudflare, Route53…) get heuristics that fit how they actually mint serials, not false alarms.
Run it on your domain — the audit includes this check.
Other tools: SPF · DMARC · llms.txt · Header analyzer