Skip to content
SysGlass
Full infrastructure report

Inspect anything

One box, one full report. Enter a domain and SysGlass detects everything — DNS, DNSSEC, WHOIS, TLS & HTTP, the whole mail suite, subdomains, and the reputation/health of its servers. Enter an IP and it runs reverse DNS, network/ASN, blacklists, a well-known open-port check and TLS. You get an overall health score and exact fixes without running each tool by hand.

Coverage: DNS, TLS, mail, network, and exposure
DNS
records, DNSSEC, delegation, propagation
TLS/Web
certificate, TLS scan, HTTP, headers, reputation
Mail
SPF, DKIM, DMARC, BIMI, MTA-STS, TLS-RPT, SMTP
Network
reverse DNS, ASN, BGP, geolocation, ports, blacklists
Exposure
subdomains, origin hints, service inventory, CVEs

What Inspect runs

Inspect fans out to dozens of checks in parallel — each one the same engine that powers the matching standalone tool — and merges them into a single graded report. For a domain it covers the whole stack; for an IP it runs the server-and-network half directly:

  • DNS — every record that matters (A, AAAA, MX, NS, SOA, CAA, TXT) plus DNSSEC validation, nameserver and delegation health, and multi-resolver propagation.
  • Domain WHOIS registration, expiry, registrar and ownership details.
  • TLS & Web — the live certificate, a deep TLS configuration scan, an HTTP/web-server scan, security headers and URL reputation.
  • Mail — the complete authentication suite (SPF, DKIM, DMARC, BIMI, MTA-STS, TLS-RPT, DANE), SMTP and MX server health, and blacklist reputation on the IPs the domain actually sends from — run automatically when the domain receives mail.
  • Discovery subdomain enumeration from certificate transparency and a subdomain-takeover check.
  • Network & IP reverse DNS (PTR), ASN/network owner, BGP route and RPKI, geolocation, and an open-port check of the server behind the name.
  • For an IP target — the same server battery (RIR/WHOIS, reverse DNS, ASN, BGP, geolocation, open-port check, TLS, web and blacklist), minus the domain-only checks. For a full attack-surface view of a single host, the IP / Host Exposure Audit adds confirmed-vs-version CVEs and a deep service scan.

What you get

  • One overall health score out of 100 with an ok / warn / fail verdict and a plain-language summary.
  • A Top issues box that surfaces the highest-impact problems first.
  • Every check grouped into expandable sections (DNS, TLS/Web, Mail, Network/IP, Domain) with the raw findings and a status on each row.
  • The exact fix for each problem — what to change and why — attached to its section.
  • CVEs and exposures surfaced from the services it finds, with a one-click drill-down into a deep service scan.
  • After a domain finishes, an option to inspect its subdomains with the same full breakdown.

How to read the result

  • Start at the score and the Top issues — they are ordered by impact, so work from the top down.
  • A single critical finding forces the whole verdict down (weakest-link), even when everything else is green — that one item is your priority.
  • A green tick means nothing to improve; a muted "recommended" mark means the section passes but has optional hardening (DNSSEC, DANE, BIMI, IPv6 and similar) that does not cost you score.
  • Sections stream in live — a check that has not appeared yet is still running, not failing; wait for the score to finalise.
  • Mail checks only appear when the domain actually receives mail (publishes a real MX); a null-MX or no-mail domain is not penalised for missing receiving-side records.
  • Behind a CDN, the network findings (ASN/BGP/ports/reputation) describe the real origin wherever SysGlass can find it, not the shared edge.

Frequently asked questions

What does Inspect actually run?

One target, the full battery. For a domain SysGlass runs your DNS records (A, AAAA, MX, NS, SOA, CAA, TXT), DNSSEC, nameserver and delegation health, multi-resolver propagation and WHOIS; the live TLS certificate plus a deep TLS scan, an HTTP/web-server scan, security headers and URL reputation; subdomain discovery and a takeover check; and the full mail-authentication suite (SPF, DKIM, DMARC, BIMI, MTA-STS, TLS-RPT, DANE) plus SMTP/MX health when the domain receives mail — then reverse DNS, ASN/network, BGP route, geolocation, an open-port check and blacklist reputation on the server behind it. For an IP it skips the domain-only checks and runs the server-and-network side directly. Every check uses the same engine as the matching standalone tool, just orchestrated for you.

Do I need to run each tool separately first?

No — that is the whole point. Inspect fans out to every relevant check in parallel and merges the results into one report with a single health score, so you don't have to run DNS Lookup, the SSL Checker, the mail tools and a open-port check by hand and stitch the findings together yourself. You can still open any individual tool afterwards to dig deeper into one area.

How long does it take, and why do results appear gradually?

Results stream in live over Server-Sent Events. Each section is shown the moment its check finishes, so fast lookups (DNS, WHOIS) appear within a second or two while slower ones (open-port check, traceroute, deep TLS) fill in afterwards — they never block the rest. The overall score and verdict finalise once everything is done, within the inspection's time budget.

What does the health score mean?

The score is out of 100 and rolls every section up into one number weighted by severity, with a verdict of ok, warn or fail. Any single critical finding drags the whole result down on a weakest-link basis, regardless of how clean everything else is, because one exploitable hole matters more than a dozen green ticks. The Top issues box surfaces the highest-impact problems first, and each section carries the exact fix.

Does it work behind a CDN or WAF like Cloudflare?

Yes. When a domain resolves to a CDN/WAF edge, the DNS, TLS and HTTP checks still run against the public name, and SysGlass pivots the IP-level checks (ASN, BGP, geolocation, open-port check, reputation) to the real origin server wherever it can discover it — so the network findings describe your actual machine, not the shared edge. If the origin is hidden, the Origin Exposure tool can help surface it.

Is it safe and legal to inspect a target?

The checks are read-only and non-destructive — DNS and registry lookups, certificate and header reads, banner-grab open-port checks and safe behavioural probes. Inspect public-facing infrastructure you own or are authorised to assess; scanning third-party systems without permission may be unlawful, and you remain responsible for having authorisation for whatever you enter.

Other tools