
Understanding email headers: the complete guide to reading and analyzing every field
Every email carries an invisible logbook. This guide teaches you how to extract it, read it field by field, and diagnose deliverability or security issues.
DNS Lookup
Choose a DNS record type to search for.
Propagation & diagnostics
Compare resolvers worldwide and inspect returned answers.
Keep history, monitor your zones and automate recurring checks.
Email Diagnostics
Tools to verify and validate your email authentication setup.
Secure & Monitor
Record generators, policy hosting and continuous monitoring.
Generators
Network & Web
Network tools, web page analysis and certificates.
IP Tools
My IP address
Detect your IPv4/IPv6 addresses and their geolocation.
Reverse lookup
Resolve a PTR record and validate DNS consistency.
IP WhoIs
Identify the owner of an IP range and its contacts.
IPv4 netmask
Calculate network, broadcast and usable hosts for any IPv4 block.
IPv6 subnet calculator
Calculate IPv6 subnets, address ranges and reverse DNS entries.
Certificates & BIMI
BIMI logo lookup
Inspect a BIMI logo URL - format, metadata and live rendering - before rollout.
BIMI SVG converter
Convert any SVG to BIMI-compliant Tiny-PS format in seconds.
CSR parser
Inspect a CSR, extract subject details, fingerprints and requested SANs.
VMC inspector
Inspect a Verified Mark Certificate - issuer, validity and SAN coverage - before you publish BIMI.
Developer Tools
Text utilities and tools for everyday dev work.
Text
Transform and measure your content in seconds.
Text case converter
Convert any block of text to upper or lower case instantly.
Slug generator
Transform any sentence into an SEO-friendly slug in seconds.
Word & character counter
Measure the length of any text, with instant word and character counts.
Password generator
Generate strong random passwords and memorable passphrases instantly.
Developer
Encoding, hashing, regex and formatting for everyday dev work.
Base64 encoder / decoder
Encode or decode any content in Base64 without leaving the browser.
Hash Generator
Compute MD5, SHA-1, SHA-256 and SHA-512 hashes of any text.
URL encoder / decoder
Encode or decode text using percent-encoding (RFC 3986) right in your browser.
Regex Tester
Test a regular expression against text and visualize matches.
JSON / YAML Formatter
Format, validate and convert JSON and YAML in one click.
CaptainDNS hosts your MTA-STS policy and BIMI logo, and monitors your DMARC and TLS-RPT reports automatically. All free, no server required.
Google, Yahoo and Microsoft now require stronger email authentication. Protect your deliverability in just a few clicks.
CaptainDNS hosts your MTA-STS policy and BIMI logo, and monitors your DMARC and TLS-RPT reports automatically. All free, no server required.
Google, Yahoo and Microsoft now require stronger email authentication. Protect your deliverability in just a few clicks.
Core DNS concepts, record types, and domain name system fundamentals.
53 articles

Every email carries an invisible logbook. This guide teaches you how to extract it, read it field by field, and diagnose deliverability or security issues.

The 24 to 48 hour myth is wrong. The actual delay depends on TTL, and you can control it.

Full analysis of NIST SP 800-81r3, released March 19, 2026. Protective DNS, DNSSEC, encrypted DNS: the key recommendations for securing your infrastructure.

Since March 15, 2026, the CA/Browser Forum requires CAs to verify DNSSEC during domain validation. This guide covers the context, impact, and how to check your configuration.

From registration to release: understand every stage of the domain lifecycle, the risks at each phase, and the protections to enable.

WHOIS is retiring. RDAP replaces it. This guide covers everything: technical comparison, EPP codes, GDPR impacts, domain locks, and a migration plan.

Microsoft is changing DNS provisioning for Exchange Online domains. MX records are moving from mail.protection.outlook.com to mx.microsoft to streamline DNSSEC adoption. Here's what's changing and what you need to do.

A SERVFAIL after enabling DNSSEC points to a broken chain of trust. This guide covers the five causes, three diagnostic commands, and exact fixes for each scenario.

The chain of trust is the core principle behind DNSSEC. This guide explains every link, from the DNS root to your domain, with clear diagrams.

DNSSEC protects your visitors from DNS spoofing. This guide covers step-by-step activation for the 6 most popular registrars, with instant verification.

Which IPv6 prefix should you use for your network? Detailed comparison of /48, /56, and /64 sizes with a table, decision tree, and real-world examples.

Detailed comparison of the 3 main email blocklists: detection methods, false positive rates, delisting procedures, and impact on Gmail, Outlook, and Yahoo deliverability.

Are your emails consistently landing in spam? This guide analyzes the 5 main causes and gives you a concrete action plan to restore optimal deliverability.

Is your IP on a blacklist and your emails getting rejected? This guide details the delisting procedures for each major blacklist, including processing times and best practices to avoid getting listed again.

From DVAG (10,562 domains) to Toyota: analysis of 5 .brand models by country. Discover which strategy to adopt based on your industry.

From $350K for a .brand to over a million for a commercial gTLD: discover all ICANN 2026 application costs.

On April 30, 2026, ICANN opens applications for new domain extensions. A complete breakdown for decision-makers.

Complete Amazon SES configuration with Easy DKIM, Custom MAIL FROM, strict DMARC alignment. Everything you need for optimal deliverability and GDPR compliance.

A comprehensive guide to compare the best public DNS resolvers: privacy, security, family filtering, DoH/DoT/DoQ, and deployment methods.

Surfshark DNS is a free public DNS resolver (IPv4/IPv6, DoH) focused on privacy. Here's when to use it, how to configure it, and what to check.

DNS4EU is a European public DNS with 5 variants (security, kids, ad blocking, neutral) and IPv4/IPv6 + DoH/DoT addresses. Deployment and verification guide.

CleanBrowsing is a public filtering DNS resolver (Family/Adult/Security) with DoH/DoT. Practical guide: router, mobile, checks, and anti-bypass.

NextDNS is a customizable DNS resolver: DoH/DoT encryption, filtering, profiles, and logs. Here's how to deploy it cleanly at home or in an SMB.

AdGuard DNS is a public DNS resolver that can block ads/trackers (and, in Family mode, adult content). Addresses, DoH/DoT/DoQ, and an action plan.

1.1.1.1 is Cloudflare's public DNS resolver. Here's how to use it properly (addresses, DoH/DoT/ODoH, tests, pitfalls) and deploy it.

Quad9 (9.9.9.9) is a public DNS resolver focused on security and privacy: malware blocking, DNSSEC validation, and encrypted DoT/DoH options. Here's how to deploy it properly.

Add the CaptainDNS MCP server to ChatGPT and use 3 widgets to troubleshoot DMARC/DNS and analyze email headers without leaving the conversation.

Putting your logo in the inbox: what you actually need to configure in DNS for BIMI, and how to choose between VMC and CMC.

Gmail and Yahoo require a one-click unsubscribe via RFC 8058-compliant List-Unsubscribe headers. Here's the expected format, the server-side POST, and the compliance checklist.

IPv4 vs IPv6: address sizes, performance, security, NAT, DNS... Learn how to differentiate ipv4 and ipv6, what ipv6 vs ipv4 really means, the ipv4 and ipv6 difference for DNS, and how to keep both stacks coexisting.

Learn what Google Public DNS 8.8.8.8 is, how it works, its speed and reliability benefits, privacy drawbacks, how to configure it on Windows 11 or a router, and which alternatives (Cloudflare 1.1.1.1, OpenDNS, etc.) to consider.

How we connected Auth0 to our CaptainDNS MCP server: dedicated audiences, PRM, Resource Parameter Compatibility Profile, JWT validation, identity propagation into profiles and api_requests, with optional auth today and protected tools ready for later.
How we wired CaptainDNS to AIs through MCP: architecture, HTTP+SSE transport, JSON-RPC, 424 errors, timeouts, and what we learned along the way.

Your logo changed but inboxes still display the old one? It is not only a DNS issue: mailbox providers cache BIMI assets. Discover how the cache layers work and how to plan a smooth BIMI migration.

Diagnose, archive, share, then monitor: CaptainDNS now supervises the full lifecycle of a DNS query from the first lookup to automated watch jobs.

Starting in November 2025, Google enforces new security requirements for bulk senders: full SPF/DKIM/DMARC authentication, TLS encryption and strict unsubscribe management.

Behind 4.3M .fr domains, geography reveals a two-speed country: from 21 to 235 domains per 1,000 inhabitants depending on the department.

EDNS Client Subnet (ECS) lets a DNS resolver pass a client address prefix to improve geolocation of the answers.

Ensure visibility of your domains by combining zone differences, active queries and propagation tests.