Who registered it and when, who governs it today, whether it can be impersonated in e-mail, what it declares about itself.
It consumes no slots and has no usage limits: it is included in C.E.R.T.O. Desktop and available to anyone with an account.
The result is sealed in a bundle with an Ed25519 signature and an RFC 3161 timestamp, with a report in text and PDF.
A domain's information arrives through two different and non-interchangeable channels. RDAP is structured data, machine-readable and therefore comparable. WHOIS is free text, with a different format for every registry.
WHOIS is preserved exactly as it arrives and is not interpreted: a program guessing at its fields would produce data that looks established and is not. The full text is in the bundle, and the reader can read it with their own eyes.
Only what the program actually does: every item matches a finding that exists in the code.
Creation, update and expiry dates, normalised domain statuses, declared DNSSEC, registered name servers. Where the registry exposes RDAP, all of this is structured data.
The name servers the registry declares, compared with those the zone actually publishes: two independent sources on the same fact. A divergence is notable — a provider change under way, or a stale delegation — and it is recorded, not interpreted.
SPF, DMARC with the actual meaning of its policy, MTA-STS. This is the most consulted finding in practice: a domain with neither SPF nor DMARC can be impersonated with nothing to flag it, and that is exactly what one wants to be able to assert or rule out.
robots.txt, llms.txt and the declared sitemaps, followed down to child indexes. They state which parts of the site the operator asks not to be indexed and how many pages it claims to have.
A stated limit is worth more than a claim of completeness — and it goes into the report too, not just onto this page.
Six of the extensions most used in Italy expose no RDAP: .it, .eu, .de, .ch, .es and .io. Measured against the IANA registry on 22 September 2026, across 1,202 extensions. For those the registry's only source is free-text WHOIS, which is preserved and not parsed. It is not a failure: it is known before querying, by reading the extension registry, and the report states “the .it registry exposes no RDAP”.
The holder's personal data is often absent, and not because it was not looked for: registries redact it for natural persons. The report distinguishes redacted data from missing data.
The .htaccess file cannot be downloaded. That is not a limitation of the program: a correctly configured server denies it, and indeed on every domain tested it answers “access denied”. What gets established — and it is a useful fact — is that it is in fact denied.
The questions we are asked most often about this check.
All inside C.E.R.T.O. Desktop's OSINT section, all with their own sealed bundle.
Register and download C.E.R.T.O. Desktop for Windows and macOS from your client area.