Every change Wellknown observed on this agent, newest first, with what it was before and what it became. Tool-surface changes carry the definition diff. Nothing here is edited after the fact.
Changed the definition of "asn_lookup", "check_dns", "check_ssl" and 17 more
before
—after
ASN lookupResolveResolves a public IP address, or a domain, ⟨4 unchanged words⟩ that announces it: AS number and name,theannounced prefix, country code, registry and allocation date.Answers who operates the network an address sits on, which tells aDistinguishes hostingprovider from a CDNproviders,fromCDNsaand corporatenetwork.networks;Itit does not identify the siteowner, andowner.privatePrivateorand reserved addresses have no announcing AS. ip_geolocation returns the same AS data plus country and PTR. Anonymousand, rate-limited per IP.
{"openWorldHint":true,"readOnlyHint":true,"title":"ASN lookup"}
before
—after
Check DNSResolveResolves a domain's DNS records in one call (A, AAAA, CNAME, MX, TXT, NS, SOA and more),returningand returns each record type with its values,andor a per-type error where a lookup failed. Answers come fromthe resolver Uptimeify uses, so this is one vantage point: to see whether the answer is already theasamesingleeverywhere,resolver;usedns_propagation
before
—after
Check SSLFetchFetches andevaluateevaluates a host'sTLS/SSLTLS certificate over a live handshake: subjectand, issuer, validity window, days until expiry, ⟨8 unchanged words⟩ SANs, serial and SHA-256 fingerprint. Takes a hostname,(not an IP address,)plusand an optional port (default 443).This is aA single sample takennow: it does not watch the certificate over time, says nothing about the
before
—after
DKIM checkFetchFetches andvalidatevalidates the DKIM public keypublishedata given selector (<selector>._domainkey.<domain>) and report the: parsed tags, key type, key sizein bits,and warnings such as a revoked or malformed key. The selector is required and cannot be derived from thedomain: readdomain; itfromappears in a message's DKIM-Signature header,or try the provider's(common
before
—after
DMARC checkFetchFetches a domain's DMARC record from _dmarc.<domain> andevaluateevaluates it:theraw record,everyparsedtagtags,thepolicy and subdomain policy,thepercentagethe policy applies to, and warnings for records that parse butdooffernotnoprotectprotection (p=none, missing rua, syntax receivers ignore
before
—after
DNS propagationQuery theQueriessameone domain against several public resolvers andcomparecompares the answers,sowhich tells a recent record changecan be toldapart from a stale cache. Returns each resolver withtheits valuesit gave, plusand aconsistent`consistent` flag that stays false while the answersstilldiffer.Use
before
—after
DNSBL checkQueryChecks a public IP address against common DNSblacklistsblocklists andreturnreturns, per list, whether it is listed, the list's reason codethe list gaveanditsdelisting URL, plus totals and aclean`clean` flag. Takes an IP address, not a domain:resolve the sending host first with(mx_lookup orcheck_dns.check_dns resolve one).
before
—after
Domain expiryReportReports a domain's registration expiry from WHOIStogetherwithdaysUntilExpirythe remaining days, plus registrar, creation and update dates and the EPP status codes that reveala domain already inredemption or pending delete.This isCovers the registration, not thecertificate: an expiringTLS certificateis check_ssl.(check_ssl). tldSupported=false means the TLD has no queryable WHOIS serverUptimeify can query,which isnotthe samethat
before
—after
HSTS checkCheckChecks a domain's HTTP Strict Transport Securityconfigurationsetup:whether theheaderis present,presenceitsand raw value, max-agein seconds,theincludeSubDomains and preload flags, whether plain HTTP redirects to HTTPS,whether the configuration would qualify for the browser preloadpreload-listlisteligibility, and warnings forvalues that make the headerineffective
before
—after
HTTP headersFetchFetches a URL andreturnreturns its HTTP response headers verbatim as a name/value map, with the status line and every redirecthop taken to get there. Use it to inspect caching, security and server headers as they are actually sent;hop.theThe response body is neverreturned, so this says nothing about pagereturned.content.website_statusForgives a plain up/down verdictuse website_status,andfor
before
—after
IP geolocationLocateLocates a public IP address, or a domain resolved to one, at network level: country code,allocatingregistry, announced prefix, PTR hostname andtheautonomoussystems the address belongs to. It issystems.registry-basedRegistry-based, so it names the network operator's country, which for hosted orCDN-frontedCDN addressesisdiffersnotfrom wherethea visitor orthe
before
—after
MX lookupLookLooks up a domain's MX records andresolveresolves each mail exchanger to its IPv4 and IPv6 addresses, ordered by priorityand flagged,whenflaggingahostshostthatresolvesresolve into private address space.Tells youShows where mailfor the domainis delivered; it does not connect tothose
before
—after
Ping testMeasureMeasures reachability and round-trip timeby openingwith repeated TCP connections to a host,reportingportevery(defaultattempt443),plusreturningtheeverycountattempt, sent and received counts, packet losspercentage
before
—after
Port checkOpen aOpens TCPconnectionconnections to one port ormorea list of up to 10 ports on a host andreportreports each as open, closed or filtered, with the timethe attempt took. Pass a single port or a list of up to 10; a single-port call also gets its answer flat, exactly as before the list form existed.taken. partial=true means not everyrequestedportwasansweredinsidewithin
before
—after
Redirect checkFollowFollows a URL'sHTTPredirect chain hop by hop andreturn every stepreturnswitheachitsstep's statuscode, source and target, the final URL and status, the hop count, and warnings forchains that loop, drop from HTTPS to HTTPloops,or run longer than they should. Answers where a URL endsHTTPS-to-HTTPupdowngrades andhow many round trips that costs; it returns neither
before
—after
Response timeMeasureMeasures how fast a URL answersby takingover several samplesand, returning eachonesample plus min, average and max milliseconds, the HTTP status and anup`up` flag. partial=true means fewer samplescame backreturned thanwere requested,requested.soMeasures theaverage rests on a smaller base. This measures theHTTP
before
—after
Reverse DNSResolveResolves a public IP address to the PTR hostnames published for it,returning every name the pointer record carries,or returns the resolver's error where there is none. A ⟨10 unchanged words⟩ it names the host rather than necessarily thesite running on it, andsite; a missing PTR is common and not a fault.It is not the inverse of check_dns: a forward recordForward andareversePTRrecords need not agree, and this call does notverifycheck that they do. Anonymousand
before
—after
SPF checkFetchFetches a domain's SPF record andevaluate theevaluatespolicyit:theraw record,everyparsedtermterms withits qualifierqualifiers,the number ofDNS lookupsit costscounted against the RFC 7208 limit of ten, the finalall`all` qualifier, and warnings forthe failure modes that
before
—after
Website statusIsChecks whether a website is up rightnow? Start here for any is-the-site-down questionnow: up/down verdict, HTTP status andstatustext, response timein milliseconds,theserver header andthenumber of redirectsfollowed,followed.inTheoneusualcall.first
before
—after
WHOISRetrieveRetrieves WHOIS registration data for a domain: registrar, ⟨8 unchanged words⟩ nameservers and the contact roles the registry stillpublishes. Registries redactpublishes (personal datasince GDPR, so contacts areis usuallyroles withoutredacted).names.tldSupported=falseNotmeanseverythe TLD hasano
Certificate recorded, valid to 2026-12-07
Authorization not required
First tool surface recorded: 20 tools (server version 1.6.0)
Showing the latest 4 events. The API returns up to 500 and filters by kind: ?kind=tool_surface_changed
{"openWorldHint":true,"readOnlyHint":true,"title":"Check DNS"}
{"openWorldHint":true,"readOnlyHint":true,"title":"Check SSL"}
{"openWorldHint":true,"readOnlyHint":true,"title":"DKIM check"}
{"openWorldHint":true,"readOnlyHint":true,"title":"DMARC check"}
{"openWorldHint":true,"readOnlyHint":true,"title":"DNS propagation"}
{"openWorldHint":true,"readOnlyHint":true,"title":"DNSBL check"}
{"openWorldHint":true,"readOnlyHint":true,"title":"Domain expiry"}
{"openWorldHint":true,"readOnlyHint":true,"title":"HSTS check"}
{"openWorldHint":true,"readOnlyHint":true,"title":"HTTP headers"}
{"openWorldHint":true,"readOnlyHint":true,"title":"IP geolocation"}
{"openWorldHint":true,"readOnlyHint":true,"title":"MX lookup"}
{"openWorldHint":true,"readOnlyHint":true,"title":"Ping test"}
{"openWorldHint":true,"readOnlyHint":true,"title":"Port check"}
{"openWorldHint":true,"readOnlyHint":true,"title":"Redirect check"}
{"openWorldHint":true,"readOnlyHint":true,"title":"Response time"}
{"openWorldHint":true,"readOnlyHint":true,"title":"Reverse DNS"}
{"openWorldHint":true,"readOnlyHint":true,"title":"SPF check"}
{"openWorldHint":true,"readOnlyHint":true,"title":"Website status"}
{"openWorldHint":true,"readOnlyHint":true,"title":"WHOIS"}