IQsolutions.dev
Toolbox
Everyday security and email tools for IT support. Passwords and headers are handled entirely on your device. DNS tools look things up live.
Generator
Select a mode and tune the parameters
Password Length
Character Sets
Number of Words
Passphrase Options
Corporate Options
Preview Pattern
Number and symbol go in a random spot each time.
Session History
Last 20 items · memory only, never saved to disk
Password Strength
Measured the same way as the checker
Generate a password to see the analysis.
Time to crack
Tap a row to see what that situation means
Security Information
Composition & complexity report
- Password Type
- —
- Character Count
- —
- Guesses Needed
- —
- Security Rating
- —
- Character Sets Used
- none
- Complexity Summary
- —
Best Practice
Security guidance
- Use a unique password for every single system.
- Store credentials in an approved password manager.
- Enable multi-factor authentication wherever available.
- Prefer 16+ characters for administrative accounts.
- Never send passwords over unencrypted e-mail or chat.
Check a password
It's analysed on this device and never saved or sent anywhere
Separate with commas. If the password contains any of these, it counts as easy to guess.
How an attacker would read it
How the rating works
Three ways of guessing, and the quickest one wins
Counting uppercase letters and symbols says little on its own. P@ssw0rd2024 ticks every box
and still falls in seconds, because cracking tools try leaked passwords, dictionary words, names, dates and
keyboard patterns long before anything else. So this works out how many guesses three different attacks would
need and keeps the lowest, since an attacker gets to pick the easiest one: known patterns, the recipe the
Generate tab builds passwords with, and plain brute force. The Generate tab runs this same check, so a
password reads the same on both screens.
Time to crack
Tap a row to see what that situation means
Policy checklist
Recommended for business accounts
Check email headers
Paste the headers of a suspicious message. Nothing leaves this device.
Paste headers above to see who really sent the message.
What stands out
Delivery route
Every server that handled the message, oldest first
Each line is one server handing the message to the next. The time is how long that step took, so a big gap shows where a slow message got stuck. The first line is where it really came from, which is far harder to fake than the From address.
Sender authentication
What the receiving server recorded
Message
The fields the recipient sees, and the ones they don't
What this can and can't tell you
Read before acting on a result
This reads what the receiving mail server already wrote into the headers: whether SPF, DKIM and DMARC passed, which servers handled the message, and what the spam filter decided. It runs entirely here, so the headers, the internal addresses and the IP addresses in them never leave this device. It can't re-check a signature or look up a DNS record. For a sender's live SPF, DKIM and DMARC setup, use Email health. A pass means nothing obvious is wrong, not that the message is genuine.
DNS and MX lookup
Type a domain, or an IP for a reverse lookup
Resolver check
Two public resolvers, asked at the same time
- Status
- Run a lookup to see results.
About these lookups
What leaves your device
Browsers can't speak DNS directly, so each lookup goes to Cloudflare (1.1.1.1) and Google (8.8.8.8) over HTTPS. They see the name you look up and your IP address, nothing else. If the two answers differ, a change is probably still spreading, or the site gives different answers by region (common with CDNs). Results are cached by the resolvers for the record's TTL, so a fresh edit can take that long to show. The registrar and dates come from RDAP through rdap.org, which asks the domain's registry.
Email health check
MX, SPF, DKIM and DMARC for one domain
Enter a domain to check how its email is set up.
Scorecard
One line per check
What each check means
In plain terms
- MX says which servers receive the domain's mail.
- SPF lists the servers allowed to send for it. It's limited to 10 DNS lookups.
- DKIM publishes the key that proves a message wasn't altered.
- DMARC tells receivers what to do when SPF and DKIM fail, and where to send reports.
Only the domain name is sent, to Cloudflare and Google DNS. DKIM can't be proven from DNS alone: a missing selector here may just be one this tool didn't guess.
Blacklist and reverse DNS
For an IP, or for a domain's mail servers
Lists checked
Public lists that answer over DNS
Check by hand
These lists refuse lookups from public resolvers
Spamhaus, the most important list, doesn't answer queries that arrive through public DNS, so it can't be checked here honestly. Use the links below with the same IP.
Reading the result
Reverse DNS matters too
A mail server should have a reverse DNS (PTR) name that resolves back to the same IP. Many receivers reject or down-rank mail from servers where it doesn't. Being on one small list rarely blocks mail by itself; being on several, or on a big one, usually does.
Glossary
What everything here means
Short, plain explanations of the terms and results you'll meet in the Toolbox.
Reading the results
The colours and labels you'll see in every tool
- Pass
- Nothing wrong was found for this check.
- Review
- Not broken, but worth a look or an easy improvement.
- Problem
- Something is missing or set up wrong and should be fixed.
- Info
- Good to know, but neither good nor bad on its own.
Passwords
Generator and checker
- Guesses needed
- How many tries an attacker would need. It's shown as a power of ten, so 10^12 means about a trillion guesses.
- Time to crack
- How long those guesses would take in four situations, from a login page that locks accounts to stolen password databases cracked on graphics cards.
- Rate-limited login
- A login page that locks or slows down after a few wrong tries, like Microsoft 365 or a VPN.
- Leaked database and hash
- When a site is hacked, attackers get the stored passwords in scrambled form (hashes). Fast hashes like MD5 or NTLM can be guessed billions of times per second. Slow ones like bcrypt or Argon2 are far harder.
- Pattern
- A shortcut attackers try first: leaked passwords, dictionary words, names, dates, keyboard walks like qwerty, repeats and letter swaps.
- Letter swaps
- Replacing letters with look-alike symbols, like @ for a. It looks complex, but cracking tools try it first.
- Memorable and Corporate
- Memorable joins several random words. Corporate is adjective, noun, number and symbol, the style helpdesks often hand out. Both are easier to guess than a random string of the same length.
Email headers
What the header check reads
- Headers
- The hidden technical lines at the top of every email: who sent it, which servers passed it along and what the receiving server decided.
- SPF
- A list, published in DNS, of the servers allowed to send email for a domain.
- DKIM
- A digital signature added by the sending server and checked against a public key in DNS. It shows the message wasn't altered and came from that domain.
- DMARC
- The domain owner's rule for what to do when SPF and DKIM don't line up with the From address: nothing, spam folder or block. It also asks for reports.
- Alignment
- Whether the domain that passed SPF or DKIM is the same one shown in the From address. DMARC passes when at least one lines up.
- ARC
- A record that lets forwarders and mailing lists pass along the original results, so legitimate forwarded mail isn't judged unfairly.
- Return-Path
- Where bounce messages go. It can differ from From, especially with mailing lists and newsletter services.
- Reply-To
- Where your reply will go. If it differs from From, take a second look.
- Delivery route
- Every server that handled the message. The first one is where it really entered the mail system, and it is far harder to fake than the From address.
- TLS
- Encryption between two mail servers. No TLS means the message may have travelled unencrypted on that step.
- SCL
- Microsoft's spam score, from 0 (clean) to 9 (certain spam). 5 and above is treated as spam.
Email health
What the live domain check looks at
- MX record
- Says which servers receive email for the domain. The lowest priority number is tried first.
- The 10 lookup limit
- Every include, a, mx or similar in an SPF record costs a DNS lookup. Past 10, receivers treat SPF as broken.
- -all and ~all
- How an SPF record ends. -all rejects mail from servers not on the list. ~all marks it as suspicious (softfail).
- DKIM selector
- A name that lets a domain publish several DKIM keys. Find yours in the s= value of a DKIM-Signature header.
- DMARC policy
- none only monitors, quarantine sends to spam, reject blocks the message.
- Aggregate reports
- The address (rua) that receives DMARC reports about who is sending as your domain.
- MTA-STS, TLS-RPT and BIMI
- Optional extras. MTA-STS forces encrypted delivery, TLS-RPT sends reports about failures and BIMI shows your logo in supporting mail apps.
DNS records
What each record type is for
- A and AAAA
- The IPv4 and IPv6 address a name points to.
- CNAME
- An alias: this name is really another name.
- NS
- The servers that hold the domain's DNS records.
- TXT
- Free text stored in DNS. It's used for SPF, DKIM, DMARC and ownership checks.
- SOA
- Administrative details of a DNS zone: primary server, admin contact, serial number and refresh timers.
- CAA
- Which certificate authorities may issue HTTPS certificates for the domain.
- PTR
- A reverse lookup: the name an IP address points back to.
- TTL
- How long, in seconds, a resolver may keep a record before asking again. It's why DNS changes take time to spread.
- Resolver
- The server that looks up DNS answers for you. Here that's Cloudflare (1.1.1.1) and Google (8.8.8.8).
- NXDOMAIN
- The name doesn't exist.
- Registrar and DNS provider
- The registrar is where the domain name was bought and is renewed. The DNS provider is who answers for it. They are often different companies, and each change happens at its own place.
- RDAP
- The registries' public lookup, the modern replacement for WHOIS. It tells who the registrar is and when the domain expires.
- Transfer lock
- A flag that stops the domain from being moved to another registrar without permission. It's normally on.
- DNSSEC
- Signatures that prove DNS answers weren't tampered with. Not signed means the domain doesn't use it.
Blacklists
What the reputation check means
- Blacklist
- A public list of IP addresses linked to spam or abuse. Many mail servers check it and reject mail from listed IPs.
- Listed, not listed and no answer
- Listed means the IP is on that list. Not listed means it isn't. No answer means the list didn't respond or doesn't accept public resolvers, which is not the same as clean.
- Reverse DNS match
- A mail server should have a PTR name that resolves back to the same IP. Receivers use that match as a sign the server is set up properly.