Glossary
The terms the tools on this site use, defined in plain language and attributed to the specification or convention they come from — email authentication and transport, DNS and redirects, the impersonation tricks the link tools look for, and the date conventions behind the calculators.
Sender Policy Framework (SPF)
A DNS record listing which servers may send mail for a domain. Receiving servers compare the connecting IP against the list. The specification caps the number of DNS lookups a record may trigger at ten, which is where most broken records fail.
DomainKeys Identified Mail (DKIM)
A cryptographic signature added to outgoing mail. The sender signs headers and body with a private key; the recipient verifies it using a public key published in DNS at selector._domainkey.example.com. A valid signature proves the message was not altered in transit.
Domain-based Message Authentication, Reporting & Conformance (DMARC)
The policy layer over SPF and DKIM. It requires the domain that passed authentication to align with the visible From: address, and tells receivers what to do when that fails: nothing (p=none), quarantine, or reject.
Authenticated Received Chain (ARC)
A way of preserving SPF and DKIM results when a message passes through a forwarder or mailing list that legitimately modifies it. Each intermediary seals the results it saw, so the final receiver can see the message was authentic before it was relayed.
Brand Indicators for Message Identification (BIMI)
A standard that shows a sender’s logo beside authenticated mail in inboxes such as Gmail and Apple Mail. It requires DMARC at enforcement, an SVG logo in the Tiny P/S profile, and usually a Verified Mark Certificate.
Verified Mark Certificate (VMC)
A certificate from an authorised issuer (currently DigiCert or Entrust) attesting that the logo in a BIMI record belongs to a registered trademark held by the sending organisation. Most mailbox providers will not display a logo without one.
Mail Transfer Agent Strict Transport Security (MTA-STS)
A published policy declaring that a domain accepts TLS-encrypted SMTP and that senders should refuse to deliver over an unencrypted or untrusted connection. It closes the downgrade attack that opportunistic STARTTLS leaves open.
SMTP TLS Reporting (TLS-RPT)
A companion to MTA-STS: receiving domains publish an address at which sending servers report aggregate TLS connection and policy failures, so a misconfigured certificate shows up as a report rather than as silently lost mail.
Transport Layer Security (TLS 1.3)
The current version of the protocol that encrypts almost all web and mail traffic. It completes its handshake in fewer round trips than TLS 1.2 and requires forward secrecy, so a later key compromise cannot decrypt past sessions.
DNS-over-HTTPS (DoH)
DNS queries carried inside an ordinary HTTPS request, which hides them from anyone watching the network and prevents tampering in transit. It is how the lookup tools here resolve records from the edge.
Registration Data Access Protocol (RDAP)
The structured JSON successor to WHOIS, served by registries under ICANN policy. It returns registration and expiry dates in a machine-readable form, which is why domain age is read from RDAP rather than scraped from a WHOIS page.
Time To Live (TTL)
The number of seconds a resolver may cache a DNS record before asking again. It is the reason a record you changed minutes ago can still return its old value: the answer you see is whatever the cache holds until the TTL expires.
HTTP Redirect (301, 302, 307, 308)
A response telling the browser the resource is somewhere else, with the new address in the Location header. 301 and 308 are permanent, 302 and 307 temporary; 307 and 308 preserve the original request method, where 301 and 302 historically did not.
Redirect Chain
The sequence of hops between the link that was clicked and the page that finally loads. Shorteners and click trackers each add one. Tracing the chain by reading headers reveals the real destination without loading or executing anything at it.
Meta Refresh
A redirect written into the page itself as <meta http-equiv="refresh">, rather than sent as an HTTP status. Because it only takes effect once the HTML is parsed, tools that inspect headers alone miss it, and it is often used to hide the last hop of a chain.
IDN Homograph Attack
A domain registered with lookalike Unicode characters — a Cyrillic а in place of a Latin a, for instance — so that it renders almost identically to a brand it is impersonating. Detection compares the scripts a name mixes rather than the letters it appears to use.
Typosquatting (URL Hijacking)
Registering plausible misspellings of a well-known domain — gogle.com, paypa1.com — to catch mistyped traffic and serve a phishing page or malware to whoever arrives.
Quishing (QR Code Phishing)
A malicious link delivered as a QR code on a poster, invoice or email, so that the URL is never visible as text and is opened on a phone rather than a filtered corporate machine. Decoding the image before scanning it is the defence.
Shannon Entropy
A measure of how unpredictable a string is, in bits. High entropy in a domain name suggests it was generated by an algorithm rather than chosen; in a password it is the honest way to express strength, since it counts guesses rather than character classes.
Chronological Age
Elapsed time since a date of birth, given as years, months and days. It is computed by calendar subtraction rather than by dividing days by 365.25, so the answer depends on the actual lengths of the months and years crossed.
Corrected Age (Adjusted Age)
For a baby born preterm, chronological age minus the weeks of prematurity — the age the child would be had they been born at 40 weeks. Developmental milestones are judged against it, conventionally until about two years.
Gestational Age
The age of a pregnancy counted from the first day of the last menstrual period, written as weeks and days (32w4d). Under Naegele’s rule the estimated due date is that first day plus 280 days, and full term is 39 to 40 completed weeks.
DATEDIF Convention
The whole-unit counting rule spreadsheets use: the difference between two dates in completed years, months or days, truncated rather than rounded. Two years and eleven months is reported as two years — which is why a tool must say which convention it applied.
Leap Year
A 366-day year that keeps the calendar aligned with the solar year. A year is one if divisible by 4, except century years, unless also divisible by 400 — so 2000 was a leap year and 1900 and 2100 are not. February 29 birthdays are the standard edge case.
Proleptic Gregorian Calendar
The Gregorian calendar projected backwards before its 1582 introduction. Date libraries and ISO 8601 use it so that arithmetic over historical dates stays internally consistent, even though those dates were originally recorded in the Julian calendar.
No term matches that. Try a shorter word, or ask us to add it from thecontact page.