One tab, every tool you need.
Your one-stop shop for networking, DNS, security, and developer tools. Subnet calculator, port checker, DNS lookup, SSL inspector, security headers, email security and more.
Instant results, shareable links, free forever. Built for engineers, sysadmins, developers, and security professionals.
No account · No ads · No tracking · No rate limits · Free for humans
Quick Access
All Tools
MyNet
Your real public IP address as seen by the internet, with ISP, location and network details.
Instantly check whether your connection supports IPv6. See your address, type, /64 prefix and ISP details.
Browser-based download, upload, and latency test from nearby servers.
DNS
Query any DNS record type for any domain - A, AAAA, MX, TXT, CNAME, NS, SOA, CAA. Results come from Cloudflare's global DNS resolver (1.1.1.1).
Check if your DNS changes have propagated globally. Queries 6 public resolvers across Google, Cloudflare, NextDNS, dns.sb, Tiarap, and DNSPod to compare results.
Audit the DNS setup of any domain and get a letter grade with specific fix hints for each failing check.
Resolve and analyze the SPF record for any domain - including recursive include chains, DNS lookup counting, and policy violation detection.
Query MX (Mail Exchanger) records for any domain to see which mail servers handle its inbound email.
Look up the PTR (reverse DNS) record for any IPv4 address. PTR records map IPs back to hostnames.
Check which Certificate Authorities are permitted to issue SSL/TLS certificates for a domain.
Query NS (Name Server) records to find which nameservers are authoritative for a domain.
Query the SOA (Start of Authority) record for any domain to see its primary nameserver, admin contact, and zone timing parameters.
Look up TLSA DNS records for DANE (DNS-Based Authentication of Named Entities) across HTTPS, SMTP, and SMTPS services.
Trace DNS resolution step-by-step from root nameservers to the final answer.
Compare DNS results across four public resolvers and test for NXDOMAIN hijacking - a sign of ISP DNS interception.
Look up DNS SRV records to discover service endpoints. Used by SIP, XMPP, Matrix, Minecraft, Kubernetes and more.
Verify whether a domain has DNSSEC enabled and check the full chain of trust from root to authoritative nameserver.
Build a valid SPF TXT record. Select your email providers, add custom includes and IP ranges, then copy the record into your DNS.
Generate an RSA key pair for DKIM email signing. The public key goes into your DNS as a TXT record. Keep the private key on your mail server.
Compare two DNS zone files. Paste your original and modified zones to see exactly which records changed. Runs entirely in your browser.
Generate a BIND-format reverse DNS zone file from a subnet CIDR. Supports standard /8, /16, /24 subnets and classless /25-/31 delegation per RFC 2317.
Calculators
Enter any IPv4 address and CIDR prefix or dotted subnet mask like 255.255.255.0. Network address, broadcast, host range, and wildcard mask calculate instantly. The built-in visual subnet calculator lets you split and rejoin blocks interactively.
List every IP address in a subnet block. Enter a network address and CIDR prefix - usable hosts, network and broadcast addresses are highlighted.
Allocate subnets of different sizes from one address block. Enter your base network and the number of hosts each subnet needs.
Design your network segmentation - assign VLAN IDs, names, and subnets with live validation and CSV export.
Convert network speeds between Mbps, Gbps, MB/s and more. Estimate file transfer time for any file size and link speed, and calculate link utilisation percentage.
Enter an IPv6 address and prefix to calculate the network address, host range, total address count, and 128-bit binary breakdown.
Convert any IPv4 address to its 32-bit binary representation - and back. Click any bit to toggle it and watch the IP address update instantly.
Aggregate multiple IPv4 CIDR blocks into the smallest single supernet that covers all of them. Useful for route summarisation, firewall rule consolidation, and IP address planning.
Paste a list of IPv4 CIDR blocks and merge overlapping or adjacent ranges into the smallest possible set of non-overlapping prefixes.
Convert a CIDR block to its first and last IP, or find the smallest CIDR that covers two IP addresses.
Split a CIDR block into equal subnets by count or prefix length.
Convert IPv4 to IPv6 representations, or expand and compress any IPv6 address. Results update as you type.
Find unallocated gaps in a CIDR block after accounting for allocated subnets.
Calculate DHCP pool range and total leases from a subnet. Exclude reserved IPs and generate a ready-to-paste config.
Calculate the effective MTU and TCP MSS after adding tunnel and encapsulation overhead to your base MTU.
Lookup
Look up domain registration details - registrar, expiry date, nameservers, and status. Data comes from the RDAP protocol, the modern successor to classic WHOIS.
Look up location, ISP, ASN, timezone, and proxy detection for any IP address.
Find subdomains by searching public Certificate Transparency logs. Results include all subdomains that have ever had an HTTPS certificate issued.
Look up an Autonomous System Number to see the organisation and all announced IP prefixes. Also resolves any IP address to its ASN.
Look up the BGP routing information for any IP address or CIDR prefix. See which AS announces the route, the organisation name, and the parent IP block.
Check how old a domain is and when it expires. Uses WHOIS/RDAP registration data.
Check if an IPv4 address is listed on 15 major DNS-based spam and abuse blacklists (DNSBLs).
Find all domains hosted on an IP address using passive DNS data and web crawl records.
Identify the manufacturer of any network device by its MAC address or OUI.
Validate whether a BGP route has a valid Route Origin Authorization (ROA). Detects potential prefix hijacks and misconfigured RPKI records.
Enter an email address to validate it and grade its domain security, or enter a domain alone to check SPF, DMARC, DKIM, and MX records.
Verify that a DKIM public key is published correctly for a domain and selector.
Paste raw email headers to trace the delivery path, check authentication results, and measure hop-by-hop timing.
Check if a mail server accepts connections on ports 25, 465, and 587. Also tests STARTTLS and TLS security for all MX servers.
Test SMTP TLS security across all MX servers. Checks STARTTLS advertisement, TLS upgrade success, and MTA-STS policy enforcement. Overall grade A-F.
Check the health of your mail exchange servers. Tests IP resolution, PTR match, SMTP port 25 reachability, and STARTTLS capability for each MX record.
Check MTA-STS transport security policy and BIMI brand indicator record for any domain - both in one lookup.
Build a valid DMARC TXT record for your domain. Choose a policy, add a reporting address, and copy the result into your DNS.
Testing
Check if any website is reachable right now. Tested from a Cloudflare edge server - independent of your own connection.
Check a domain’s SSL certificate - expiry date, issuer, covered domains, and whether HTTPS is currently reachable.
Test a specific port, scan all {{count}} common ports, or check which self-hosted services are exposed on any host or IP address - checked from VLANlab global edge servers.
Measure HTTP response time from a Cloudflare edge server to any host. Runs {{count}} measurements and reports min, avg, and max.
Inspect response headers and grade the HTTP security configuration for any URL. One request - raw headers and an A‑F security score side by side.
Trace every HTTP redirect hop for any URL - see status codes, final destination, and timing per step.
Analyze Content Security Policy headers from any URL or paste a CSP string directly. Get a security grade, per-directive breakdown, and actionable violation details.
Detect the technologies powering any website - CDN, web server, CMS, framework, and analytics. Detected from HTTP response headers and HTML source.
Network path summary for any hostname or IP - latency from a Cloudflare edge, geolocation, and ASN. Full hop-by-hop traceroute coming soon.
Check Open Graph tags, Twitter Cards, meta description, favicon, and hreflang for any URL. Preview how your page looks when shared on Facebook, X/Twitter, LinkedIn, and Slack.
Check which HTTP protocol version a website uses and whether it advertises HTTP/3 (QUIC) support via the Alt-Svc header.
Parse the robots.txt file for any website - see crawler rules, blocked paths, and sitemap URLs in a readable format.
Paste a PEM-encoded certificate to decode all its fields. Runs entirely in your browser - nothing is sent to a server.
Connect to a TCP port and read the initial service greeting banner.
Check TLS certificate revocation status via OCSP.
Connect to any WebSocket endpoint from your browser. Send messages and inspect the full frame log with timestamps.
Fire a real preflight OPTIONS request from a global edge server. See what Access-Control headers the server returns and whether your API allows cross-origin requests.
Measure TTFB and HTTP response time for any URL. Results are measured from Cloudflare’s nearest edge, not your browser.
Security
Share a secret that self-destructs after one view. Encrypted in your browser with AES-256-GCM - the server never sees your plaintext.
Generate MD5, SHA-1, SHA-256 and SHA-512 hashes from any text or file. All processing happens in your browser - no data is transmitted.
Check how strong your password is. Your password is never sent to our server - all analysis runs in your browser.
Check if a domain publishes a security.txt file (RFC 9116) with responsible disclosure contact information.
Search Certificate Transparency logs for all SSL/TLS certificates issued for a domain. Detect unauthorized certificates and track your issuance history via crt.sh.
Test if your nameservers allow DNS zone transfers. A server that responds to AXFR queries exposes your full DNS structure including internal hostnames.
Grade any website A+ to F on its HTTP security headers. Checks HTTPS enforcement, HSTS, CSP, X-Frame-Options, and more.
Check if your browser leaks your real IP address through WebRTC, even when using a VPN or proxy. Runs entirely in your browser - no data leaves your device.
Check the abuse reputation score of any IP address. Powered by AbuseIPDB.
DevKit
Paste JSON to format, minify, or validate it instantly. All processing happens in your browser - no data is transmitted.
Paste YAML to format, validate, minify, or convert to and from JSON. All processing happens in your browser - no data is transmitted.
Encode or decode Base64 and URL percent-encoded strings. Supports Unicode. Runs entirely in your browser.
Paste a JWT token to decode its header and payload claims. Runs entirely in your browser - the token is never sent to a server.
Test regular expressions with real-time match highlighting, flag toggles, match details and replace mode. All processing runs in your browser.
Convert between Unix epoch timestamps and human-readable dates. Live counter, seconds and milliseconds both supported.
Break any URL into its components - protocol, hostname, path, port, query parameters and fragment. Runs entirely in your browser.
Encode or decode URL percent-encoded strings. Choose the mode that matches your use case - full URL, query string, or single component.
Pick a schedule from the presets below, or paste any cron expression to see it explained in plain English with the next 5 run times.
Paste two texts to compare them line by line. Changed words are highlighted within each line.
Generate universally unique identifiers in your browser. UUID v4, UUID v1, and ULID - no server, no tracking.
Convert between Unicode international domain names and Punycode (ACE) encoding used in DNS.
Build HTTP request code from a visual form. Fill in the URL, method, headers, auth and body - get curl, fetch, axios or Python snippets ready to paste.
Convert numbers between binary, octal, decimal, and hexadecimal. Type in any field to update all others instantly.
Look up any HTTP status code or check the live status of a URL.
Build Cisco IOS and iptables access control rules visually. Add permit/deny entries and copy the ready-to-paste config.
Cloud
Plan your cloud network layout for AWS, Azure, or GCP. Define subnets, get provider-aware usable host counts, and generate ready-to-run CLI commands and Terraform HCL.
Check whether an IP address belongs to AWS, GCP, or Cloudflare by matching against each provider's official published prefix lists.
Detect overlapping IP address ranges between CIDR blocks. Check a single pair or scan an entire list for conflicts.
Paste an AWS Security Group or Azure NSG JSON to flag overly permissive rules. Detects critical exposures like SSH, RDP, and database ports open to the internet.
Paste an AWS IAM policy, Azure RBAC role definition, or GCP IAM policy JSON to instantly flag dangerous permissions and overpermissive patterns.
Virtualization
Generate paste-ready /etc/network/interfaces entries for Proxmox bridges, bonds, VLANs, and OVS bridges.
Generate esxcli, PowerCLI, and Terraform commands to create vSphere standard or distributed switch port groups.
Generate PowerShell commands to create Hyper-V external, internal, or private virtual switches, with optional VLAN tagging.
Allocate VNI ranges across segments and generate multicast group assignments. Get Linux VTEP, Open vSwitch, and Cisco NXOS deployment commands.
DevOps
Built for engineers
Instant results
Every calculation runs in your browser - no server round-trip, no waiting.
Shareable URLs
Every result has a unique link. Share a subnet layout or IP lookup with one click.
Dark mode first
Designed for engineers who live in terminals. Easy on your eyes at 2am.
No login, no ads
Free forever. No account required, no tracking, no advertisements.
Learn more about what we are building and why.
The one-stop shop engineers actually want.
VLANlab brings together the tools network engineers, sysadmins, DevOps teams, and developers reach for every day. Subnet calculators, DNS lookups, port checkers, SSL inspectors, security header graders, email security validators, traceroutes, and more - all in one place, all free, all instant.
Every result has a unique shareable URL. Every tool works without an account. No ads, no tracking, no rate limits on the web interface. Just open it, use it, and get back to work.