# GET /api/v1/dns/health

> Diagnose a zone's DNS health

- Group: dns
- Tier: R
- Required scope: read:dns
- Docs: https://api.inleed.com/reference/dns/check-dns-health

## Description

Returns derived `checks` (root A points here, MX/spf/dkim/dmarc present, delegated) and an `alerts[]` of human-readable problems for the resolved domain. For the raw records use `list_dns_records`; this composes an answer from them.

## Query parameters

- `input` — string (required). A domain, email address, website URL, or Inleed service id — for example example.se, info@example.se or 42976. Resolved to the owning account automatically, and the resolved target is echoed back in the response. Up to 255 characters.

## Request

```bash
curl -X GET "https://mcp.inleed.com/api/v1/dns/health?input=example.se" \
  -H "Authorization: Bearer inl_live_…"
```

## Response · 200

```json
{
  "target": {
    "input": "example.se",
    "kind": "domain",
    "domain": null,
    "mailbox": null,
    "serviceId": 90714,
    "domainServiceId": null,
    "daUsername": "inleed42",
    "node": "web12",
    "userId": 4821,
    "note": null
  },
  "domain": "example.se",
  "nodeIp": "web12",
  "hostingIps": [],
  "checks": {
    "aRecordPointsHere": "rec_01hx8n3k5p7q9r2s4t6v8w0y03",
    "hasMx": "example.se",
    "hasSpf": "example.se",
    "hasDkim": "example.se",
    "hasDmarc": "example.se",
    "isDelegated": "example.se"
  },
  "aRecords": "rec_01hx8n3k5p7q9r2s4t6v8w0y04",
  "mx": "example.se",
  "nameservers": "example.se",
  "alerts": [
    "example.se"
  ],
  "isHealthy": true
}
```

## Errors

- **400**  — codes: invalid_request
- **401** No token was presented, or the token is revoked, expired or unknown. — codes: unauthorized, token_expired, token_revoked
- **403** The token lacks a required scope, or this account does not own the resource. — codes: insufficient_scope, domain_not_owned
- **404** No such resource for this account. — codes: not_found, record_not_found
- **422** Validation error — codes: validation_failed
- **429** The rate limit for this token is exhausted. See `Retry-After`. — codes: rate_limited
- **500** Something went wrong on our side. The failure is logged against `requestId`. — codes: internal_error

