What the checker tests

A name can be valid DNS and still be a poor hostname. The checker applies the rules that decide whether a name can be published and reached, then flags choices that tend to cause trouble later: labels that collide with other protocols, names that invite phishing when handed to third parties, and certificate assumptions that do not hold.

RuleLimitWhere it comes from
Label length1–63 charactersRFC 1035, section 2.3.4
Whole name253 characters (255 octets on the wire)RFC 1035
Hostname charactersletters, digits, hyphen; no hyphen at either end of a labelRFC 952 and RFC 1123
Leading digitsallowedRFC 1123 relaxed RFC 952
Hyphens in positions 3–4reserved for A-labels such as xn--RFC 5891
Underscore labelsvalid DNS, not valid hostnamesRFC 2181, RFC 8552

Why some valid labels get a warning

Protocol-sensitive labels. Clients look for certain names automatically. Windows can use wpad to discover a web proxy, and Microsoft's DNS server blocks wpad and isatap by default for that reason. Mail clients probe autodiscover and autoconfig. Publishing these by accident, or letting someone else control them, changes how other software behaves.

Trust-sensitive labels. Names such as login, account, pay or secure look official to readers. If a subdomain is given to a third party, those words lend it your credibility, which is why services that hand out subdomains usually reserve them.

Lifecycle labels. staging, old, temp and test describe a moment rather than a service. They are the names most often left pointing at deleted resources, which is how subdomain takeovers start.

Reserved and special-use names. .test, .example, .invalid and .localhost are reserved by RFC 2606 and RFC 6761; .local belongs to multicast DNS (RFC 6762); home.arpa is for home networks (RFC 8375); and ICANN reserved .internal for private use in 2024. None of them can be used for a public site.

Wildcard certificates cover exactly one label

A certificate for *.example.com matches api.example.com but not example.com itself and not v2.api.example.com. The wildcard stands for a single, whole left-most label. Deeper names need their own certificate or a wildcard one level down, such as *.api.example.com. The coverage panel lists exactly which certificate names would match the hostname you entered.

What it does not check

The checker does not look anything up. It cannot tell you whether the name exists, whether you own the parent domain, or where the registrable domain ends (for that you need the Public Suffix List). Use the DNS lookup to see what the name currently resolves to.