Examples and testing guide
Netmin runs checks you choose on your Mac. No Netmin account, login, or sample-file import is needed. This page and the sample text file have stable public addresses and are available without signing in.
Quick start · Results and controls · Local network · Trial and Pro · All tools
A five-minute walkthrough
- Open Netmin and accept the first-launch trial notice. The notice does not start a subscription or request payment.
- Press ⌘K, type a tool name from the table, and select it in the sidebar.
- Enter its sample input. Leave Use custom resolver off for the first DNS check.
- Press ⌘Return or click the run button. Output appears as the check runs, followed by its result.
- Press ⌘1 for Overview or ⌘2 for Raw Output. Use New Lookup or Escape after completion to try another tool.
| Tool | Input | What to look for |
|---|---|---|
| DNS A | min.tools | One or more published IPv4 addresses. |
| HTTP Headers | https://min.tools/netmin/examples/sample.txt | A successful HTTP response with headers. |
| TLS Certificate | min.tools | Certificate identity, issuer, validity, and fingerprint. |
| Mail MX | min.tools | Mail-server records and priorities. |
| CIDR Calculator | 192.0.2.0/28 | A 16-address subnet calculated locally. |
| MAC Formatter | 02-00-00-00-00-01 | 02:00:00:00:00:01. |
For a combined report, choose Network Lookup, enter min.tools, select Quick, and run it. Exact addresses, certificates, timings, and registry data can change. Optional sections may be empty or unavailable.
Results and controls
Use the result header to switch between Overview and Raw output. The Copy Result menu offers raw output, the command, and a structured summary. During the trial or with Pro, use Save Report to export a text file to a location you choose.
To check cancellation, start Network Lookup with Full selected, then click Stop or press Escape while it is running. Start a new lookup afterward. The sidebar search, recent targets, window resizing, and light/dark appearance remain available throughout normal use.
An empty DNS answer, a closed port, a refused connection, and an unsupported service are diagnostic results. They do not require an account or indicate that a feature is locked. A timeout can mean the network blocks that traffic or the destination does not respond. Raw output shows the details.
Local-network setup
Choose Interface Inventory, Gateway and Routes, or DNS Configuration for an immediate view of the reviewing Mac's own network. These tools need no target.
For Local Device Sweep, use an isolated test network you manage, select one of the detected ranges, then run the check. Allow macOS Local Network access when prompted. If permission was denied, enable Netmin under System Settings → Privacy & Security → Local Network.
For positive discovery results, connect a test device to the same network: a Bonjour-capable printer or Mac for Bonjour, a UPnP-enabled router or TV for SSDP, or a Windows/SMB device advertising NetBIOS for Windows Name Discovery. Enter that device's hostname for the last tool. Guest Wi-Fi isolation, VPNs, absent devices, and disabled services can prevent discovery. A public website cannot substitute for a device on the reviewing Mac's LAN.
Trial, purchases, and legal links
The free download includes 30 days of Pro access. During the trial, all tools, structured reports, export, summary copying, and unlimited diagnostic requests are available. No subscription starts automatically.
Open Netmin → Netmin Pro… to view the yearly subscription, lifetime purchase, and Restore Purchases. App Review can exercise purchases using Apple's sandbox purchase flow. After the trial, Free retains all tools and raw output with five new requests per day; a verified Pro purchase restores unrestricted access. Reinstalling should not be used as a way to reset access.
The purchase window's bottom row contains Terms of Use (EULA) and Privacy Policy. These links can be opened without buying anything.
Inputs for all 84 tools
Expand a group to find its tools. The quick-start examples are the easiest starting point. The reference also identifies optional records, expected negative examples, and tools that require a particular device or service.
Reports
| Tool | Example input or setup | Expected behavior |
|---|---|---|
| Network Lookup | min.tools; Depth: Quick | A combined DNS, address, and ownership report. Full adds reachability and service checks; those results depend on the target. |
| Site Report | min.tools | DNS, HTTPS, and certificate sections. Unavailable SSH or mail services are reported separately; a website need not provide those services. |
| My Network Report | No input | A report about the Mac's current connection. Addresses and interfaces depend on the review network. |
| My Public IP | No input | The public address seen by an external IP lookup service. |
Local Network
| Tool | Example input or setup | Expected behavior |
|---|---|---|
| Local Device Sweep | Select a detected test network | Allow Local Network access. Select only a test network you manage; devices and services must be present to appear. See local setup below. |
| ARP Table | No input | Information from this Mac. Empty neighbor caches, no IPv6, no DHCP lease, or an Ethernet-only connection can leave a section empty. |
| IPv6 Neighbors | No input | Information from this Mac. Empty neighbor caches, no IPv6, no DHCP lease, or an Ethernet-only connection can leave a section empty. |
| Bonjour Services | No input | Advertised service types on the local test network. An empty result means no matching announcements were received. |
| SSDP/UPnP Discovery | No input | Responses from a UPnP-enabled router, TV, or other device on the same test network. See local setup below. |
| Windows Name Discovery | Your test Windows/SMB device's hostname | Its advertised NetBIOS name and workgroup. Requires a device with that service enabled; a website cannot supply this result. |
| Gateway and Routes | No input | Information from this Mac. Empty neighbor caches, no IPv6, no DHCP lease, or an Ethernet-only connection can leave a section empty. |
| DNS Configuration | No input | Information from this Mac. Empty neighbor caches, no IPv6, no DHCP lease, or an Ethernet-only connection can leave a section empty. |
| DHCP Lease | No input | Information from this Mac. Empty neighbor caches, no IPv6, no DHCP lease, or an Ethernet-only connection can leave a section empty. |
| Wi-Fi Diagnostics | No input | Information from this Mac. Empty neighbor caches, no IPv6, no DHCP lease, or an Ethernet-only connection can leave a section empty. |
| Interface Inventory | No input | Information from this Mac. Empty neighbor caches, no IPv6, no DHCP lease, or an Ethernet-only connection can leave a section empty. |
IP, Routing and Registration
| Tool | Example input or setup | Expected behavior |
|---|---|---|
| IP Information | 1.1.1.1 | Public address information, registry data, or its reverse-DNS name. This performs a lookup, not a device scan. |
| RDAP IP | 1.1.1.1 | Public address information, registry data, or its reverse-DNS name. This performs a lookup, not a device scan. |
| RDAP Domain | min.tools | Public registration data. Redacted registrant fields and registry referrals are normal. |
| WHOIS | min.tools | Public registration data. Redacted registrant fields and registry referrals are normal. |
| ASN and BGP Lookup | AS13335 | Public routing information for the example network. |
| RPKI Validation | Target: AS13335; IP prefix: 1.1.1.0/24 | Route-origin authorization status from the public registry service. |
| Reverse DNS | 1.1.1.1 | Public address information, registry data, or its reverse-DNS name. This performs a lookup, not a device scan. |
| Ping | 127.0.0.1 | A reachability or route check of the reviewing Mac itself. An external destination can be used on a permitted test network; missing ICMP replies are possible. |
| Traceroute | 127.0.0.1 | A reachability or route check of the reviewing Mac itself. An external destination can be used on a permitted test network; missing ICMP replies are possible. |
DNS
| Tool | Example input or setup | Expected behavior |
|---|---|---|
| DNS Zone Discovery | min.tools; Depth: Quick | A report assembled from published DNS records. A partial result is expected when optional records are absent; complete zone contents are not required. |
| DNS Zone Transfer | localhost (negative example) | No usable authoritative public zone is available for this local name. A successful transfer requires a test zone whose administrator allows transfers; ordinary public domains usually refuse them. |
| DNS A | min.tools | Published records of the selected type. A successful query with no answers means the domain does not publish that record type. |
| DNS AAAA | min.tools | Published records of the selected type. A successful query with no answers means the domain does not publish that record type. |
| DNS CNAME | www.min.tools | An alias record if one is published. A hostname that publishes A/AAAA directly can have no CNAME. |
| DNS NS | min.tools | Published records of the selected type. A successful query with no answers means the domain does not publish that record type. |
| DNS SOA | min.tools | Published records of the selected type. A successful query with no answers means the domain does not publish that record type. |
| DNS TXT | min.tools | Published records of the selected type. A successful query with no answers means the domain does not publish that record type. |
| DNS CAA | min.tools | Published records of the selected type. A successful query with no answers means the domain does not publish that record type. |
| DNS SRV | _submission._tcp.min.tools | A mail-submission service record, if published. No matching answer is a valid result. |
| DNS NAPTR | min.tools | Optional service-rewrite or geographic records. No matching answer is a valid result. |
| DNS LOC | min.tools | Optional service-rewrite or geographic records. No matching answer is a valid result. |
| DNS HTTPS | min.tools | Published records of the selected type. A successful query with no answers means the domain does not publish that record type. |
| DNS SVCB | min.tools | Published records of the selected type. A successful query with no answers means the domain does not publish that record type. |
| DNS TLSA | _443._tcp.min.tools | Certificate-association records or their validation status. A site using ordinary HTTPS may publish no TLSA records. |
| DNS Propagation | min.tools | DNS answers from the selected public resolvers or encrypted DNS endpoint. Resolver access depends on the review network. |
| DNS over HTTPS | min.tools | DNS answers from the selected public resolvers or encrypted DNS endpoint. Resolver access depends on the review network. |
| DNSSEC DS | cloudflare.com | Published DNSSEC data, validation, or delegation information. Some direct queries can be blocked by the review network; NSEC3 is a normal alternative to NSEC. |
| DNSSEC DNSKEY | cloudflare.com | Published DNSSEC data, validation, or delegation information. Some direct queries can be blocked by the review network; NSEC3 is a normal alternative to NSEC. |
| DNSSEC Check | cloudflare.com | Published DNSSEC data, validation, or delegation information. Some direct queries can be blocked by the review network; NSEC3 is a normal alternative to NSEC. |
| DNSSEC Validation | cloudflare.com | Published DNSSEC data, validation, or delegation information. Some direct queries can be blocked by the review network; NSEC3 is a normal alternative to NSEC. |
| DNSSEC Chain Trace | cloudflare.com | Published DNSSEC data, validation, or delegation information. Some direct queries can be blocked by the review network; NSEC3 is a normal alternative to NSEC. |
| DNS NSEC Walk Check | cloudflare.com | Published DNSSEC data, validation, or delegation information. Some direct queries can be blocked by the review network; NSEC3 is a normal alternative to NSEC. |
| DNS Trace | cloudflare.com | Published DNSSEC data, validation, or delegation information. Some direct queries can be blocked by the review network; NSEC3 is a normal alternative to NSEC. |
| Tool | Example input or setup | Expected behavior |
|---|---|---|
| Mail MX | min.tools | Published mail routing or policy records. Optional policies and service records may be absent; Netmin reports that outcome. |
| Mail SPF | min.tools | Published mail routing or policy records. Optional policies and service records may be absent; Netmin reports that outcome. |
| Mail DMARC | min.tools | Published mail routing or policy records. Optional policies and service records may be absent; Netmin reports that outcome. |
| Mail DKIM | review._domainkey.min.tools (negative example) | No answer is expected for this sample selector. A positive check requires the exact selector supplied by the administrator of a mail domain. |
| Mail BIMI | min.tools | Published mail routing or policy records. Optional policies and service records may be absent; Netmin reports that outcome. |
| Mail MTA-STS | min.tools | Published mail routing or policy records. Optional policies and service records may be absent; Netmin reports that outcome. |
| Mail TLS-RPT | min.tools | Published mail routing or policy records. Optional policies and service records may be absent; Netmin reports that outcome. |
| Mail Autodiscover SRV | min.tools | Published mail routing or policy records. Optional policies and service records may be absent; Netmin reports that outcome. |
| Mail Submission SRV | min.tools | Published mail routing or policy records. Optional policies and service records may be absent; Netmin reports that outcome. |
| Mail IMAPS SRV | min.tools | Published mail routing or policy records. Optional policies and service records may be absent; Netmin reports that outcome. |
| Mail TLS Report | localhost (negative example) | Connection results for mail services on the reviewing Mac. Closed ports are expected unless a local mail test service is running. For positive handshakes, use a mail test server you manage. |
| SMTP STARTTLS | localhost:25 (negative example) | A local connection refusal when no SMTP test service is running. A positive STARTTLS test requires a mail server offering it on the specified port. |
| DANE Validation | _443._tcp.min.tools | Certificate-association records or their validation status. A site using ordinary HTTPS may publish no TLSA records. |
TLS, Web and Ports
| Tool | Example input or setup | Expected behavior |
|---|---|---|
| TLS Certificate | min.tools | The website's certificate details or negotiated TLS connection. |
| TLS Handshake | min.tools | The website's certificate details or negotiated TLS connection. |
| TLS Service Handshake | min.tools:443 | The certificate chain or selected TLS protocol. Protocol support depends on both the system TLS utility and the server. |
| TLS Certificate Chain | min.tools:443 | The certificate chain or selected TLS protocol. Protocol support depends on both the system TLS utility and the server. |
| TLS 1.2 Handshake | min.tools:443 | The certificate chain or selected TLS protocol. Protocol support depends on both the system TLS utility and the server. |
| TLS 1.3 Handshake | min.tools:443 | The certificate chain or selected TLS protocol. Protocol support depends on both the system TLS utility and the server. |
| DNS over TLS Endpoint | one.one.one.one | TLS connection details for a public DNS-over-TLS endpoint. The network must allow outbound TCP 853. |
| HTTP Headers | https://min.tools/netmin/examples/sample.txt | Response headers, any published security headers, or HTTP status and protocol. The sample text file returns a normal successful response. |
| HTTP Security Headers | https://min.tools/netmin/examples/sample.txt | Response headers, any published security headers, or HTTP status and protocol. The sample text file returns a normal successful response. |
| HTTP Protocol | https://min.tools/netmin/examples/sample.txt | Response headers, any published security headers, or HTTP status and protocol. The sample text file returns a normal successful response. |
| Security.txt | min.tools | The published policy file, or a clear missing-document result. Not every website publishes security.txt. |
| Robots.txt | min.tools | The published policy file, or a clear missing-document result. Not every website publishes security.txt. |
| HSTS Preload Status | min.tools | Public preload status or certificate-log data. External service availability can affect the result. |
| Certificate Transparency | min.tools | Public preload status or certificate-log data. External service availability can affect the result. |
| TCP Port Check | min.tools:443 | A successful connection to the website's HTTPS port. |
| Common Port Scan | 127.0.0.1 | Open/closed results for common ports on the reviewing Mac only. All ports may be closed; use an isolated managed test host for positive service examples. |
| SSH Host Keys | localhost (negative example) | No keys if Remote Login is disabled. A positive result requires a managed SSH test host; do not enable remote access solely to follow this guide. |
Utilities
| Tool | Example input or setup | Expected behavior |
|---|---|---|
| CIDR Calculator | 192.0.2.0/28 | The subnet boundaries and size, calculated locally. This documentation address is not contacted. |
| IP Range Expander | 192.0.2.0/30 | Four documentation addresses, expanded locally without contacting them. |
| Punycode Converter | xn--bcher-kva.example | The Unicode form bücher.example; no live website is required. |
| MAC Formatter | 02-00-00-00-00-01 | 02:00:00:00:00:01, calculated locally. |
| NTP Offset | time.apple.com | Clock-offset information if the network permits NTP traffic. |
| Network Quality | No input | Upload, download, and responsiveness measurements for this connection. This test transfers data and takes longer than a DNS lookup. |
Report a problem
If a step fails, include the tool name, sample input, Netmin and macOS versions, and the message shown in Raw output when contacting support. Remove private addresses and diagnostic data before posting publicly.