DomainDig is a local-first iOS domain inspection toolkit for DNS, web, ownership, monitoring, reporting, and audit workflows. The app gathers a point-in-time domain snapshot, normalizes it into a canonical DomainReport, and keeps user data on device unless the user exports, shares, or syncs it.
- Domain inspection for DNS records, email security, TLS certificates, HTTP headers, redirects, IP geolocation, reachability, open ports, RDAP, ownership, subdomain discovery, and availability.
- Canonical
DomainReportoutput used by the app UI and exports. - History snapshots with change summaries, risk scoring, notes, and saved domain context.
- Dashboard, watchlist, monitoring, workflows, batch results, integrations, and data portability screens.
- Audit Mode with sessions, checklist progress, reviewer notes, findings, evidence snapshots, audit timelines, and markdown/json/pdf export.
- Backup and restore for tracked domains, history, audit sessions, workflows, monitoring settings/logs, app settings, and local feature metadata.
- Local-first operation with no required backend.
- Optional local API surface for automation-compatible report output.
DomainDig stores local app data in on-device persistence. Backup exports can include tracked domains, lookup history, audit sessions, workflow definitions, monitoring configuration, monitoring logs, app settings, and cached feature metadata. Imports are processed on device.
Network inspection requests are made only to perform the requested domain checks or configured resolver lookups. The app does not require a hosted DomainDig backend.
- Xcode with current iOS SDK support
- iOS Simulator or physical iOS device
- Swift/Xcode support for filesystem-synchronized groups used by the project
- Clone the repository.
git clone https://github.com/zerolabsco/domain-dig.git
- Open
DomainDig.xcodeprojin Xcode. - Select the
DomainDigscheme. - Build and run on a simulator or device.
xcodebuild -project DomainDig.xcodeproj -scheme DomainDig -destination 'platform=iOS Simulator,name=iPhone 16' buildThe app and local API share the canonical report pipeline through DomainInspectionService, DomainReportBuilder, and DomainReportExporter. The Local API's endpoints, response envelope, and v1 compatibility policy are documented in Docs/local-api.md. How the on-device store evolves across app versions is documented in Docs/data-migration.md.
Unit coverage of the deterministic core — DomainReportBuilder, DomainReportExporter, DiffService, DomainDataPortabilityService (merge/replace dedup), the migration runner, and the Local API contract — lives in the DomainDigTests target:
xcodebuild test -project DomainDig.xcodeproj -scheme DomainDig -destination 'platform=iOS Simulator,name=iPhone 16' -only-testing:DomainDigTestsThe DomainDig scheme's test action runs both DomainDigTests and the DomainDigUITests accessibility audit, so a plain xcodebuild test (and CI) exercises both.
DomainDigUITests runs performAccessibilityAudit() over every primary screen,
at default and at the largest accessibility text size.
./Scripts/audit-a11y.sh # oldest supported + newest runtime
./Scripts/audit-a11y.sh floor # oldest supported runtime only (~85s)Findings are reported, not enforced — they are the burndown list for the
accessibility pass. Widen AccessibilityAuditHarness.enforcedAuditTypes to turn
a category into a build failure as each phase lands.
Optional pre-push hook, which runs the floor audit when Swift or project files change:
git config core.hooksPath .githooksSee Docs/ACCESSIBILITY.md for why coverage is split between this script and CI.
See RELEASE_ROADMAP.md for the semver release history from v4.4.1 through the v5.0.0 contract-stabilization milestone.
Contributions are welcome. Keep changes scoped, include tests or build verification when behavior changes, and open a pull request with a clear summary of user-facing impact.
If you discover a security issue, see SECURITY.md.
This project is licensed under the MIT License. See LICENSE.
Questions or feedback: hello@zerolabs.sh