diff --git a/flake.nix b/flake.nix
index 1215be6..336b360 100644
--- a/flake.nix
+++ b/flake.nix
@@ -111,6 +111,16 @@
           allChecks = {
             deploy-rs = lib.deploy-rs.${channels.nixpkgs.system}.deployChecks inputs.self.deploy;
             clicks = lib.clicks.checks channels.nixpkgs;
+            adhoc = let
+              nixFiles = lib.snowfall.fs.get-nix-files-recursive ./.;
+              checkFiles = builtins.filter (lib.clicks.strings.endsWith ".check.nix") nixFiles;
+              importedChecks = lib.forEach checkFiles (file: {
+                name = builtins.unsafeDiscardStringContext (builtins.baseNameOf file);
+                value = import file {
+                  inherit channels lib inputs;
+                };
+              });
+            in builtins.listToAttrs importedChecks;
           };
 
           mergedChecks = lib.trivial.pipe allChecks [
diff --git a/lib/nginx/http/internal/default.nix b/lib/nginx/http/internal/default.nix
index 767bc6f..d5b679e 100644
--- a/lib/nginx/http/internal/default.nix
+++ b/lib/nginx/http/internal/default.nix
@@ -9,6 +9,7 @@
         then {
           "${name}" = lib.attrsets.removeAttrs host [ "www" ];
           "www.${name}" = {
+            inherit (host) dnsProvider;
             routes."~ ^/?([^\r\n]*)$" = lib.home-manager.hm.dag.entryAnywhere (lib.clicks.nginx.http.redirectPermanent "https://${name}/$1");
             service = null;
             enableHttp = host.enableHttp;
diff --git a/lib/nginx/http/internal/lib.nginx.http.internal.design.spec.nix b/lib/nginx/http/internal/lib.nginx.http.internal.design.spec.nix
index 6710523..4d81e3a 100644
--- a/lib/nginx/http/internal/lib.nginx.http.internal.design.spec.nix
+++ b/lib/nginx/http/internal/lib.nginx.http.internal.design.spec.nix
@@ -34,6 +34,7 @@
         _type = "redirect";
         headers = null;
       };
+      dnsProvider = "cloudflare";
       authWith = null;
       service = null;
       enableHttp = false;
@@ -59,6 +60,7 @@
         _type = "redirect";
         headers = null;
       };
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = false;
     };
@@ -93,6 +95,7 @@
           };
         }
       ];
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = false;
     };
@@ -127,6 +130,7 @@
           };
         }
       ];
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = false;
     };
@@ -156,6 +160,7 @@
           };
         }
       ];
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = false;
     };
@@ -177,6 +182,7 @@
         return = "307 https://calibre.clicks.codes/$1";
         priority = 100;
       };
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = false;
     };
@@ -200,6 +206,7 @@
         return = "307 https://calibre.clicks.codes/$1";
         priority = 100;
       };
+      dnsProvider = "cloudflare";
       onlySSL = true;
       addSSL = false;
       useACMEHost = "www.calibre.clicks.codes";
diff --git a/lib/nginx/http/internal/lib.nginx.http.internal.header.spec.nix b/lib/nginx/http/internal/lib.nginx.http.internal.header.spec.nix
index 97756f4..88a438f 100644
--- a/lib/nginx/http/internal/lib.nginx.http.internal.header.spec.nix
+++ b/lib/nginx/http/internal/lib.nginx.http.internal.header.spec.nix
@@ -39,6 +39,7 @@
         _type = "redirect";
         headers = null;
       };
+      dnsProvider = "cloudflare";
       authWith = null;
       service = null;
       enableHttp = false;
@@ -69,6 +70,7 @@
         _type = "redirect";
         headers = null;
       };
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = false;
     };
@@ -108,6 +110,7 @@
           };
         }
       ];
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = false;
     };
@@ -144,6 +147,7 @@
           };
         }
       ];
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = false;
     };
@@ -174,6 +178,7 @@
           };
         }
       ];
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = false;
     };
@@ -196,6 +201,7 @@
         return = "307 https://calibre.clicks.codes/$1";
         priority = 100;
       };
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = false;
     };
@@ -220,6 +226,7 @@
         return = "307 https://calibre.clicks.codes/$1";
         priority = 100;
       };
+      dnsProvider = "cloudflare";
       onlySSL = true;
       addSSL = false;
       useACMEHost = "www.calibre.clicks.codes";
diff --git a/lib/nginx/http/internal/lib.nginx.http.internal.headers.spec.nix b/lib/nginx/http/internal/lib.nginx.http.internal.headers.spec.nix
index 66ced1d..004e439 100644
--- a/lib/nginx/http/internal/lib.nginx.http.internal.headers.spec.nix
+++ b/lib/nginx/http/internal/lib.nginx.http.internal.headers.spec.nix
@@ -47,6 +47,7 @@
         _type = "redirect";
         headers = null;
       };
+      dnsProvider = "cloudflare";
       authWith = null;
       service = null;
       enableHttp = false;
@@ -82,6 +83,7 @@
         _type = "redirect";
         headers = null;
       };
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = false;
     };
@@ -126,6 +128,7 @@
           };
         }
       ];
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = false;
     };
@@ -163,6 +166,7 @@
           };
         }
       ];
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = false;
     };
@@ -193,6 +197,7 @@
           };
         }
       ];
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = false;
     };
@@ -215,6 +220,7 @@
         return = "307 https://calibre.clicks.codes/$1";
         priority = 100;
       };
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = false;
     };
@@ -239,6 +245,7 @@
         return = "307 https://calibre.clicks.codes/$1";
         priority = 100;
       };
+      dnsProvider = "cloudflare";
       onlySSL = true;
       addSSL = false;
       useACMEHost = "www.calibre.clicks.codes";
diff --git a/lib/nginx/http/internal/lib.nginx.http.internal.http.spec.nix b/lib/nginx/http/internal/lib.nginx.http.internal.http.spec.nix
index 4f56d96..2b0e6f1 100644
--- a/lib/nginx/http/internal/lib.nginx.http.internal.http.spec.nix
+++ b/lib/nginx/http/internal/lib.nginx.http.internal.http.spec.nix
@@ -34,6 +34,7 @@
         _type = "redirect";
         headers = null;
       };
+      dnsProvider = "cloudflare";
       authWith = null;
       service = null;
       enableHttp = true;
@@ -59,6 +60,7 @@
         _type = "redirect";
         headers = null;
       };
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = true;
     };
@@ -93,6 +95,7 @@
           };
         }
       ];
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = true;
     };
@@ -127,6 +130,7 @@
           };
         }
       ];
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = true;
     };
@@ -156,6 +160,7 @@
           };
         }
       ];
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = true;
     };
@@ -177,6 +182,7 @@
         return = "307 https://calibre.clicks.codes/$1";
         priority = 100;
       };
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = true;
     };
@@ -200,6 +206,7 @@
         return = "307 https://calibre.clicks.codes/$1";
         priority = 100;
       };
+      dnsProvider = "cloudflare";
       onlySSL = false;
       addSSL = true;
       useACMEHost = "www.calibre.clicks.codes";
diff --git a/lib/nginx/http/internal/lib.nginx.http.internal.https-proxy.spec.nix b/lib/nginx/http/internal/lib.nginx.http.internal.https-proxy.spec.nix
index 77ad490..801230c 100644
--- a/lib/nginx/http/internal/lib.nginx.http.internal.https-proxy.spec.nix
+++ b/lib/nginx/http/internal/lib.nginx.http.internal.https-proxy.spec.nix
@@ -34,6 +34,7 @@
         _type = "redirect";
         headers = null;
       };
+      dnsProvider = "cloudflare";
       authWith = null;
       service = null;
       enableHttp = false;
@@ -59,6 +60,7 @@
         _type = "redirect";
         headers = null;
       };
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = false;
     };
@@ -93,6 +95,7 @@
           };
         }
       ];
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = false;
     };
@@ -127,6 +130,7 @@
           };
         }
       ];
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = false;
     };
@@ -156,6 +160,7 @@
           };
         }
       ];
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = false;
     };
@@ -177,6 +182,7 @@
         return = "307 https://calibre.clicks.codes/$1";
         priority = 100;
       };
+      dnsProvider = "cloudflare";
       authWith = null;
       enableHttp = false;
     };
@@ -200,6 +206,7 @@
         return = "307 https://calibre.clicks.codes/$1";
         priority = 100;
       };
+      dnsProvider = "cloudflare";
       onlySSL = true;
       addSSL = false;
       useACMEHost = "www.calibre.clicks.codes";
diff --git a/modules/nixos/clicks/services/nginx/auxolotl-eval.check.nix b/modules/nixos/clicks/services/nginx/auxolotl-eval.check.nix
new file mode 100644
index 0000000..c6201df
--- /dev/null
+++ b/modules/nixos/clicks/services/nginx/auxolotl-eval.check.nix
@@ -0,0 +1,60 @@
+# SPDX-FileCopyrightText: 2024 Auxolotl Infrastructure Contributors
+# SPDX-FileCopyrightText: 2024 Clicks Codes
+#
+# SPDX-License-Identifier: GPL-3.0-only
+
+{ inputs, lib, channels, ... }:
+let
+  modules = [
+    {
+      system.stateVersion = "24.05";
+    }
+    {
+      fileSystems."/" = {
+        device = "none";
+        fsType = "tmpfs";
+      };
+    }
+    {
+      boot.loader.grub.device = "nodev";
+    }
+    {
+      nixpkgs.config = {
+        allowBroken = true;
+        allowUnfree = true;
+      };
+    }
+    {
+      clicks.services = {
+        nginx = {
+          enable = true;
+
+          hosts = {
+            "aux.computer" = {
+              service = lib.clicks.nginx.http.redirectPermanent "https://auxolotl.org";
+              www = false;
+            };
+
+            "forum.aux.computer" = {
+              service = lib.clicks.nginx.http.redirectPermanent "https://forum.auxolotl.org";
+              www = false;
+            };
+          };
+        };
+      };
+    }
+    {
+      clicks.security.acme = {
+        enable = true;
+        defaults.email = "check@example.com";
+      };
+    }
+  ];
+  libPlusClicks = lib.attrsets.recursiveUpdate channels.unstable.lib {
+    clicks = lib.clicks; # Our own lib is permitted as a requirement... but we're doing this song/dance to stop us, say, relying on snowfall lib/agenix lix/whatever...
+  };
+in (inputs.unstable.lib.nixosSystem {
+  lib = libPlusClicks;
+  system = channels.unstable.system;
+  modules = (lib.attrsets.attrValues inputs.self.nixosModules) ++ modules;
+}).config.system.build.toplevel
