The acronyms, explained in plain English.
You should not need a DNS degree to protect your own name. These are the controls that stop impersonation, what each one actually does, and the order to set them in.
Or skip the reading and check your domain, it takes about twenty seconds.
Cloudflare WAF, DNSSEC and CAA: what to actually switch on
Most domains sit on Cloudflare half configured. What the WAF is really for, why DNSSEC order takes domains offline, and the settings worth turning on before you pay for a plan.
Read the article →What building a domain checker taught us about email security
Over 100 parastatal CEOs are facing action over cyber security failings. We built a tool to grade any domain on DMARC, SPF, DNSSEC and CAA, and the first thing it caught was a fault in our own scoring.
The CAA record explained: one line that stops any CA issuing for your domain
Without a CAA record, any certificate authority on earth can issue an HTTPS certificate for your domain. It is free, takes minutes, and almost nobody has one. Here is how it works.
DMARC policy: none, quarantine or reject, and how to move between them
What p=none, p=quarantine and p=reject actually do, why most domains are stuck at none, and the staged path to enforcement that does not take your own email down.
SPF, DKIM and DMARC explained, without the acronyms
The three records that stop anyone sending email as your business, what each one actually does, why two of them are not enough on their own, and the order to set them in.
What is DNSSEC, and why does the order you enable it in matter?
DNSSEC signs your DNS answers so they cannot be forged in transit. Here is what it protects against, why enabling it in the wrong order takes your whole domain offline, and how to check whether you have it.
Stop impersonation. Control access. Protect your business.
Choose the service you need, or book a security review and we will help you identify the correct starting point.
