CertaDNS Academy
Domain trust, taught properly
Email authentication and domain security, in deployment order.
- courses
- 12
- lessons
- 236
- total
- 42 h
- certificates
- 13
Start here
Email Authentication Fundamentals
Why spoofing works, what SPF, DKIM and DMARC each assert, and how to reach enforcement without blocking your own mail.
26 lessons · 4 h · no prerequisites
Email Security and Authentication
6 courses · 130 lessons · 23 h
SPF, DKIM, DMARC and alignment — in deployment order.
- Email Authentication FundamentalsWhy spoofing works, what SPF, DKIM and DMARC each assert, and how to reach enforcement without blocking your own mail.Beginner · 26 lessons · 4 h
- SPF PractitionerOperating SPF on a real estate: exact lookup accounting, macros, flattening against dynamic SPF, multi-domain architecture, third-party senders, and a diagnostic method that names the failure.Intermediate · 23 lessons · 4 h
- DKIM PractitionerOperating DKIM: what a signature covers, why it breaks in transit, key records and their tags, selector and rotation strategy, vendor signing, and reading a verification failure down to its cause.Intermediate · 23 lessons · 4 h
- DMARC PractitionerOperating DMARC: every tag including the ones nobody sets, how a receiver finds your policy, reporting at scale, staged enforcement with a rollback, and a triage method for failures.Intermediate · 22 lessons · 4 h
- Advanced Email TrustWhat sits on top of authentication: MTA-STS and DANE for transport, TLS-RPT for evidence, BIMI for the inbox, and the deliverability signals no DNS record can buy.Advanced · 20 lessons · 4 h
- Email Security PractitionerThe capstone: auditing a domain cold, sequencing a programme across an estate, running the three incidents you will actually meet, and saying honestly what none of it stops.Advanced · 16 lessons · 3 h
Domain and Brand Security
6 courses · 106 lessons · 19 h
DNS, DNSSEC, CAA, registrar control and impersonation.
- Domain Security FundamentalsHow a name resolves, what DNSSEC proves, what CAA constrains, and how domains that look like yours are used against you.Beginner · 21 lessons · 4 h
- DNS Security PractitionerOperating a signed zone: key roles and algorithms, the rollover that breaks delegations, authenticated denial and zone walking, CAA against ACME, registrar locks, resilience, and the dangling records that outlive the services behind them.Intermediate · 19 lessons · 3 h
- Domain Abuse & ImpersonationAnalysing a suspicious domain: generating the permutation space, reading registration and infrastructure signals, using Certificate Transparency as a detection channel, and classifying a finding before acting on it.Intermediate · 18 lessons · 3 h
- Brand ProtectionRunning the programme: the monitoring channels and what each one sees, evidence that survives a challenge, the takedown chain and who to approach first, abuse reports that get acted on, and where automation has to stop.Intermediate · 17 lessons · 3 h
- Domain Trust ArchitectureWhere both tracks converge: the four surfaces of domain trust, the controls as one system with a dependency graph, a repeatable estate assessment, honest prioritisation, and making the case to a budget holder.Advanced · 15 lessons · 3 h
- Domain Security PractitionerThe capstone, worked end to end on one estate: a full posture assessment, the impersonation exposure, the findings nobody can fix cleanly, a 30/90/365 plan with an explicit not-doing list, and delivering it to people who will act on it.Advanced · 16 lessons · 3 h