CertaDNS
Academy

Certificates

A CertaDNS Academy certificate records that you completed a course and passed its assessment on a given date. It is not a professional certification, it is not accredited, and it does not expire.

available now
13
in the full ladder
13
no cost, ever
Free

Available now

Email Authentication Fundamentals

Requires

  • Complete every lesson in Email Authentication Fundamentals
  • Pass the final assessment with at least 80%

Demonstrates

  • Reads an SPF record and predicts its result for a given sending IP
  • Locates and evaluates a domain’s DKIM keys
  • Reads a DMARC record and states what a receiver will do with a failing message
  • Explains why a message can pass SPF and DKIM and still fail DMARC
  • Builds a staged path to enforcement from aggregate-report evidence
Start Email Authentication Fundamentals

SPF Practitioner

Requires

  • Complete every lesson in SPF Practitioner
  • Pass the SPF Practitioner assessment with at least 80%

Demonstrates

  • Walks an SPF evaluation term by term and names the result code
  • Reads and writes macros, including exists-based per-IP authorisation
  • Audits a record against both RFC 7208 limits with the working shown
  • Chooses between flattening, delegation and dynamic SPF on the merits
  • Designs SPF across subdomains, brands and non-sending domains
  • Diagnoses permerror and temperror from evidence rather than by guessing
Start SPF Practitioner

DKIM Practitioner

Requires

  • Complete every lesson in DKIM Practitioner
  • Pass the DKIM Practitioner assessment with at least 80%

Demonstrates

  • Reads a DKIM-Signature header tag by tag and states what it commits to
  • Predicts whether a signature survives forwarding, a list or a gateway
  • Reads a key record’s size, flags and revocation state from the record itself
  • Designs a selector scheme and a rotation with a defensible overlap window
  • Names the cause of a verification failure from the result alone
  • Judges a vendor signing arrangement, including shared signing keys
Start DKIM Practitioner

DMARC Practitioner

Requires

  • Complete every lesson in DMARC Practitioner
  • Pass the DMARC Practitioner assessment with at least 80%

Demonstrates

  • Writes a policy record that says what was intended, including sp and np
  • Predicts which policy a receiver applies to a given subdomain
  • States what aggregate reports do and do not contain
  • Authorises an external report destination and verifies it
  • Stages enforcement against evidence, with a rollback defined in advance
  • Triages a DMARC failure to a cause from the headers alone
Start DMARC Practitioner

Advanced Email Trust

Requires

  • Complete every lesson in Advanced Email Trust
  • Pass the Advanced Email Trust assessment with at least 80%

Demonstrates

  • Explains the attack opportunistic TLS is open to, and what closes it
  • Deploys and changes an MTA-STS policy without losing mail
  • Reads a TLS report and names the failure it describes
  • Reads a TLSA record and says when DANE is available to a domain at all
  • Chooses between DANE and MTA-STS on the merits
  • States what BIMI requires, costs, and does not prove
Start Advanced Email Trust

Email Security Practitioner

Requires

  • Complete every lesson in Email Security Practitioner
  • Pass the Email Security Practitioner assessment with at least 80%

Demonstrates

  • Audits a domain from public DNS and ranks findings by consequence
  • Writes findings that lead to action rather than to a filed report
  • Sequences an authentication programme across an estate
  • Runs a spoofing campaign, an enforcement outage and a compromised sender
  • Explains residual risk to people who do not operate DNS
  • Holds a third-party sender to an alignment commitment
  • States plainly what email authentication does not stop
Start Email Security Practitioner

DNS Security Fundamentals

Requires

  • Complete every lesson in Domain Security Fundamentals
  • Pass the final assessment with at least 80%

Demonstrates

  • Traces a resolution from the root and names what each step proves
  • Walks a DNSSEC chain of trust by hand and locates a broken link
  • Reads a CAA record set and says which authorities may issue
  • Audits registrar-level controls and names what is missing
  • Recognises a dangling record and classifies a lookalike domain by technique
Start Domain Security Fundamentals

DNS Security Practitioner

Requires

  • Complete every lesson in DNS Security Practitioner
  • Pass the DNS Security Practitioner assessment with at least 80%

Demonstrates

  • Reads a zone’s key set and identifies its signing arrangement
  • Chooses a DNSSEC algorithm and names what to migrate off
  • Performs a KSK rollover without breaking the delegation
  • States what an attacker learns from a zone’s authenticated denial
  • Writes a CAA set that constrains issuance without blocking ACME
  • Distinguishes a transfer lock from a registry lock in RDAP output
  • Finds dangling CNAME, NS and MX records and retires services safely
Start DNS Security Practitioner

Domain Impersonation Analyst

Requires

  • Complete every lesson in Domain Abuse & Impersonation
  • Pass the Domain Abuse & Impersonation assessment with at least 80%

Demonstrates

  • Generates a permutation space and cuts it to what is worth watching
  • Reads registration signals without mistaking privacy for guilt
  • Escalates on infrastructure signals and ranks them correctly
  • Uses Certificate Transparency as a detection channel and states its limits
  • Classifies a domain into one of four outcomes with a defensible rationale
  • Accounts for the cost of misclassification in both directions
Start Domain Abuse & Impersonation

Brand Protection Practitioner

Requires

  • Complete every lesson in Brand Protection
  • Pass the Brand Protection assessment with at least 80%

Demonstrates

  • Chooses monitoring channels and states the coverage of each
  • Detects a cloned site from signals that are costly to change
  • Decides when a defensive registration pays for itself
  • Assembles an evidence package that survives a challenge
  • Chooses the right party in the takedown chain to approach first
  • Writes an abuse report that is acted on rather than filed
Start Brand Protection

Domain Trust Architecture

Requires

  • Complete every lesson in Domain Trust Architecture
  • Pass the Domain Trust Architecture assessment with at least 80%

Demonstrates

  • Defines domain trust generically and names its four surfaces
  • Draws the dependency graph between the controls
  • Sequences a programme and identifies what cannot be parallelised
  • Runs a repeatable estate assessment with evidence per finding
  • States the limits of any scoring scheme, including their own
  • Makes the case to a budget holder without scare tactics
Start Domain Trust Architecture

Domain Security Practitioner

Requires

  • Complete every lesson in Domain Security Practitioner
  • Pass the Domain Security Practitioner assessment with at least 80%

Demonstrates

  • Assesses a whole estate and produces an evidenced finding per domain
  • Quantifies an impersonation exposure from public data alone
  • Handles a domain whose administrator cannot be contacted
  • Sequences remediation around constraints that cannot be removed
  • Writes a 30/90/365 plan with owners and go/no-go criteria
  • Defends an explicit list of what is not being done, and why
Start Domain Security Practitioner

Domain Trust Practitioner

Requires

  • Hold the Email Security Practitioner credential
  • Hold the Domain Security Practitioner credential

Demonstrates

  • Holds both track capstones, covering identity, integrity, transport and perception
  • Assesses an estate end to end and ranks findings by what each one permits
  • Runs an email authentication programme from reporting to enforcement
  • Runs a domain and brand security programme from detection to takedown
  • States what none of it stops, and who owns the controls that do

The full ladder

  1. Email Authentication FundamentalsAvailable
  2. SPF PractitionerAvailable
  3. DKIM PractitionerAvailable
  4. DMARC PractitionerAvailable
  5. Advanced Email TrustAvailable
  6. Email Security PractitionerAvailable
  7. DNS Security FundamentalsAvailable
  8. DNS Security PractitionerAvailable
  9. Domain Impersonation AnalystAvailable
  10. Brand Protection PractitionerAvailable
  11. Domain Trust ArchitectureAvailable
  12. Domain Security PractitionerAvailable
  13. Domain Trust Practitionerend stateAvailable