Academy
Certificates
A CertaDNS Academy certificate records that you completed a course and passed its assessment on a given date. It is not a professional certification, it is not accredited, and it does not expire.
- available now
- 13
- in the full ladder
- 13
- no cost, ever
- Free
Available now
Email Authentication Fundamentals
Requires
- Complete every lesson in Email Authentication Fundamentals
- Pass the final assessment with at least 80%
Demonstrates
- Reads an SPF record and predicts its result for a given sending IP
- Locates and evaluates a domain’s DKIM keys
- Reads a DMARC record and states what a receiver will do with a failing message
- Explains why a message can pass SPF and DKIM and still fail DMARC
- Builds a staged path to enforcement from aggregate-report evidence
SPF Practitioner
Requires
- Complete every lesson in SPF Practitioner
- Pass the SPF Practitioner assessment with at least 80%
Demonstrates
- Walks an SPF evaluation term by term and names the result code
- Reads and writes macros, including exists-based per-IP authorisation
- Audits a record against both RFC 7208 limits with the working shown
- Chooses between flattening, delegation and dynamic SPF on the merits
- Designs SPF across subdomains, brands and non-sending domains
- Diagnoses permerror and temperror from evidence rather than by guessing
DKIM Practitioner
Requires
- Complete every lesson in DKIM Practitioner
- Pass the DKIM Practitioner assessment with at least 80%
Demonstrates
- Reads a DKIM-Signature header tag by tag and states what it commits to
- Predicts whether a signature survives forwarding, a list or a gateway
- Reads a key record’s size, flags and revocation state from the record itself
- Designs a selector scheme and a rotation with a defensible overlap window
- Names the cause of a verification failure from the result alone
- Judges a vendor signing arrangement, including shared signing keys
DMARC Practitioner
Requires
- Complete every lesson in DMARC Practitioner
- Pass the DMARC Practitioner assessment with at least 80%
Demonstrates
- Writes a policy record that says what was intended, including sp and np
- Predicts which policy a receiver applies to a given subdomain
- States what aggregate reports do and do not contain
- Authorises an external report destination and verifies it
- Stages enforcement against evidence, with a rollback defined in advance
- Triages a DMARC failure to a cause from the headers alone
Advanced Email Trust
Requires
- Complete every lesson in Advanced Email Trust
- Pass the Advanced Email Trust assessment with at least 80%
Demonstrates
- Explains the attack opportunistic TLS is open to, and what closes it
- Deploys and changes an MTA-STS policy without losing mail
- Reads a TLS report and names the failure it describes
- Reads a TLSA record and says when DANE is available to a domain at all
- Chooses between DANE and MTA-STS on the merits
- States what BIMI requires, costs, and does not prove
Email Security Practitioner
Requires
- Complete every lesson in Email Security Practitioner
- Pass the Email Security Practitioner assessment with at least 80%
Demonstrates
- Audits a domain from public DNS and ranks findings by consequence
- Writes findings that lead to action rather than to a filed report
- Sequences an authentication programme across an estate
- Runs a spoofing campaign, an enforcement outage and a compromised sender
- Explains residual risk to people who do not operate DNS
- Holds a third-party sender to an alignment commitment
- States plainly what email authentication does not stop
DNS Security Fundamentals
Requires
- Complete every lesson in Domain Security Fundamentals
- Pass the final assessment with at least 80%
Demonstrates
- Traces a resolution from the root and names what each step proves
- Walks a DNSSEC chain of trust by hand and locates a broken link
- Reads a CAA record set and says which authorities may issue
- Audits registrar-level controls and names what is missing
- Recognises a dangling record and classifies a lookalike domain by technique
DNS Security Practitioner
Requires
- Complete every lesson in DNS Security Practitioner
- Pass the DNS Security Practitioner assessment with at least 80%
Demonstrates
- Reads a zone’s key set and identifies its signing arrangement
- Chooses a DNSSEC algorithm and names what to migrate off
- Performs a KSK rollover without breaking the delegation
- States what an attacker learns from a zone’s authenticated denial
- Writes a CAA set that constrains issuance without blocking ACME
- Distinguishes a transfer lock from a registry lock in RDAP output
- Finds dangling CNAME, NS and MX records and retires services safely
Domain Impersonation Analyst
Requires
- Complete every lesson in Domain Abuse & Impersonation
- Pass the Domain Abuse & Impersonation assessment with at least 80%
Demonstrates
- Generates a permutation space and cuts it to what is worth watching
- Reads registration signals without mistaking privacy for guilt
- Escalates on infrastructure signals and ranks them correctly
- Uses Certificate Transparency as a detection channel and states its limits
- Classifies a domain into one of four outcomes with a defensible rationale
- Accounts for the cost of misclassification in both directions
Brand Protection Practitioner
Requires
- Complete every lesson in Brand Protection
- Pass the Brand Protection assessment with at least 80%
Demonstrates
- Chooses monitoring channels and states the coverage of each
- Detects a cloned site from signals that are costly to change
- Decides when a defensive registration pays for itself
- Assembles an evidence package that survives a challenge
- Chooses the right party in the takedown chain to approach first
- Writes an abuse report that is acted on rather than filed
Domain Trust Architecture
Requires
- Complete every lesson in Domain Trust Architecture
- Pass the Domain Trust Architecture assessment with at least 80%
Demonstrates
- Defines domain trust generically and names its four surfaces
- Draws the dependency graph between the controls
- Sequences a programme and identifies what cannot be parallelised
- Runs a repeatable estate assessment with evidence per finding
- States the limits of any scoring scheme, including their own
- Makes the case to a budget holder without scare tactics
Domain Security Practitioner
Requires
- Complete every lesson in Domain Security Practitioner
- Pass the Domain Security Practitioner assessment with at least 80%
Demonstrates
- Assesses a whole estate and produces an evidenced finding per domain
- Quantifies an impersonation exposure from public data alone
- Handles a domain whose administrator cannot be contacted
- Sequences remediation around constraints that cannot be removed
- Writes a 30/90/365 plan with owners and go/no-go criteria
- Defends an explicit list of what is not being done, and why
Domain Trust Practitioner
Requires
- Hold the Email Security Practitioner credential
- Hold the Domain Security Practitioner credential
Demonstrates
- Holds both track capstones, covering identity, integrity, transport and perception
- Assesses an estate end to end and ranks findings by what each one permits
- Runs an email authentication programme from reporting to enforcement
- Runs a domain and brand security programme from detection to takedown
- States what none of it stops, and who owns the controls that do
The full ladder
- Email Authentication FundamentalsAvailable
- SPF PractitionerAvailable
- DKIM PractitionerAvailable
- DMARC PractitionerAvailable
- Advanced Email TrustAvailable
- Email Security PractitionerAvailable
- DNS Security FundamentalsAvailable
- DNS Security PractitionerAvailable
- Domain Impersonation AnalystAvailable
- Brand Protection PractitionerAvailable
- Domain Trust ArchitectureAvailable
- Domain Security PractitionerAvailable
- Domain Trust Practitionerend stateAvailable