CertaDNS
Skip to lesson

Assessing an Estate · lesson 3 of 3

What a score cannot say

After this lesson you can

Use a posture score without letting it stand in for the assessment.

Assumes you have read Evidence per finding.

A posture score compresses an assessment into one number, which is exactly what makes it useful for tracking and dangerous for deciding. Both properties come from the same compression.

What a score is good for

  • Direction over time. Was this estate better last quarter? A single number answers that and a table does not.
  • Comparing domains within one estate, where the same weights were applied to all of them.
  • Getting attention. A number moves a conversation that a list of records does not.

What it cannot say

The score cannot expressBecause
That one missing control matters more than five present onesWeights are fixed in advance and cannot know this estate’s exposure.
That a domain should not be sending at allIt scores what is published, not whether publishing it was right.
That an enforcing policy is over failing mailp=reject scores well whether or not the domain’s own mail passes it.
That a selector nobody can account for existsA present, valid key scores as a positive.
That the registrar account has no MFANot observable from public data at all.
That the business depends on this domain and not that oneNothing in DNS expresses importance.

The third row is the one that catches people. A domain at p=reject whose own mail fails scores near the top of any grader and is having an outage nobody has noticed.

If you publish a score, publish the weights

A score is defensible when a reader can:
   see which checks contributed
   see what each was worth
   reproduce the number from the table

A score is not defensible when it is
   a letter grade with no working shown
   compared across estates with different exposure
   used as the finding rather than as an index to one

Never let the score be the deliverable

The assessment is the table of findings; the score is an index into it. Reporting the number alone produces work aimed at raising the number, which is how a programme ends up deploying BIMI while the primary domain is at p=none — both move the score, and only one of them is security.

Knowledge check

A domain scores highly: p=reject, DNSSEC signed, CAA present, MTA-STS enforcing. What might the score be hiding?

Last reviewed