CertaDNS

Domain Security Fundamentals

How a name resolves, what DNSSEC proves, what CAA constrains, and how domains that look like yours are used against you.

lessons
21
total
4 h
level
Beginner

You will be able to

  • Trace a resolution from the root and name what each step proves
  • Walk a DNSSEC chain by hand and locate the broken link
  • Read a CAA record set and say which authorities may issue
  • Audit registrar controls and name what is missing
  • Recognise a dangling record before someone else does
  • Classify a lookalike domain and judge whether it is a live threat

Syllabus

  1. 1. DNS Architecture

    The hierarchy, how a name resolves, and what caching actually delays.

    1. The hierarchy, and who the three parties are9 min
    2. How a name resolves11 min
    3. Caching, and why "propagation" is the wrong word8 min
  2. 2. Authoritative DNS

    Zones, delegation, glue, the records worth knowing, TTL, and dig.

    1. Zones, delegation and glue11 min
    2. The records worth knowing, field by field12 min
    3. TTL as a planning constraint8 min
    4. Reading DNS by hand11 min
  3. 3. DNSSEC

    What signing proves, the four record types, walking a chain, and how it breaks.

    1. What DNSSEC protects against9 min
    2. DNSKEY, RRSIG, DS and NSEC12 min
    3. Walking the chain of trust12 min
    4. How DNSSEC breaks in production11 min
  4. 4. CAA

    Constraining which certificate authorities may issue for your domain.

    1. CAA: constraining who may issue11 min
  5. 5. Registrar Security

    Locks, contacts and expiry — the account that can hand over everything.

    1. The account that owns everything8 min
    2. Locks, contacts and expiry10 min
  6. 6. Subdomain Takeover

    Records pointing at services nobody pays for, and how to find them.

    1. Dangling records10 min
    2. Finding them before someone else does10 min
  7. 7. Typosquatting and Homograph Attacks

    Typosquatting, combosquatting, homographs, and where browser defences stop.

    1. How lookalike domains are generated10 min
    2. Combosquatting, and why it is harder8 min
    3. Homographs, IDN and where the protections stop10 min
  8. 8. Domain Monitoring

    Certificate Transparency, and scoping monitoring so it produces action.

    1. Certificate Transparency as a detection channel11 min
    2. Scoping monitoring so it produces action10 min
  9. 9. Final assessment

    15 scenario questions · 80% to pass · unlimited retakes

    What the assessment covers

DNS Security Fundamentals

  • Complete every lesson in Domain Security Fundamentals
  • Pass the final assessment with at least 80%
About the certificates

CertaDNS Engineering · last reviewed