Domain Security Fundamentals
How a name resolves, what DNSSEC proves, what CAA constrains, and how domains that look like yours are used against you.
- lessons
- 21
- total
- 4 h
- level
- Beginner
You will be able to
- Trace a resolution from the root and name what each step proves
- Walk a DNSSEC chain by hand and locate the broken link
- Read a CAA record set and say which authorities may issue
- Audit registrar controls and name what is missing
- Recognise a dangling record before someone else does
- Classify a lookalike domain and judge whether it is a live threat
Syllabus
1. DNS Architecture
The hierarchy, how a name resolves, and what caching actually delays.
2. Authoritative DNS
Zones, delegation, glue, the records worth knowing, TTL, and dig.
3. DNSSEC
What signing proves, the four record types, walking a chain, and how it breaks.
4. CAA
Constraining which certificate authorities may issue for your domain.
5. Registrar Security
Locks, contacts and expiry — the account that can hand over everything.
6. Subdomain Takeover
Records pointing at services nobody pays for, and how to find them.
7. Typosquatting and Homograph Attacks
Typosquatting, combosquatting, homographs, and where browser defences stop.
8. Domain Monitoring
Certificate Transparency, and scoping monitoring so it produces action.
9. Final assessment
15 scenario questions · 80% to pass · unlimited retakes
What the assessment covers
DNS Security Fundamentals
- Complete every lesson in Domain Security Fundamentals
- Pass the final assessment with at least 80%
CertaDNS Engineering · last reviewed