CertaDNS
Skip to lesson

The Estate · lesson 1 of 2

The brief

After this lesson you can

Read an estate description and list what you still have to find out.

The rest of this course works one estate end to end. It is fictional and every element in it is something you will meet.

Calder & Voss

A 40-year-old manufacturer. 1,200 staff. Domains
accumulated since 1996.

calderandvoss.com    primary. Single DNS provider. Unsigned.
cv-industrial.com    marketing. Different provider. Signed —
                     with an expired RRSIG.
calderandvoss.de     managed by a local agency nobody can
calderandvoss.co.uk  contact. Registrar unknown internally.
+ 6 parked domains   discontinued product lines.
                     Two still have MX records.

One CNAME points at a SaaS platform the company
stopped paying for in 2024.
No CAA anywhere.
No transfer lock on the primary. The registrar account
is a shared team login.
Three lookalike domains registered in the last 90 days.
One has an MX and a certificate.
Email authentication sits at p=none, with reports going
to an address nobody reads.

Reading it as findings

StatedAlready a findingStill to establish
Primary unsignedLow, on its ownWhether the team could operate DNSSEC if it were signed
Expired RRSIG on the marketing domainCritical — the domain does not resolve for validating resolversHow long, and whether anyone noticed
Two country domains, agency uncontactableHigh — no control over records or renewalWho is the registrant of record, and when do they expire
Two parked domains with MXHigh — mail can be received as the brandWhether anything is actually reading it
A CNAME to a cancelled platformCritical until proven otherwiseWhether the target name can be claimed
Shared registrar login, no transfer lockCritical — it outranks every other findingWhether MFA exists at all
Three lookalikes, one with MX and a certificateCritical — that one is operationalWhat it serves, and to whom
Mail at p=none, reports unreadHigh, and it is also why you have no evidenceWhich senders exist

What the brief already tells you

  • Two findings are live incidents rather than posture gaps — the expired signature and the lookalike with an MX. Both need work today.
  • One finding outranks everything else: the shared registrar login. It can undo every other remediation.
  • The unread reports are the reason the sender inventory does not exist, which is the dependency the whole email programme sits behind.

The brief is a starting point, not an assessment

Everything above came from reading a description somebody else wrote. The next lesson is about what such a description always leaves out — and those omissions decide more of the plan than anything written down here.

Last reviewed