Skip to main content

Intelligence module

The configuration everything else depends on

Domain configuration is edited rarely, by different people, over many years, and almost never reviewed as a whole. The result is usually a set of records that made sense individually and no longer agree with each other.

Infrastructure expertise from Elite Security Europe.

A domain’s public configuration determines where visitors are sent, where mail is delivered, which certificate authorities may vouch for you, and how quickly any of that can be changed in an emergency.

It is also, in most organisations, an accumulation. A nameserver added during a migration in 2019 that was never removed. A mail record pointing at a platform decommissioned two years ago. A time-to-live value set high for performance which now means a change takes a day to propagate. None of it is wrong exactly; it simply no longer describes the organisation as it currently operates.

This module reads that configuration as published and reports where it is inconsistent, incomplete or likely to cause difficulty when something needs to change quickly.

Scope

What is examined

Read-only lookups against records your domain publishes. No connection is made to any service beyond retrieving the website itself.

Resolution

  • Nameserver records and whether they are consistent
  • Whether nameservers are distributed across providers
  • Address records for the domain and common subdomains
  • Time-to-live values and their operational consequence

Mail routing

  • MX records and their priority ordering
  • Whether routing matches the observable mail provider
  • Records for platforms apparently no longer in use
  • Consistency between routing and authentication policy

Certificates

  • TLS certificate summary from the connection
  • Issuing authority and validity window
  • Whether the certificate covers the names in use
  • CAA records governing which authorities may issue

Transport

  • Whether HTTPS is enforced consistently
  • HSTS policy and its declared duration
  • Redirect behaviour between protocol and hostname variants
  • Whether both www and apex resolve coherently

Text records

  • Verification records and what they indicate
  • Records referencing services apparently no longer in use
  • Policy records for mail transport security
  • Duplication or contradiction between records

Resilience

  • Single points of failure in the resolution path
  • Whether the configuration supports a rapid change
  • Concentration of dependencies on one provider
  • Observable indicators of drift between systems

Nothing in a domain's configuration is secret. What makes an aggregated profile sensitive is that somebody has taken the trouble to assemble it.

Interpretation

What the score reflects

Reflects the consistency and completeness of the domain's public configuration, including nameservers, mail routing and certificate handling.

It is a measure of coherence rather than of security. A domain can be configured impeccably and still be hosted on a compromised server; a passive DNS review would see nothing wrong, correctly, because that is not what it examines.

Where a check cannot be completed — a record type that does not resolve, a lookup that times out — the result is recorded as unknown rather than as absent. This distinction matters particularly here, where an absent record and an unanswered query have entirely different implications.

Commonly surfaced

  • A nameserver from a previous host still delegated
  • All nameservers with a single provider
  • No CAA record, so any authority may issue
  • Verification records for services long since dropped
  • Time-to-live values that make changes slow to take effect
  • Mail routing that does not match the authentication policy
  • Inconsistent handling of www against the apex domain
  • A certificate that does not cover every hostname in use

Example finding

A representative finding

This is an illustration of the report format rather than a result from a real assessment.

Moderate

Certificate Issuance Is Not Restricted

What we found
No CAA record is published for the domain. The current certificate is valid and correctly issued, and covers the hostnames in use.
Why it matters
Without a CAA record, any certificate authority may issue a certificate for your domain. This does not indicate that anything has gone wrong; it means one of the available controls against mis-issuance is not in place. For an organisation handling customer data or transactions, that control is inexpensive relative to what it guards against.
General direction
Publish a CAA record naming the authorities you actually use, including any used indirectly by a hosting platform or CDN. Establish the full list before publishing, since an incomplete record can prevent a legitimate renewal.
How IXSEO can help
DNS & Infrastructure Review, with infrastructure expertise from Elite Security Europe.

Domain verification confirms control of an approved domain resource. It does not automatically authorise active testing of company infrastructure.

Infrastructure expertise from Elite Security Europe

Frequently asked questions

Is this a security assessment?
No. It is a configuration review of information your domain publishes to the entire internet. Everything examined here is available to anyone who runs a lookup. It identifies inconsistency and incompleteness in that configuration, not vulnerabilities, and it involves no probing of any kind.
Why is some detail withheld until we verify the domain?
Because publishing a detailed infrastructure profile of any website to anyone who types its address would be irresponsible, even where each individual fact is public. Aggregation changes the character of information. After ownership is verified, the full picture is available to you.
Do you check DNSSEC?
Its status is not determined by this passive check. Reliable DNSSEC validation requires querying the delegation chain in a way our standard resolution path does not perform, so rather than report a guess we record it as unknown and note that it warrants separate verification.
What is a CAA record and does it matter?
It states which certificate authorities are permitted to issue certificates for your domain. Without one, any authority may issue for you, which broadens the surface for mis-issuance. It takes minutes to publish and is one of the more straightforward improvements available.
Our infrastructure is managed by a third party. Is this useful?
Frequently more so. Configuration drift is most common where several parties have made changes over several years — a nameserver from a previous host, a mail record from a migrated platform, a certificate policy nobody revisited. A review gives you something specific to raise with whoever is responsible.

See what your domain publishes

DNS & Infrastructure is an optional module on the free snapshot. Selecting it will show the verification notice, because parts of the output require ownership to be demonstrated.