DNSSEC · CAA · DNS integrity
DNS Security Guides
Review DNS security findings that affect trust, certificate issuance policy and externally observable domain configuration.
Scan a domain Explore Domain Security AssessmentDNS security
Find the remediation guide for your finding
Use the check name from a SecuTest report to open the matching operational guide.
Domain Security AssessmentAssess DNS security together with email, TLS, HTTP controls, exposure and reputation from the public internet. Run the related assessment →
DNS securityDNSSEC algorithm strengthDeprecated DNSSEC algorithms reduce cryptographic assurance and may fail modern resolver or policy requirements.Open remediation guide →DNS securityDNSSEC validationBroken DNSSEC can make a signed domain unreachable to validating resolvers, while an unsigned zone lacks cryptographic authenticity for DNS answers.Open remediation guide →DNS securityDangling DNS recordsA DNS record pointing to a retired or unresolved external dependency can break services and may become a subdomain-takeover path if the resource is claimable.Open remediation guide →DNS securitySubdomain takeover riskA claimable third-party target can let an attacker publish content and abuse trust under the organization's domain.Open remediation guide →