DomainOpsDomainOps

DomainOps Blog

Practical write-ups on domain monitoring, SSL hygiene, DNS security, and the day-to-day mechanics of keeping a portfolio of domains healthy.

·5 min read

DMARC policy: the migration path from p=none to p=reject

How to move your DMARC policy from p=none to p=reject safely: rua reports, pct= staged rollout, SPF/DKIM alignment, and why domains get stuck at none.

dmarcemaildns
·5 min read

Domain Portfolio Management: Best Practices at Scale

Domain portfolio management best practices: consolidating registrars, tracking ownership, budgeting renewals, and solving the 'who owns this domain' problem.

domainsportfoliobest-practices
·5 min read

Domain Monitoring for Agencies: Managing Many Clients at Once

Domain monitoring for agencies: how to manage many clients' domains in per-client portfolios, run white-glove reporting, and avoid the 3am SSL surprise.

agencymonitoringportfolio
·5 min read

Subdomain enumeration: a defensive guide to your own estate

A practical subdomain enumeration guide: passive vs active methods, the data sources that matter, and why you should map your own estate before attackers do.

securitydnsreconnaissance
·5 min read

What is DKIM? Signing, selectors and why it breaks silently

What is DKIM and how does it work? How message signing and DNS public keys work, selector rotation, CNAME delegation, and why DKIM fails without warning.

dkimemaildns
·6 min read

WHOIS Status Codes Explained: What Each EPP Status Means and When to Worry

WHOIS status codes explained: what clientTransferProhibited, clientHold, serverHold, redemptionPeriod and pendingDelete mean — and when to worry.

whoisdomains
·6 min read

Incomplete Certificate Chain: Why Your Site Works in Chrome but Fails in curl

An incomplete certificate chain is why your site works in Chrome but fails in curl, Java or Android. How to diagnose it with openssl and fix it properly.

ssltlsdebugging
·6 min read

HTTP Endpoint Monitoring Explained: Why a 200 Isn't Always Healthy

Endpoint monitoring explained: how status codes really work, sensible response-time thresholds, and why a 200 OK can hide a completely broken application.

endpointsmonitoringuptime
·5 min read

Email deliverability: the DNS-side checklist that keeps you inbox

Email deliverability starts in DNS. The SPF, DKIM, DMARC, MX and PTR levers that decide inbox vs spam, why mail gets filtered, and an auditable checklist.

emaildeliverabilitydns
·6 min read

Let's Encrypt Renewal Failed: The Five Failure Modes Behind Most Expired Certs

Let's Encrypt renewal failed? The common causes — broken certbot cron, blocked port 80, expired DNS API tokens, rate limits — and how to catch failures early.

ssllets-encryptmonitoring
·5 min read

Why Domain Auto-Renewal Is Not Enough on Its Own

Domain auto renewal fails more often than you think: expired cards, registrar emails in spam, transferred-away domains. Here's why, and what to add alongside it.

domainsauto-renewalexpiry
·5 min read

What is DNSSEC? Chain of trust, DS records and rotation risk

What is DNSSEC and how does it work? The chain of trust, DNSKEY and DS records, the DS-rotation outage class, and when enabling DNSSEC is worth it.

dnssecdnssecurity
·6 min read

CVE monitoring for your domains: connect exposure to known flaws

CVE monitoring connects your exposed services to known vulnerabilities. Learn how to prioritise what to patch and why continuous beats point-in-time scanning.

securitycvevulnerability-management
·5 min read

The SSL Certificate Chain Explained

The SSL certificate chain explained: root, intermediate and leaf certs, why a site works in your browser but fails in curl, and how to debug an incomplete chain.

ssltlsdebugging
·5 min read

Bulk WHOIS Lookup: Auditing a Whole Domain Portfolio

A practical bulk WHOIS lookup guide: audit every domain's expiry and registrar at once, work around WHOIS/RDAP rate limits, and keep the data fresh.

whoisdomainstools
·5 min read

Website Uptime Monitoring: A Practical Guide

A practical guide to website uptime monitoring: what to check, the right intervals, beating alert fatigue, and telling a brief blip apart from a real outage.

uptimemonitoring
·5 min read

SPF, DKIM and DMARC: the complete guide and deploy order

How SPF, DKIM and DMARC fit together, the right order to deploy them, alignment explained, and a practical checklist to lock down email authentication.

spfdkimdmarcemail
·5 min read

How to Read a WHOIS Record: A Field-by-Field Guide

Learn how to read a WHOIS record field by field: registrar vs registrant, key dates, nameservers, and what status codes like clientHold and pendingDelete mean.

whoisdomainsdns
·5 min read

How to Check SSL Certificate Expiration (3 Ways)

How to check SSL certificate expiration with openssl one-liners, your browser, and automated monitoring — copy-paste commands and when to use each method.

sslopensslmonitoring
·5 min read

How to find dangling DNS records before attackers do

Dangling DNS records point at cloud resources you no longer own. Learn what makes a record dangling across S3, GitHub Pages, Heroku and Azure, and how to detect them.

securitydnscloud
·5 min read

DMARC record guide: p=none, quarantine, reject and reports

A practical DMARC record guide: p=none vs quarantine vs reject, a safe rollout strategy, alignment, and how to actually read aggregate (RUA) reports.

dmarcemaildns
·5 min read

What Happens When an SSL Certificate Expires?

What happens when an SSL certificate expired: browser warnings, broken APIs, lost trust and how fast the failure cascades — plus what to do about it.

ssloutagesmonitoring
·5 min read

Domain Expiry Monitoring: Why Calendar Reminders Fail

A practical guide to domain expiry monitoring: why calendar reminders and registrar emails fail, and what automated WHOIS monitoring actually catches.

domainsexpirymonitoring
·6 min read

Subdomain takeover explained: dangling DNS and how to fix it

Subdomain takeover happens when DNS points at a cloud resource you no longer control. Learn the dangling-CNAME mechanism, the impact, and how to find and fix it.

securitydnssubdomain-takeover
·6 min read

SPF record explained: syntax, qualifiers and the 10-lookup trap

SPF record explained for practitioners: v=spf1 syntax, include vs ip4, ~all vs -all, the 10-DNS-lookup limit, and the mistakes that cause permerror.

spfemaildns
·6 min read

SSL Certificate Expiry Monitoring: Why Certs Still Lapse in the Age of Automation

Why SSL certificate expiry monitoring still matters in the age of automation: real outages, probing vs CT logs, and the alert lead times that work.

sslmonitoring
·5 min read

What Happens When a Domain Expires? The Full Timeline

What happens when a domain expires? The full lifecycle from expiry day through grace, redemption and pending delete — costs of recovery and how to prevent it.

domainsexpirywhois