DomainOps Blog
Practical write-ups on domain monitoring, SSL hygiene, DNS security, and the day-to-day mechanics of keeping a portfolio of domains healthy.
DMARC policy: the migration path from p=none to p=reject
How to move your DMARC policy from p=none to p=reject safely: rua reports, pct= staged rollout, SPF/DKIM alignment, and why domains get stuck at none.
Domain Portfolio Management: Best Practices at Scale
Domain portfolio management best practices: consolidating registrars, tracking ownership, budgeting renewals, and solving the 'who owns this domain' problem.
Domain Monitoring for Agencies: Managing Many Clients at Once
Domain monitoring for agencies: how to manage many clients' domains in per-client portfolios, run white-glove reporting, and avoid the 3am SSL surprise.
Subdomain enumeration: a defensive guide to your own estate
A practical subdomain enumeration guide: passive vs active methods, the data sources that matter, and why you should map your own estate before attackers do.
What is DKIM? Signing, selectors and why it breaks silently
What is DKIM and how does it work? How message signing and DNS public keys work, selector rotation, CNAME delegation, and why DKIM fails without warning.
WHOIS Status Codes Explained: What Each EPP Status Means and When to Worry
WHOIS status codes explained: what clientTransferProhibited, clientHold, serverHold, redemptionPeriod and pendingDelete mean — and when to worry.
Incomplete Certificate Chain: Why Your Site Works in Chrome but Fails in curl
An incomplete certificate chain is why your site works in Chrome but fails in curl, Java or Android. How to diagnose it with openssl and fix it properly.
HTTP Endpoint Monitoring Explained: Why a 200 Isn't Always Healthy
Endpoint monitoring explained: how status codes really work, sensible response-time thresholds, and why a 200 OK can hide a completely broken application.
Email deliverability: the DNS-side checklist that keeps you inbox
Email deliverability starts in DNS. The SPF, DKIM, DMARC, MX and PTR levers that decide inbox vs spam, why mail gets filtered, and an auditable checklist.
Let's Encrypt Renewal Failed: The Five Failure Modes Behind Most Expired Certs
Let's Encrypt renewal failed? The common causes — broken certbot cron, blocked port 80, expired DNS API tokens, rate limits — and how to catch failures early.
Why Domain Auto-Renewal Is Not Enough on Its Own
Domain auto renewal fails more often than you think: expired cards, registrar emails in spam, transferred-away domains. Here's why, and what to add alongside it.
What is DNSSEC? Chain of trust, DS records and rotation risk
What is DNSSEC and how does it work? The chain of trust, DNSKEY and DS records, the DS-rotation outage class, and when enabling DNSSEC is worth it.
CVE monitoring for your domains: connect exposure to known flaws
CVE monitoring connects your exposed services to known vulnerabilities. Learn how to prioritise what to patch and why continuous beats point-in-time scanning.
The SSL Certificate Chain Explained
The SSL certificate chain explained: root, intermediate and leaf certs, why a site works in your browser but fails in curl, and how to debug an incomplete chain.
Bulk WHOIS Lookup: Auditing a Whole Domain Portfolio
A practical bulk WHOIS lookup guide: audit every domain's expiry and registrar at once, work around WHOIS/RDAP rate limits, and keep the data fresh.
Website Uptime Monitoring: A Practical Guide
A practical guide to website uptime monitoring: what to check, the right intervals, beating alert fatigue, and telling a brief blip apart from a real outage.
SPF, DKIM and DMARC: the complete guide and deploy order
How SPF, DKIM and DMARC fit together, the right order to deploy them, alignment explained, and a practical checklist to lock down email authentication.
How to Read a WHOIS Record: A Field-by-Field Guide
Learn how to read a WHOIS record field by field: registrar vs registrant, key dates, nameservers, and what status codes like clientHold and pendingDelete mean.
How to Check SSL Certificate Expiration (3 Ways)
How to check SSL certificate expiration with openssl one-liners, your browser, and automated monitoring — copy-paste commands and when to use each method.
How to find dangling DNS records before attackers do
Dangling DNS records point at cloud resources you no longer own. Learn what makes a record dangling across S3, GitHub Pages, Heroku and Azure, and how to detect them.
DMARC record guide: p=none, quarantine, reject and reports
A practical DMARC record guide: p=none vs quarantine vs reject, a safe rollout strategy, alignment, and how to actually read aggregate (RUA) reports.
What Happens When an SSL Certificate Expires?
What happens when an SSL certificate expired: browser warnings, broken APIs, lost trust and how fast the failure cascades — plus what to do about it.
Domain Expiry Monitoring: Why Calendar Reminders Fail
A practical guide to domain expiry monitoring: why calendar reminders and registrar emails fail, and what automated WHOIS monitoring actually catches.
Subdomain takeover explained: dangling DNS and how to fix it
Subdomain takeover happens when DNS points at a cloud resource you no longer control. Learn the dangling-CNAME mechanism, the impact, and how to find and fix it.
SPF record explained: syntax, qualifiers and the 10-lookup trap
SPF record explained for practitioners: v=spf1 syntax, include vs ip4, ~all vs -all, the 10-DNS-lookup limit, and the mistakes that cause permerror.
SSL Certificate Expiry Monitoring: Why Certs Still Lapse in the Age of Automation
Why SSL certificate expiry monitoring still matters in the age of automation: real outages, probing vs CT logs, and the alert lead times that work.
What Happens When a Domain Expires? The Full Timeline
What happens when a domain expires? The full lifecycle from expiry day through grace, redemption and pending delete — costs of recovery and how to prevent it.