Domain and Brand Security
DNS, DNSSEC, CAA, registrar control and impersonation.
Courses
How a name resolves, what DNSSEC proves, what CAA constrains, and how domains that look like yours are used against you.
Operating a signed zone: key roles and algorithms, the rollover that breaks delegations, authenticated denial and zone walking, CAA against ACME, registrar locks, resilience, and the dangling records that outlive the services behind them.
Analysing a suspicious domain: generating the permutation space, reading registration and infrastructure signals, using Certificate Transparency as a detection channel, and classifying a finding before acting on it.
Running the programme: the monitoring channels and what each one sees, evidence that survives a challenge, the takedown chain and who to approach first, abuse reports that get acted on, and where automation has to stop.
Where both tracks converge: the four surfaces of domain trust, the controls as one system with a dependency graph, a repeatable estate assessment, honest prioritisation, and making the case to a budget holder.
The capstone, worked end to end on one estate: a full posture assessment, the impersonation exposure, the findings nobody can fix cleanly, a 30/90/365 plan with an explicit not-doing list, and delivering it to people who will act on it.