Both tracks end here, and they end at the same place because they were always answering one question from two directions.
The definition
Domain trust is the property that third parties can correctly determine what is yours and what is not.
- Third parties — receivers, resolvers, browsers, customers. Not you. Every control in both tracks is a statement made to somebody else.
- Correctly — in both directions. Accepting what is yours matters as much as rejecting what is not, which is why a policy that breaks your own mail is a failure rather than a strict success.
- Determine — an active check they perform, not a belief they hold. If nothing is published, nothing can be determined.
What each track was asking
| Track | Question |
|---|---|
| Email authentication | Can someone send mail that appears to come from us? |
| Domain and brand security | Can someone be deceived about who controls this name, or about what is ours? |
The same answer serves both: publish assertions a third party can check, make them complete, and keep them true. Everything else is which assertion, in what format, to which audience.
What the definition excludes
- Inbound security. Filtering what arrives at your people is a different problem with different owners.
- The security of your systems. A compromised mailbox produces perfectly trustworthy mail; domain trust is working correctly and reporting a true fact.
- Anything about content. These controls answer who, never what.
Why a generic definition matters
Every vendor has a definition of domain trust shaped like their product. One that rests only on what a third party can determine lets you assess an estate, rank findings and decide what to build without any of that — and it is the definition the rest of this course is built on.