CertaDNS
Skip to lesson

Staged Enforcement · lesson 1 of 3

Evidence before policy

After this lesson you can

State the criteria that make the next policy step safe, in numbers from your own reports.

Assumes you have read What a report does not contain.

Every policy step should be a decision taken against numbers from your own reports. The numbers are not complicated; the discipline is deciding what they have to say before you look at them.

Criteria worth stating in advance

Before moving toRequire
p=quarantine
  • Every source above a volume floor is identified and attributed to a system.
  • Aligned pass rate above 95% for four consecutive weeks.
  • No unexplained source above 0.5% of volume.
  • Forwarding-shaped failures understood and accepted as the residual.
p=reject
  • Four weeks at quarantine with no incident attributable to the policy.
  • Aligned pass rate above 98%.
  • Every remaining failure explained, not merely small.
  • A rollback that has been rehearsed, not just written down.

The percentages are defensible defaults rather than laws. What matters is that they exist before the meeting where someone asks whether it is safe to proceed, because the answer to that question should not be reached by consensus in the room.

“Explained” is the load-bearing word

A residual 2% of failures is safe to enforce against if you know what it is and unsafe if you do not, and the percentage is identical in both cases.

2% failing, all from forwarding IPs at universities
   -> known shape, no owner to fix it, accept and proceed

2% failing, source unidentified
   -> could be an unknown business system
   -> could be spoofing
   -> the number does not distinguish them. Do not proceed.

Reading volume honestly

  • A low-volume source can be your most important one. Two hundred messages a month might be the system that sends password resets.
  • Report volumes are lower bounds. A source absent from reports may simply send to receivers that do not report.
  • Seasonality is real. A quarterly billing run appears in one month of reports and not the two before it. Four weeks of evidence can miss it entirely, which is an argument for looking at a quarter before the final step.

The deadline is not a criterion

A date imposed by a compliance requirement or a customer questionnaire tells you when somebody wants enforcement. It tells you nothing about whether your senders are ready, and enforcing on an unmet criterion because the date arrived is how a domain rejects its own invoices.

Try it on a real domain

Free, no account, public DNS only.

Go deeper

Last reviewed