“It’s on auto-renew.” That’s a good answer, sure. It means somebody checked a box. The thing is that domain renewals can fail. So, what happens if it does...? Here’s a likely scenario. Suppose the company card is replaced after a fraud alert. The old card remains on the registrar account. Then, when the renewal charge fails, the warning goes to whoever ... View Post
articles
Your Domain Has MFA. What Happens When Someone Calls Support?
Your team uses hardware security keys and the registrar account has a strong, unique password. So, you’ve done the sensible things. Now somebody contacts support and says they’ve lost their key. What happens next? If you don’t know, there is a part of your domain security you haven’t checked. It’s multi-factor authentication (MFA). MFA governs the normal ... View Post
AI Hallucinates Domains for Your Brand. Criminals Register Them.
Ask ChatGPT where to log into your company's customer portal. Do it a few times, in a few different phrasings, and sooner or later it hands back a URL that looks plausible and does not exist. Criminals run the same exercise at scale and register the answers. What Unit 42 Found Palo Alto Networks' Unit 42 published the numbers in June. They ran 913 ... View Post
Ask Your CTO Who Runs Your DNS. Watch What Happens.
Try asking this question at your next leadership meeting: “Who runs our DNS?” Then watch. There will be a pause. Somebody will offer to check. Somebody else will name a vendor, usually whoever registered the domain a decade ago, and nobody in the room will be able to say when that vendor was last looked at. We've been running a domain registrar and managed DNS ... View Post
The Problem With Following DNS Security “Best Practices” That Everyone Else Is Already Following
Attackers trying to compromise your domain infrastructure have read the same security frameworks you have. They know what NIST recommends. They know what CIS benchmarks look like. They test their exploits against compliant configurations before they deploy them. When everybody follows the same playbook, the playbook becomes a roadmap for your adversaries. ... View Post
Board-Ready: The DNS Security Audit Checklist for Your Next Meeting
What your board doesn't know about DNS could cost them their seats Picture a board meeting. The CISO is presenting the annual security budget. Firewalls, endpoint detection, a 24/7 SOC, penetration testing, cyber insurance. The numbers add up to seven figures. The board nods approvingly. Nobody asks about the $12/year domain name holding it all together. This ... View Post






