Plain guides on the things that break without anyone noticing: domains, certificates, business email and DNS. Written for whoever ends up responsible, which is usually not the person who set any of it up.
Every failure in this category traces back to the same gap: a process that depended on a person, and the person left.
6 min readAn incomplete chain works in your browser and fails for other people. How to spot it and how to fix it.
4 min readMost certificates renew themselves. When one does not, the renewal job has usually stopped running somewhere nobody is looking.
4 min readVisitors see a full-page warning before reaching your site. The four causes and what each one needs.
4 min readExpiry, issuer, covered names and the full chain of trust, checked continuously and kept as a dated lineage.
4 min readAutomation removed most certificate failures and made the remaining ones harder to see.
4 min readIt depends on whether it renews automatically. If it does, the expiry is a symptom and the renewal job stopping is the actual prob…
4 min readIt lists which certificate authorities may issue certificates for your domain. Without one, any authority can, and most domains do…
4 min readDKIM lets a receiving server verify a message really came from you. How to publish it and why keys stop matching.
4 min readA strict policy plus an unauthorised sender means your own mail is being rejected on your own instructions.
4 min readWithout DMARC, receiving servers have no instruction about forged mail from your domain. How to publish it safely.
4 min readSPF allows ten DNS lookups. Past that the whole record fails silently while still looking correct.
4 min readNothing tells receiving servers which systems may send mail for your domain. How to publish one that works.
4 min readMail failing produces no error on your side. Why quotes go unanswered, what actually breaks, and how to tell.
4 min readWe watch the records that decide whether your email arrives and whether it can be impersonated, and report in plain language.
4 min readIf your domain sends email, yes. Without it anyone can send mail claiming to be you, and receiving servers have no instruction abo…
4 min readUsually authentication rather than content. If SPF, DKIM or DMARC is misconfigured, receiving servers filter you regardless of wha…
4 min readRenew it, check the card on file has not expired, and move the notices somewhere that survives someone leaving.
5 min readWhat the lock does, why it is off, and how to turn it on at your registrar.
4 min readRenewal notices go to inboxes nobody reads and cards expire silently. What happens on the day a domain expires, the grace period, …
5 min readWe watch your renewal date, registrar, nameservers and transfer lock, and keep a dated record of every change.
4 min readIt arrives reliably. The problem is where it goes and what it assumes.
4 min readWhat actually happens between expiry and release, and where the cost curve turns.
5 min readYes, once it is released. Before that there is a recovery window, and how long it lasts depends on your extension.
4 min readMore often than you will. That is the actual answer, and it is why this is worth automating rather than diarising.
4 min readIt means transfer lock is on, which is good. Your domain cannot be moved to another registrar without you unlocking it first.
4 min readHow to check what is exposed, remove it from search results, and restrict it without breaking anyone's workflow.
4 min readA record pointing at a cancelled service can be claimed by someone else. How to confirm it and remove it.
4 min readA subdomain pointing at a deprovisioned service is a takeover risk. How it happens, why it matters and how to close it.
4 min readWhere your site actually lives, which third-party scripts are embedded, and what changed on the pages that matter.
3 min readEverything still resolving under your domain, including forgotten staging sites and records pointing at services that no longer ex…
3 min readNearly every established domain has one, and nobody currently employed put it there.
5 min readThree separate things, often at three different companies, and the confusion between them is why problems get investigated in the …
4 min readUsually minutes, not the 24 to 48 hours people quote. That figure is a worst case from an era of much longer cache times.
4 min readA record pointing at a service you no longer use. If that service releases the name, someone else can claim it and serve content f…
4 min readAll 10 pages on dns and subdomains
When the person who knew leaves, or someone asks how long something has been true, the answer usually has to be reconstructed by h…
4 min readWho reads a published record, where to put the link, and what it saves you from assembling by hand.
4 min readEvery check timestamped and sealed into a chain that cannot be revised. What gets kept, how the sealing works, and who reads the p…
6 min readFor agencies taking on a client. Find out what you have accepted responsibility for before you promise anything.
5 min readIt says one day because it started today. Showing that is more persuasive than any number we could have put there.
4 min readThe questions are repetitive, and most of them are about duration rather than state.
4 min read