Guides
Practical explanations that match what the tools report, with safe change steps and honest limits.
All guides
What a DKIM selector is, why selectors cannot be listed from DNS, how to find the one a message used, and how to rotate DKIM keys without failures.
How DMARC policy, alignment and report destinations work, why p=none is separate from report authorisation, and how to move to enforcement safely.
A step-by-step checklist for planning, making, verifying and rolling back DNS changes, with notes on TTLs, mail records and propagation.
Why a DNS change appears at different times for different people: authoritative servers, resolver caches, TTL, negative caching and how to plan a change.
What A, AAAA, CNAME, MX, TXT, NS, SOA, PTR, SRV, CAA, DS and DNSKEY records are for, how they interact, and the mistakes that most often break a domain.
How DNSSEC signs DNS data, how DS, DNSKEY and RRSIG records form a chain of trust, and how to enable, roll over or disable it without taking a domain offline.
A practical baseline of DNS, email authentication, transport and website controls a domain should have, with order of work and common mistakes.
What open, closed and filtered ports mean, which services should not face the internet, and how to restrict exposure without locking yourself out.
A practical guide to Received chains, Authentication-Results, SPF, DKIM and ARC fields, and why header results are claims rather than independent proof.
Exact meaning of PASS, IMPROVE, RISK, UNKNOWN, NOT_APPLICABLE, INFORMATIONAL and NOT CONFIGURED, plus severity, coverage and posture.
A checklist of HTTP security headers: what each does, which are low risk to add first, and how to roll out HSTS and CSP without breaking your site.
How server-to-server mail encryption works, why STARTTLS alone is not enforcement, and where MTA-STS, DANE and TLS-RPT each fit in.
Why SPF returns permerror when a record needs more than 10 DNS lookups, how void lookups count, and how to reduce a record without breaking senders.
Why HTTPS certificates fail: expiry, wrong hostname, missing intermediates, untrusted issuers and clock errors, with ways to diagnose each and renew safely.
What NXDOMAIN, NODATA, SERVFAIL, REFUSED and timeouts each mean, what causes them, and a step-by-step way to find the failing layer.
Understand the scopes of an external domain assessment, what each can and cannot prove, how long it takes and what coverage means.
How the guides are written
Each guide explains one topic that comes up when you read a DNS Tools result: what a record or control is, how to interpret what you see, what commonly goes wrong, and how to change it with a way back. Where a topic has limits, such as the fact that DKIM selectors cannot be listed from outside, the guide says so plainly.
The guides do not contain invented statistics, rankings or vendor claims. Where a standard defines behaviour, they point to the relevant RFC. Each carries a last-reviewed date so you can judge how current it is.
Start here
If you are new to domain security, read these three in order. They explain what a domain assessment looks at and how to read its output before you get into individual protocols.
- What a domain security assessment covers: scopes, evidence and limits.
- Reading statuses: PASS, IMPROVE, RISK, UNKNOWN: exact meaning of every label and of coverage.
- Domain and email security baseline: a sensible set of controls to aim for.
DNS foundations
These guides cover the records and behaviours that everything else depends on.
- DNS record types explained
- DNS propagation explained
- DNSSEC explained
- Troubleshooting NXDOMAIN, SERVFAIL and timeouts
- DNS change checklist
Email authentication and transport
Guides for the controls that decide whether mail from your domain can be trusted, and whether it travels encrypted.
- SPF PermError and the ten-lookup limit
- DMARC policy and reporting
- DKIM selectors explained
- SMTP STARTTLS and MTA-STS
- Reading email headers
Network and web exposure
Guides for what a domain's servers show to the public internet.
- Open ports and exposure explained
- Security headers checklist
- TLS certificate expiry and chain problems
Using guides with the tools
Every guide links to the tools that test the subject it discusses, and every tool page links back to the guides that explain its results. A typical workflow is to run a tool, read the matching guide to understand what the result means, make one change at a time, then run the same tool again to confirm it.
Written by DNS Tools editorial · Last updated 2026-10-09