REFERENCE

Guides

Practical explanations that match what the tools report, with safe change steps and honest limits.

All guides

DKIM Selectors Explained

What a DKIM selector is, why selectors cannot be listed from DNS, how to find the one a message used, and how to rotate DKIM keys without failures.

DMARC Policy and Reporting

How DMARC policy, alignment and report destinations work, why p=none is separate from report authorisation, and how to move to enforcement safely.

DNS change checklist

A step-by-step checklist for planning, making, verifying and rolling back DNS changes, with notes on TTLs, mail records and propagation.

DNS propagation explained

Why a DNS change appears at different times for different people: authoritative servers, resolver caches, TTL, negative caching and how to plan a change.

DNS record types explained

What A, AAAA, CNAME, MX, TXT, NS, SOA, PTR, SRV, CAA, DS and DNSKEY records are for, how they interact, and the mistakes that most often break a domain.

DNSSEC explained

How DNSSEC signs DNS data, how DS, DNSKEY and RRSIG records form a chain of trust, and how to enable, roll over or disable it without taking a domain offline.

Domain and email security baseline

A practical baseline of DNS, email authentication, transport and website controls a domain should have, with order of work and common mistakes.

Open Ports and Network Exposure Explained

What open, closed and filtered ports mean, which services should not face the internet, and how to restrict exposure without locking yourself out.

How to Read Email Headers

A practical guide to Received chains, Authentication-Results, SPF, DKIM and ARC fields, and why header results are claims rather than independent proof.

Reading statuses: PASS, IMPROVE, RISK and UNKNOWN

Exact meaning of PASS, IMPROVE, RISK, UNKNOWN, NOT_APPLICABLE, INFORMATIONAL and NOT CONFIGURED, plus severity, coverage and posture.

Security Headers Checklist for Websites

A checklist of HTTP security headers: what each does, which are low risk to add first, and how to roll out HSTS and CSP without breaking your site.

SMTP, STARTTLS and MTA-STS

How server-to-server mail encryption works, why STARTTLS alone is not enforcement, and where MTA-STS, DANE and TLS-RPT each fit in.

SPF PermError: Too Many DNS Lookups

Why SPF returns permerror when a record needs more than 10 DNS lookups, how void lookups count, and how to reduce a record without breaking senders.

TLS Certificate Expiry and Chain Problems

Why HTTPS certificates fail: expiry, wrong hostname, missing intermediates, untrusted issuers and clock errors, with ways to diagnose each and renew safely.

Troubleshoot NXDOMAIN, SERVFAIL and DNS timeouts

What NXDOMAIN, NODATA, SERVFAIL, REFUSED and timeouts each mean, what causes them, and a step-by-step way to find the failing layer.

What a domain security assessment covers

Understand the scopes of an external domain assessment, what each can and cannot prove, how long it takes and what coverage means.

How the guides are written

Each guide explains one topic that comes up when you read a DNS Tools result: what a record or control is, how to interpret what you see, what commonly goes wrong, and how to change it with a way back. Where a topic has limits, such as the fact that DKIM selectors cannot be listed from outside, the guide says so plainly.

The guides do not contain invented statistics, rankings or vendor claims. Where a standard defines behaviour, they point to the relevant RFC. Each carries a last-reviewed date so you can judge how current it is.

Start here

If you are new to domain security, read these three in order. They explain what a domain assessment looks at and how to read its output before you get into individual protocols.

DNS foundations

These guides cover the records and behaviours that everything else depends on.

Email authentication and transport

Guides for the controls that decide whether mail from your domain can be trusted, and whether it travels encrypted.

Network and web exposure

Guides for what a domain's servers show to the public internet.

Using guides with the tools

Every guide links to the tools that test the subject it discusses, and every tool page links back to the guides that explain its results. A typical workflow is to run a tool, read the matching guide to understand what the result means, make one change at a time, then run the same tool again to confirm it.

Written by DNS Tools editorial · Last updated 2026-10-09