SCANTIDE ONLINE
Scantide Online Guide

DNS Security Basics for a Public Domain

DNS controls how users and systems find your web, mail and other services. Reviewing records can expose stale infrastructure, weak mail policy and unexpected providers.

Technical guideUpdated 25 September 2026Scantide Online
Short answer: DNS controls how users and systems find your web, mail and other services. Reviewing records can expose stale infrastructure, weak mail policy and unexpected providers.

DNS is the map to your public services

A, AAAA, CNAME, MX and TXT records reveal where traffic and mail are intended to go. Changes can have immediate operational impact.

TXT records carry important security policy

SPF, DMARC and verification records often live in DNS. Old vendor tokens and duplicated policies can accumulate over time.

Names reveal dependencies

CNAME and MX records can expose CDN, SaaS and mail providers that are part of the public architecture.

Online reviews DNS as part of the whole posture

Scantide Online combines DNS evidence with HTTP, TLS, headers and infrastructure so a record can be interpreted in context.

Practical depth: examples, failure modes and what to verify

Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.

Current Scantide detail

Current Scantide source: SSL and TLS Scanner for Public Websites

Scantide Online reviews public DNS, mail-security records, HTTP/HTTPS behavior, TLS, security headers, cookies, infrastructure and CVE-related context to provide a readable external assessment of a domain.

Current Scantide source: DNS, SPF and DMARC Security Checker

Scantide Online checks public DNS and mail-security signals including SPF and DMARC as part of a broader external domain assessment.

Current Scantide source: Domain Security Scanner for DNS, HTTPS and Web Exposure

Use Scantide Online to check DNS and mail security, HTTPS/TLS, security headers, cookies and public infrastructure context from one domain scan.

Current Scantide source: External Attack Surface Assessment and Discovery

External attack surface work begins with visibility: which hosts answer, which services are exposed and which systems appear to belong to the organization.

Current Scantide source: Scantide Online – Domain Security, Privacy and Infrastructure Scanner

A single domain can expose signals across DNS, mail, HTTPS, headers and infrastructure. Scantide Online brings those observations into one readable assessment.

Field experience from the archive

Historical source · JufCorp: Securing your servers, users and customers online

Also, as a complement, use an online service also that filters all of your incoming and outgoing mail from viruses and SPAM and also have you secondary MX records point to it. Usually these services also hold you mail in queue if they cant' be delivered, buying you time to change the IP addresses or server if you are under attack and not losing any mails.

Also, you external DNS server needs to be secured! Have a word with your ISP or whoever is running the external DNS server and see what they've got in place.

On the subject of DNS servers. There's absolutely no point in having your DNS servers reachable through the firewall thus enabling attackers to flood it with DNS queries and UDP floods.

Historical source · JufCorp: Security Reality Check: Why a Perfect Score Doesn't Mean You're Safe

Implementation: Configure these DNS servers in your router/firewall for network-wide protection, or set them on individual devices. Many services offer deployment guides for various platforms.

Why Use jufCorp Security Scanner? The jufCorp scanner goes beyond basic port scanning by actively searching passive DNS databases to discover forgotten servers, typosquatting domains, and shadow IT infrastructure that standard scans miss. This helps identify attack vectors before adversaries do.

Historical source · Red Cloud Blog: Att använda sin egen e-postadress för att hitta rCloud ..

Om ni ändå vill ha just era användares e-postadress i URL fältet så krävs ett litet ingrepp i er externa DNS. Den automatiseringen bygger på ett s.k. TXT record i er DNS och ser ut så här _msradc https://tsgw.rcasp.se/rdweb/feed/webfeed.aspx Ni behöver alltså skapa ett TXT record i er DNS hos t.ex. One.com, Loopia eller var ni har er externa DNS med innehållet https://tsgw.rcasp.se/rdweb/feed/webfeed.aspx Naturligtvis kan vi hjälpa er med att sätta upp det så det blir rätt.

Practical review checklist

Frequently asked questions

Is DNSSEC the same as SPF or DMARC?

No. DNSSEC protects DNS authenticity; SPF and DMARC are email-related policies published through DNS.

Why review old TXT records?

They can reveal obsolete integrations and make configuration harder to understand.

Check the evidence with Scantide Online

External domain security, privacy and infrastructure assessment. Scantide is designed to show observable evidence and readable context rather than turn every observation into a vulnerability claim.

Run Scantide OnlineMore guidesAll Scantide guides