Security Knowledge Base

Domain security
explained clearly

In-depth guides to understand every finding DomainRisk.io surfaces - what it means, why it matters and exactly how to fix it.

Latest articles

Guides, references & remediation playbooks

Domain spoofing attack vectors — exact-domain, lookalike, subdomain and display name spoofing explained
Threat Intel13 min read

What Is Domain Spoofing? Attacks, Risks & How to Prevent It

An email lands in your customer's inbox, sent from your exact domain, with your visual identity — but you never sent it. That is domain spoofing. No network configuration prevents it by default. Here is how attackers pull it off, what it costs, and how to close every vector.

Read article
DNSSEC chain of trust — zone signing, DS records, DNSKEY and RRSIG validation diagram
DNS Security11 min read

DNSSEC Explained: How to Protect Your Domain from DNS Spoofing

By default, DNS has no authentication — anyone who can intercept or poison a response can silently redirect your users to a malicious server. DNSSEC closes that gap with cryptographic signatures on every record. Here is how the chain of trust works and how to enable it.

Read article
BIMI email brand logo display in Gmail, Apple Mail and Yahoo — DNS record, SVG and VMC chain
Email Security12 min read

BIMI Setup Guide: Show Your Logo in Gmail, Apple Mail & Yahoo

BIMI is the only email standard that lets you display a verified brand logo directly in the inbox — combining anti-phishing protection with a measurable trust signal. Here is how the technical chain works, when you need a VMC, and how to implement it step by step.

Read article
Domain security score breakdown — exploitable risk, hardening gaps, governance axes and score thresholds
Risk Intelligence10 min read

What Is a Domain Security Score — and How Should You Use It?

Finding lists are useful — but they are not decisions. A domain security score collapses dozens of signals into a single number with clear thresholds. Here is how it is built, what each band means, and why a guardrail prevents a 90/100 from hiding a critical flaw.

Read article
Suspicious domain security checklist — registration age, WHOIS, DNS, SSL, typosquatting indicators
Threat Intel13 min read

What Makes a Domain Suspicious? A Security Checklist

Registration age, registrar reputation, WHOIS redaction, DNS configuration, SSL metadata, typosquatting distance, subdomain proliferation — none is sufficient alone. Here is how to combine all seven signals into a composite risk verdict.

Read article
Put the knowledge to work

Scan your domain. See your real risk.

Every article in this knowledge base maps to a real finding DomainRisk.io can detect automatically. Add your domain and get a full WHOIS, DNS, SSL and email-auth report in under 60 seconds.