Registrar locks
RDAP (the registry's structured successor to WHOIS) publishes a domain's EPP status codes. We
check for the three client locks on apex scans only (one lookup per registrable domain, not per
host). A registry-side server*Prohibited lock counts as locked.
| Status | Finding | Why it matters |
|---|---|---|
clientTransferProhibited | dns.transfer-lock-missing medium | Without it, a hijacked registrar account or a social-engineered support ticket can move the domain to another registrar. |
clientUpdateProhibited | dns.update-lock-missing low | Stops nameserver and contact changes without an extra unlock step. |
clientDeleteProhibited | dns.delete-lock-missing low | Stops accidental or malicious deletion. |
Some country-code registries do not support client locks at all; the findings say so when that may be the reason. For high-value domains, ask your registrar about registry lock, which requires an out-of-band confirmation to change.
Lock status is also checked nightly. A change produces domain.lock_changed: critical
when the transfer lock is removed, high when another lock is removed, low when a lock is added.
The first observation of a domain never produces a change.
DNSSEC
Checked through public validating resolvers over DNS-over-HTTPS (Google and Cloudflare), exactly as any resolver on the internet would: a DS lookup at the parent, then a validated SOA query.
dns.dnssec-missinglow: no DS record, so the zone is not protected.dns.dnssec-brokenhigh: a DS record exists but validation fails. Validating resolvers (a large share of the internet) cannot resolve the domain at all, usually after a DNS provider move that left a stale DS record behind. It is only raised when the validated query fails, the same query succeeds with checking disabled, and a second resolver confirms it, so a resolver outage never reads as broken DNSSEC.
security.txt
headers.missing-security-txt info and headers.security-txt-expired
low check /.well-known/security.txt on the apex, per RFC 9116. The second fires
when the Expires field has passed, is missing or cannot be parsed. The file is how a researcher who
finds a problem knows where to report it.
Weak certificate signatures
tls.weak-signature medium flags leaf certificates signed with SHA-1 or MD5,
usually an old appliance or internal certificate that has survived on a public host. Unlike the
checks above it runs on every host, not only the apex.
Registration expiry and registrar sprawl
Registration expiry is read from RDAP nightly, with warnings at 60, 30, 14 and 7 days. The Domains page shows the registrar, expiry and lock status of each domain, and a notice when your domains are split across several registrars, so "our domains are spread over five registrars, two of them on a former employee's card" becomes visible.