A domain and certificate review should determine whether the business controls its online identity and whether each public service resolves and encrypts traffic as intended. A website can display a valid lock icon while the registrar belongs to a former employee, unused subdomains point to abandoned services, certificate renewals depend on an unknown account, or email authentication permits impersonation.
The review must examine records, live behavior, administrative access, and recovery. It should cover every registered domain and active subdomain, not just the primary website. Findings should distinguish an immediate takeover or outage risk from cleanup, documentation, and long-term resilience work. Each correction needs an owner, rollback plan, validation, and evidence of completion.
ALLMSP conducts domain, DNS, SSL, and TLS reviews through its in-house web, infrastructure, and cybersecurity teams for organizations in Lawrenceville, Suwanee, Gwinnett County, Metro Atlanta, and throughout Georgia. This checklist helps leadership understand where control is strong, where it is assumed, and what must be corrected first.
Audit ownership, live configuration, and recovery before trusting the lock icon
- Reconcile domains: Compare registrations, billing, renewals, redirects, websites, email, applications, defensive names, and planned retirements.
- Review access: Verify company ownership, named administrators, MFA, recovery, locks, support, service accounts, activity, and offboarding.
- Inspect DNS: Evaluate delegation, records, TTLs, DNSSEC, CAA, mail, verifications, unused names, change history, exports, and resilience.
- Test TLS: Check hostname coverage, chain, trust, dates, protocols, ciphers, redirects, mixed content, proxies, origins, and renewal automation.
- Assess email: Inventory senders, inspect SPF and DKIM, analyze DMARC alignment and reports, and identify spoofing or delivery gaps.
- Plan corrections: Rank ownership loss, takeover exposure, expirations, broken trust, unsafe records, monitoring gaps, and documentation work.
Reconcile the domain portfolio, registrar control, renewals, and recovery
Collect domains from registrar accounts, finance records, DNS providers, certificates, web analytics, search tools, email systems, cloud applications, advertising, legal records, brand teams, and public discovery. Include country and alternate spellings, defensive registrations, legacy brands, redirect names, campaign names, parked domains, and domains held by subsidiaries. Identify active subdomains through DNS zones, certificate transparency data where appropriate, proxies, hosting platforms, source configuration, and application records.
For each domain, verify the registered holder, registrar, account owner, administrators, contacts, MFA, recovery, lock status, privacy service, nameservers, expiration, automatic renewal, payment, notices, support, and transfer requirements. Confirm that legal and business records match the intended owner. Investigate accounts using personal addresses, unknown agencies, former employees, stale phone numbers, expired cards, unmonitored mailboxes, or a single administrator. Test authorized recovery without triggering an unnecessary transfer or lockout.
Evaluate the business purpose and retirement plan. Confirm which websites, email, authentication, portals, APIs, remote access, certificates, marketing campaigns, and customer documents depend on the domain. Record known alternate paths and minimum retention after a rebrand or migration. Before allowing expiration, assess impersonation, phishing, email, backlinks, saved customer links, software callbacks, certificates, and contractual use. A domain that appears inactive may still protect the organization from takeover or support a hidden dependency.
- Discovery evidence: Compare registrars, finance, DNS, certificates, email, cloud apps, analytics, search, campaigns, legal, and public records.
- Registrant control: Verify holder, account, contacts, administrators, MFA, recovery, lock, support, transfer, activity, and ownership evidence.
- Renewal evidence: Check expiration, automatic renewal, payment, notices, budget, backup contacts, support path, and escalation lead time.
- Dependency map: Connect website, email, identity, applications, APIs, remote access, certificates, documents, links, and customer use.
- Retirement decision: Assess impersonation, phishing, mail, traffic, backlinks, callbacks, contracts, records, retention period, and final validation.
Portfolio reconciliation finds the domains most likely to be lost, misused, or retired without understanding their remaining business value.
Inspect DNS records, DNSSEC, subdomain exposure, certificates, and HTTPS
Compare the intended authoritative nameservers with registry delegation and live answers from independent resolvers. Review zone records, TTLs, duplicate or conflicting entries, wildcard use, verification tokens, stale migrations, development names, and records pointing to services that no longer belong to the business. A dangling CNAME or other abandoned mapping can create subdomain takeover risk when the external provider permits a new customer to claim the unassigned resource. Confirm ownership at the destination before deleting or repointing anything.
Validate DNSSEC from the parent delegation through the signed zone where it is enabled. Check delegation signer records, key state, algorithms, expiration where relevant, rollover procedures, and responses from validating resolvers. Review authoritative-provider resilience, access, logs, change history, zone exports, and emergency support. NIST’s current Secure DNS Deployment Guide treats DNS as both critical infrastructure and a defense-in-depth component, which makes availability, integrity, privacy, and operating responsibility part of the review.
Inventory every publicly trusted certificate and endpoint. Check subject alternative names, issuer, chain, validity, key type and protection, validation method, deployment targets, load balancers, proxies, origins, applications, APIs, mail services, renewal automation, failed jobs, and responsible owners. Review CAA policy against legitimate issuers. Test HTTPS redirects, protocols, ciphers, hostname consistency, mixed content, secure cookies, canonical URLs, sitemaps, external callbacks, and representative client devices. Identify certificates that are valid but deployed to the wrong service or absent from one traffic path.
- Delegation test: Verify registrar nameservers, parent delegation, authoritative answers, IPv4 and IPv6, independent resolvers, and intended providers.
- Record review: Assess name, type, value, TTL, purpose, owner, destination ownership, wildcard, verification, change history, and retirement.
- DNSSEC validation: Check delegation signer data, zone signing, keys, algorithms, rollover, validating resolvers, monitoring, and recovery.
- Certificate inventory: Record names, issuer, chain, validation, key, endpoints, proxies, origin, dates, automation, alerts, owner, and revocation.
- HTTPS test: Inspect trust, protocols, ciphers, redirects, hostnames, mixed content, cookies, applications, APIs, callbacks, and device behavior.
Live DNS and TLS testing reveals abandoned mappings, broken trust paths, and configuration differences that an account export cannot show.
Review email authentication, monitoring, change control, and correction priorities
Inventory every system authorized to send mail for each domain, including primary email, marketing, CRM, ticketing, invoicing, ecommerce, forms, applications, monitoring, and vendors. Inspect SPF lookup structure and included services, DKIM selectors and key ownership, DMARC alignment, policy, aggregate-report destinations, and legitimate forwarding or mailing-list behavior. Analyze reports before increasing enforcement. Remove departed senders and rotate keys according to provider capabilities and risk.
Test monitoring and operating controls. Verify alerts for domain and certificate expiration, renewal failure, DNS change, nameserver change, DNSSEC validation, unexpected certificate issuance where monitored, website availability, HTTPS errors, and email-authentication trends. Confirm recipients, primary and backup owners, escalation, business-hours and after-hours expectations, ticket creation, acknowledgment, and closure. Review DNS and registrar change procedures for request identity, approval, exact values, dependencies, timing, export, rollback, and post-change validation.
Rank findings by credible scenario and business effect. Lost registrar control, imminent expiration, unauthorized nameservers, abandoned subdomain destinations, exposed administrator accounts, broken DNSSEC, certificates that are expired or nearing failure, unsafe private-key handling, and undetected critical changes require prompt attention. Document each issue with asset, evidence, scenario, likelihood, impact, existing control, correction, owner, due date, rollback, validation, and residual risk. Retest the actual record or service after correction.
- Sender inventory: Record system, domain, envelope and header identity, owner, SPF, DKIM, purpose, volume, data, and retirement.
- DMARC review: Analyze alignment, legitimate sources, failures, forwarding, policy, reporting addresses, trends, exceptions, and advancement plan.
- Monitoring test: Trigger or simulate renewals, certificate alerts, DNS changes, website failures, and routing to confirm accountable response.
- Change control: Require verified requester, business reason, approved values, dependencies, export, TTL, window, test, rollback, and record.
- Correction record: State asset, scenario, evidence, impact, priority, action, owner, target, rollback, validation, and accepted residual risk.
The review is complete when ownership, configuration, monitoring, and recovery gaps become a prioritized plan with verified corrections.
SSL, TLS, DNS, and domain security reviews from ALLMSP
ALLMSP can discover domain portfolios, reconcile registrar ownership, review access and renewals, inspect DNS and DNSSEC, identify unsafe subdomains, inventory certificates, test HTTPS, analyze email authentication, validate monitoring, and complete prioritized corrections. Our in-house team can continue managing domains, hosting, websites, email, cybersecurity, and renewals after the review.
We provide domain and certificate security audits for businesses in Lawrenceville, Suwanee, Gwinnett County, Metro Atlanta, and throughout Georgia, including organizations with many domains, cloud applications, ecommerce, portals, and complex sending environments.
- Discover: Reconcile registrations, subdomains, DNS zones, certificates, email senders, services, owners, access, and dependencies.
- Test: Validate delegation, records, DNSSEC, TLS, HTTPS, renewals, email alignment, monitoring, recovery, and live customer paths.
- Correct: Restore ownership, secure access, remove exposure, repair configuration, automate renewals, improve alerts, and verify results.
Official references for domain and certificate reviews
Use current documentation from every registrar, DNS provider, certificate authority, hosting platform, and email sender represented in the environment.
- NIST Secure DNS Deployment Guide. Provides current guidance for protecting authoritative, recursive, encrypted, protective, and DNSSEC services.
- ICANN registrant account protection guide. Explains risks and protective practices for domain registration accounts and authorized changes.
- Let’s Encrypt CAA guidance. Explains how CAA records can restrict certificate authority issuance and how lookup behavior affects subdomains.
- Google site-move and HTTPS migration guidance. Explains HTTP-to-HTTPS moves, redirects, canonical URLs, sitemaps, testing, monitoring, and Search Console considerations.
SSL and domain security review FAQs
How are unknown business domains discovered?
Compare registrar and finance records, DNS providers, certificates, email, cloud applications, analytics, search tools, campaigns, legal records, brand records, and public discovery.
What makes a domain account high risk?
Personal ownership, no MFA, one administrator, stale recovery, expired payment, no lock, unknown access, unmonitored notices, poor documentation, and no tested support path increase risk.
What is a dangling DNS record?
It is a record that still points to an external resource no longer controlled by the business and may create takeover risk if another party can claim that resource.
How is DNSSEC reviewed?
Validate delegation signer data, signed responses, keys, algorithms, rollover, provider ownership, independent resolver behavior, monitoring, and emergency recovery.
What should a TLS certificate inventory contain?
Include hostnames, issuer, chain, validation, private-key location, deployment targets, proxies, origins, dates, automation, alerts, owner, and revocation process.
Can a valid certificate still be configured incorrectly?
Yes. It may cover the wrong names, omit an endpoint, use an incomplete chain, expose weak settings, fail behind a proxy, renew to the wrong target, or leave mixed content.
Why include email authentication in a domain review?
SPF, DKIM, and DMARC use DNS and domain alignment to support delivery and reduce impersonation, so unknown senders or weak policy can affect brand trust and security.
What should be monitored after the audit?
Monitor registrations, renewals, nameservers, DNS changes, DNSSEC, certificate issuance and expiration, HTTPS, critical journeys, email alignment, administrative access, and alert delivery.
Can ALLMSP correct the issues found during the review?
Yes. ALLMSP restores ownership, secures accounts, repairs DNS and TLS, configures email authentication, automates renewals, improves monitoring, and documents the environment in house.
Where does ALLMSP perform SSL and domain audits?
ALLMSP reviews domain, DNS, and SSL security for organizations in Lawrenceville, Suwanee, Gwinnett County, Metro Atlanta, and statewide across Georgia.
























































