A CAA record names which CAs may issue certificates for your domain. One DNS line closes off a whole class of mis-issuance. Here is how to use it.
Read more
SBL, CSS, XBL, and PBL each say something different about your IP. The Spamhaus return code is the diagnosis. Here is how to read it and who has to file the removal.
Read more
Let's Encrypt shut off its OCSP responders in August 2025, but most CAs still run theirs. Here is where revocation actually stands and how to check what your own certificates carry.
Read more
Quantum-resistant algorithms are landing in TLS now, not in some distant future. Here is what is changing for certificates and what to do before it reaches you.
Read more
An expired SSL certificate fails closed: browsers block the page, API clients refuse to connect. Here is what breaks, how to fix it fast, and how to never repeat it.
Read more
Blacklists score two things: the IP a message came from and the domains inside it. Confuse them and you fix the wrong problem when mail starts bouncing.
Read more