SAINTCON 2023 - Jesse Harris - DNS as a Security Tool

Discover how DNS can be used as a powerful security tool to protect against email spoofing, phishing, and other threats, including DNSSEC, CAA records, DMARC, SPF, and DNS filtering.

Key takeaways
  • DNS is an essential security tool that can be used to protect against various threats, including email spoofing and phishing.
  • DNSSEC is a method of securing DNS records by adding cryptographic signatures, which ensures the authenticity and integrity of DNS data.
  • CAA records can be used to specify which certificate authorities are allowed to issue certificates for a particular domain.
  • DMARC is a policy that helps prevent email spoofing by authenticating the domain of an email sender.
  • SPF is a method of validating the authenticity of email senders by checking the IP address of the sender’s mail server.
  • DNS filtering can be used to block malicious domains and IP addresses from being accessed.
  • Let’s Encrypt is a free certificate authority that provides free SSL/TLS certificates to domain owners.
  • DNS records can be used to control who can access a domain and to block certain types of traffic.
  • DNS filtering can be used to block ads and other unwanted content from being accessed.
  • DNS can be used to filter out malicious domains and IP addresses from being accessed.
  • DNS can be used to authenticate the domain of an email sender and prevent email spoofing.
  • DNSSEC can be used to secure DNS records and prevent them from being tampered with.
  • CAA records can be used to specify which certificate authorities are allowed to issue certificates for a particular domain.
  • DNS filtering can be used to block certain types of traffic and prevent unauthorized access to a domain.