Jelia.nyc

Jelia.nyc / Proof / Domains under management

PROOF · DOMAINS

Thirty-nine domains, and nobody guessing

Every one of the 39 domains on this estate has a known registrar, DNS in one place, and mail records that pass. That is less about the number and more about the discipline that stops any of them quietly expiring.

What the number means

Thirty-nine is the count of domains I hold and run myself. Not parked names in a drawer, and not domains I once registered for someone and forgot about. Each one resolves, each one is accounted for, and each one has an owner — me — who knows where it is registered and when it renews.

Most organisations have more domains than they think. Marketing bought a few for a campaign. A previous IT lead registered the company name in three spellings on a personal card. A product was renamed and the old domain still sends mail. The number on its own is not impressive. What matters is whether every name on the list can be answered for.

What sits behind it

39domains, each with a recorded registrar and renewal date
Oneplace where DNS is hosted and edited for all of them
Everysending domain carries SPF, DKIM and DMARC
AutomaticTLS certificate issue and renewal, with a daily expiry sweep

Registration and DNS are kept as two separate jobs. A domain can be registered wherever it was bought, but its DNS is delegated to one central place. That means one set of records to read, one change process and one view of the whole estate, instead of logging into several registrar dashboards to find out where a single record lives.

Every domain that sends mail has SPF to say which servers may send for it, DKIM to sign what leaves, and DMARC to tell receiving servers what to do when either check fails. Those records are verified passing at Gmail, not just present. A domain that does not send mail still gets records saying so, because an unprotected domain is an easy one to forge.

How it is kept that way

  1. One inventory. Every domain is listed with its registrar, renewal date, DNS location and what it serves. If it is not on the list, it is either added or let go deliberately.
  2. Renewals tracked, not remembered. Renewal dates live in the inventory, not in someone's inbox. Losing a domain to a missed renewal is one of the most avoidable outages there is.
  3. DNS changes in one place. Because every zone sits in the same service, a change is made once, read back, and checked from outside before it is called done.
  4. Certificates automated. Certificates are issued and renewed by machine. A daily sweep checks every expiry date anyway, because automation that fails silently is worse than none.
  5. Mail authentication checked from the receiving side. Records are tested by sending real mail and reading the verdict a large mailbox provider gives it, not by trusting that the DNS looks right.

Why it matters for you

The failures here are rarely dramatic until they are. A domain lapses and someone else buys it, along with every password-reset email still pointing at it. A DNS record for a decommissioned service still points at an address the cloud provider has since handed to a stranger. A forgotten domain with no DMARC is used to send invoices that look like yours.

None of that needs clever tooling to prevent. It needs a list, one place for DNS, and somebody whose job it is to keep both true. That is what an audit of this area produces: the full inventory, the gaps against it, and the order to close them in.

Questions people ask

Do all the domains need to move to one registrar?

No. Consolidating registrars can be tidy, but it is not the point. Central DNS and an accurate inventory get you most of the benefit without a round of transfers.

We only send mail from one domain. Do the others need SPF and DMARC?

Yes. A domain that never sends mail should say so in DNS. Otherwise it is exactly the one someone will borrow to impersonate you.

How long does it take to get a messy estate under control?

The inventory is the slow part, because it means finding domains nobody wrote down. Once the list exists, bringing DNS and mail records into line is usually quick, routine work.