{"id":13873,"date":"2025-08-19T00:22:22","date_gmt":"2025-08-18T22:22:22","guid":{"rendered":"https:\/\/monodes.com\/predaelli\/?p=13873"},"modified":"2025-08-19T00:22:25","modified_gmt":"2025-08-18T22:22:25","slug":"how-not-to-configure-your-domainname-internet-nl","status":"publish","type":"post","link":"https:\/\/monodes.com\/predaelli\/2025\/08\/19\/how-not-to-configure-your-domainname-internet-nl\/","title":{"rendered":"How (not) to configure your domainname [internet.nl]"},"content":{"rendered":"\n<p><a href=\"https:\/\/program.why2025.org\/why2025\/talk\/XVET7C\/\">How (not) to configure your domainname [internet.nl]<\/a><\/p>\n\n\n\n<!--nextpage-->\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<h3 class=\"wp-block-heading\">How (not) to configure your domainname [internet.nl]<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\"><\/h3>\n\n\n\n<h3 class=\"wp-block-heading\"><small>2025-08-11 <time datetime=\"2025-08-11 14:00\">14:00<\/time>\u2013<time datetime=\"2025-08-11 14:50\">14:50<\/time>, Cassiopeia <strong>Language:<\/strong> English<\/small><\/h3>\n\n\n\n<p>The most common configurations seen in scanning domain names with <a href=\"https:\/\/program.why2025.org\/redirect\/?url=https%3A\/\/internet.nl%3A7l6wQmEpKuI1njvcGfEo_75GtRRLgt2WT04Ss86OyOg\" rel=\"noreferrer noopener\" target=\"_blank\">Internet.nl<\/a>, e.g. those found in <a href=\"https:\/\/program.why2025.org\/redirect\/?url=https%3A\/\/www.forumstandaardisatie.nl\/metingen\/informatieveiligheidstandaarden%3A_yeaCWFe7QXopNYf_9sSJLMotdacjyj8AkVbthwv8nw\" rel=\"noreferrer noopener\" target=\"_blank\">biannual governmental measurements<\/a>.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>This talk will explain how to configure modern security standards on your domain name with the help of <a href=\"https:\/\/program.why2025.org\/redirect\/?url=https%3A\/\/github.com\/internetstandards\/Internet.nl\/%3ADTVir5sOV1nqEEqE3Z04C4MqSz4iJMCuMx5fBFtwxzM\" rel=\"noreferrer noopener\" target=\"_blank\">the open source<\/a> <a href=\"https:\/\/program.why2025.org\/redirect\/?url=https%3A\/\/internet.nl%3A7l6wQmEpKuI1njvcGfEo_75GtRRLgt2WT04Ss86OyOg\" rel=\"noreferrer noopener\" target=\"_blank\">Internet.nl<\/a>. It will show common misconfigurations in DNS and security headers. Teach you why you should probably want to avoid <code class=\"\" data-line=\"\">www CNAME @<\/code>, want to enable IPv6 and other observations from the <a href=\"https:\/\/program.why2025.org\/redirect\/?url=https%3A\/\/www.forumstandaardisatie.nl\/metingen\/informatieveiligheidstandaarden%3A_yeaCWFe7QXopNYf_9sSJLMotdacjyj8AkVbthwv8nw\" rel=\"noreferrer noopener\" target=\"_blank\">biannual measurements<\/a> of scanning more than 10.000 governmental host names in The Netherlands.<\/p>\n\n\n\n<p>After this talk you&#8217;ll know at least one DNS or security header improvement for your own or organization domain.<\/p>\n\n\n\n<p>This presentation will touch:<br \/>&#8211; why enable DNSSEC (<a href=\"https:\/\/program.why2025.org\/redirect\/?url=https%3A\/\/datatracker.ietf.org\/doc\/html\/rfc4033%3A5my4zN5WbucDoqXhMNYMHgWJ99Fq35SYQdUGT3Ya3fo\" rel=\"noreferrer noopener\" target=\"_blank\">RFC 4033<\/a> and many more), some common failures (e.g. CNAME&#8217;s)<br \/>&#8211; why enable IPv6, not talking about &#8216;IPv4-mapped IPv6 address&#8217; here, issues if you&#8217;re still not supporting IPv6 (almost 30 years after <a href=\"https:\/\/program.why2025.org\/redirect\/?url=https%3A\/\/datatracker.ietf.org\/doc\/html\/rfc1883%3AQ2QpV_d3sD-y9g9hq5UtwA0B_qeiwQv9UqFvdQGsmFk\" rel=\"noreferrer noopener\" target=\"_blank\">RFC 1883<\/a>)<br \/>&#8211; why not CNAME to your apex domain (if you have an Mx record)<br \/>&#8211; why use Null MX (<a href=\"https:\/\/program.why2025.org\/redirect\/?url=https%3A\/\/datatracker.ietf.org\/doc\/html\/rfc7505%3AG2F4AQcAp-YW6awviQPj3iLyKrDPdkuMPu8TmQG1OIM\" rel=\"noreferrer noopener\" target=\"_blank\">RFC 7505<\/a>)<br \/>&#8211; why configuration SPF (<a href=\"https:\/\/program.why2025.org\/redirect\/?url=https%3A\/\/datatracker.ietf.org\/doc\/html\/rfc7208%3A2b4liLE6MWArwV4bjbXOEotUd-mpsjvcUmLb_fkcOVY\" rel=\"noreferrer noopener\" target=\"_blank\">RFC 7208<\/a>) on all hostnames<br \/>&#8211; why there are more reasons to avoid CNAME&#8217;s<br \/>&#8211; why enable DANE (<a href=\"https:\/\/program.why2025.org\/redirect\/?url=https%3A\/\/datatracker.ietf.org\/doc\/html\/rfc6698%3Aql3_gpVvpTsIG8wPhMajI6WSkX6uYqQM36Yz3Ohyt68\" rel=\"noreferrer noopener\" target=\"_blank\">RFC 6698<\/a>) and TLSRPT (<a href=\"https:\/\/program.why2025.org\/redirect\/?url=https%3A\/\/datatracker.ietf.org\/doc\/html\/rfc8460%3Ajv39sP4kycKmq7REgipZKJgw9jt3YV4R60WMkCVWy1A\" rel=\"noreferrer noopener\" target=\"_blank\">RFC 8460<\/a>) and why it&#8217;s superior to MTA-STA (<a href=\"https:\/\/program.why2025.org\/redirect\/?url=https%3A\/\/datatracker.ietf.org\/doc\/html\/rfc8461%3AuoUxZ7vvm3B15AXt0wU1dfcVChgR6cw5byNu2VctnTU\" rel=\"noreferrer noopener\" target=\"_blank\">RFC 8461<\/a>), how to rotate DANE<br \/>&#8211; why monitoring matters<br \/>&#8211; why first doing a <code class=\"\" data-line=\"\">https:\/\/<\/code> redirect before a domain redirect<br \/>&#8211; why a strict Content-Security-Policy (<a href=\"https:\/\/program.why2025.org\/redirect\/?url=https%3A\/\/www.w3.org\/TR\/CSP3\/%3Aaam2WHkFxvhzLfH4FoW_xem4_puo6k8qIVm97j0firE\" rel=\"noreferrer noopener\" target=\"_blank\">CSP v3<\/a>) will save you<br \/>&#8211; why configure <code class=\"\" data-line=\"\">ssl_reject_handshake<\/code> (nginx only)<br \/>&#8211; why have an accessible security.txt (special allow rule if you have basic auth!) that contains at least one email address<br \/>&#8211; why start cookie names with <code class=\"\" data-line=\"\">__Host-<\/code>or <code class=\"\" data-line=\"\">__Secure-<\/code> (<a href=\"https:\/\/program.why2025.org\/redirect\/?url=https%3A\/\/developer.mozilla.org\/en-US\/docs\/Web\/HTTP\/Reference\/Headers\/Set-Cookie%23cookie-namecookie-value%3AIhSV7uGkFVlorRlCIA7C7j2Z-j0_iA02x6QIhL-Cs9c\" rel=\"noreferrer noopener\" target=\"_blank\">MDN<\/a>)<\/p>\n<\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p class=\"excerpt\">How (not) to configure your domainname [internet.nl]<\/p>\n<p class=\"more-link-p\"><a class=\"more-link\" href=\"https:\/\/monodes.com\/predaelli\/2025\/08\/19\/how-not-to-configure-your-domainname-internet-nl\/\">Read more &rarr;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"link","meta":{"inline_featured_image":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"activitypub_content_warning":"","activitypub_content_visibility":"","activitypub_max_image_attachments":4,"activitypub_interaction_policy_quote":"anyone","activitypub_status":"federated","footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[72],"tags":[333],"class_list":["post-13873","post","type-post","status-publish","format-link","hentry","category-documentations","tag-dns","post_format-post-format-link"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p6daft-3BL","jetpack-related-posts":[{"id":9912,"url":"https:\/\/monodes.com\/predaelli\/2022\/12\/14\/how-to-configure-wireless-wake-on-lan-for-linux-wifi-card\/","url_meta":{"origin":13873,"position":0},"title":"How to configure wireless wake-on-lan for Linux WiFi card","author":"Paolo Redaelli","date":"2022-12-14","format":false,"excerpt":"How to configure wireless wake-on-lan for Linux WiFi card - nixCraft I have Network Attached Storage (NAS) server that backups all my devices. However, I am having a hard time with my Linux-powered laptop. I cannot back up my laptop\/computer when it is in suspended or sleep mode. How do\u2026","rel":"","context":"In &quot;Documentations&quot;","block_context":{"text":"Documentations","link":"https:\/\/monodes.com\/predaelli\/category\/documentations\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1462,"url":"https:\/\/monodes.com\/predaelli\/2016\/04\/29\/10-useful-ip-commands-to-configure-network-interfaces\/","url_meta":{"origin":13873,"position":1},"title":"10 Useful &#8220;IP&#8221; Commands to Configure Network Interfaces","author":"Paolo Redaelli","date":"2016-04-29","format":"link","excerpt":"http:\/\/www.tecmint.com\/ip-command-examples\/ When you read that ifconfig as been deprecated you realize your growing old: I use ifconfig almost subconsciously... It reminds me of the days I first installed Linux on my Amiga 1200 boosted with almighty 68060...","rel":"","context":"In &quot;Documentations&quot;","block_context":{"text":"Documentations","link":"https:\/\/monodes.com\/predaelli\/category\/documentations\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":7612,"url":"https:\/\/monodes.com\/predaelli\/2020\/09\/18\/internet-connection-sharing-with-networkmanager-fedora-magazine\/","url_meta":{"origin":13873,"position":2},"title":"Internet connection sharing with NetworkManager &#8211; Fedora Magazine","author":"Paolo Redaelli","date":"2020-09-18","format":"link","excerpt":"Internet connection sharing with NetworkManager - Fedora Magazine Or nmtui, nmcli and other commands for the shell wizard Internet connection sharing with NetworkManager Posted by Beniamino Galvani on June 17, 2020 NetworkManager is the network configuration daemon used on Fedora and many other distributions. It provides a consistent way to\u2026","rel":"","context":"In &quot;Documentations&quot;","block_context":{"text":"Documentations","link":"https:\/\/monodes.com\/predaelli\/category\/documentations\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1143,"url":"https:\/\/monodes.com\/predaelli\/2016\/03\/14\/how-to-secure-nginx-with-lets-encrypt-on-ubuntu-14-04-digitalocean\/","url_meta":{"origin":13873,"position":3},"title":"How To Secure Nginx with Let&#8217;s Encrypt on Ubuntu 14.04 | DigitalOcean","author":"Paolo Redaelli","date":"2016-03-14","format":false,"excerpt":"Following https:\/\/letsencrypt.readthedocs.org\/en\/latest\/using.html#installation you can obtain a nice SSL certificate for your own webservers; yet for those who likes NGinx like me this guide How To Secure Nginx with Let's Encrypt on Ubuntu 14.04 | DigitalOcean is also useful In this tutorial, we will show you how to use Let's Encrypt\u2026","rel":"","context":"In &quot;Software Libero&quot;","block_context":{"text":"Software Libero","link":"https:\/\/monodes.com\/predaelli\/category\/software\/software-libero\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":9107,"url":"https:\/\/monodes.com\/predaelli\/2022\/02\/16\/fai-fully-automatic-installation\/","url_meta":{"origin":13873,"position":4},"title":"FAI &#8211; Fully Automatic Installation","author":"Paolo Redaelli","date":"2022-02-16","format":"link","excerpt":"FAI - Fully Automatic Installation FAI is a tool for unattended mass deployment of Linux. It's a system to install and configure Linux systems and software packages on computers as well as virtual machines, from small labs to large-scale infrastructures like clusters and virtual environments. You can take one or\u2026","rel":"","context":"In &quot;Debian&quot;","block_context":{"text":"Debian","link":"https:\/\/monodes.com\/predaelli\/category\/debian\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":2355,"url":"https:\/\/monodes.com\/predaelli\/2017\/04\/14\/lets-chat\/","url_meta":{"origin":13873,"position":5},"title":"Let&#8217;s chat!","author":"Paolo Redaelli","date":"2017-04-14","format":false,"excerpt":"I've been lingering on OTFC #debian-it IRC channel and the almighty Elena of Valhalla made me discover the importance of maintain control over our communications that nowasdays are oftn channeled into various chat, social network and the like. So I've read her article \u00abModern XMPP Server\u00bb and Enrico Zini's \u00abModern\u2026","rel":"","context":"In &quot;Android&quot;","block_context":{"text":"Android","link":"https:\/\/monodes.com\/predaelli\/category\/smartphones\/android\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]}],"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/monodes.com\/predaelli\/wp-json\/wp\/v2\/posts\/13873","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/monodes.com\/predaelli\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/monodes.com\/predaelli\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/monodes.com\/predaelli\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/monodes.com\/predaelli\/wp-json\/wp\/v2\/comments?post=13873"}],"version-history":[{"count":0,"href":"https:\/\/monodes.com\/predaelli\/wp-json\/wp\/v2\/posts\/13873\/revisions"}],"wp:attachment":[{"href":"https:\/\/monodes.com\/predaelli\/wp-json\/wp\/v2\/media?parent=13873"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/monodes.com\/predaelli\/wp-json\/wp\/v2\/categories?post=13873"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/monodes.com\/predaelli\/wp-json\/wp\/v2\/tags?post=13873"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}