A/AAAA
RecommendedPosture: point to the intended staging host or isolated review endpoint
Boundary: routing configuration only; no private-network probing from BarkBowl
OperatorCheck: Verify the authoritative DNS zone outside WordPress.
DNS and registration boundary
Read-only operator guidance for A/AAAA, CAA, SPF/DMARC, DNSSEC, RDAP, and no-leak staging posture. This page does not change DNS.
DNS / DNSSEC / RDAP
DNS Boundary Console is a read-only operator checklist. DNS, DNSSEC, CAA, SPF/DMARC, and RDAP changes must be performed by an authorized human outside BarkBowl.
RecommendedPosture: point to the intended staging host or isolated review endpoint
Boundary: routing configuration only; no private-network probing from BarkBowl
OperatorCheck: Verify the authoritative DNS zone outside WordPress.
RecommendedPosture: restrict certificate issuance to approved certificate authorities
Boundary: prevents unauthorized issuance without claiming certifying authority
OperatorCheck: Confirm CAA record at DNS provider.
RecommendedPosture: use null-sender posture such as v=spf1 -all and DMARC reject when the subdomain does not send mail
Boundary: anti-spoofing signal only; does not send email or validate credentials
OperatorCheck: Confirm no mail systems depend on the subdomain before publishing.
RecommendedPosture: enable DNSSEC where registrar and DNS host support it
Boundary: cryptographic lookup integrity; not a runtime safety certificate
OperatorCheck: Confirm DS at registrar and DNSKEY at authoritative nameserver.
RecommendedPosture: prefer RDAP JSON over legacy WHOIS for registration lookup evidence
Boundary: administrative verification only; no nonpublic scraping
OperatorCheck: Record RDAP status in operator evidence.