Skip to content
Educational satire No money Priced in time Human review required
BarkBowlTime-commerce dogfooding

DNS and registration boundary

DNS Boundary Console

Read-only operator guidance for A/AAAA, CAA, SPF/DMARC, DNSSEC, RDAP, and no-leak staging posture. This page does not change DNS.

DNS / DNSSEC / RDAP

DNS Boundary Console

DNS Boundary Console is a read-only operator checklist. DNS, DNSSEC, CAA, SPF/DMARC, and RDAP changes must be performed by an authorized human outside BarkBowl.

Package
1.29.0
Seed
2026.06.11.031
Surface
dns-boundary-console

A/AAAA

RecommendedPosture: point to the intended staging host or isolated review endpoint

Boundary: routing configuration only; no private-network probing from BarkBowl

OperatorCheck: Verify the authoritative DNS zone outside WordPress.

CAA

RecommendedPosture: restrict certificate issuance to approved certificate authorities

Boundary: prevents unauthorized issuance without claiming certifying authority

OperatorCheck: Confirm CAA record at DNS provider.

TXT SPF/DMARC

RecommendedPosture: use null-sender posture such as v=spf1 -all and DMARC reject when the subdomain does not send mail

Boundary: anti-spoofing signal only; does not send email or validate credentials

OperatorCheck: Confirm no mail systems depend on the subdomain before publishing.

DS/DNSKEY

RecommendedPosture: enable DNSSEC where registrar and DNS host support it

Boundary: cryptographic lookup integrity; not a runtime safety certificate

OperatorCheck: Confirm DS at registrar and DNSKEY at authoritative nameserver.

RDAP

RecommendedPosture: prefer RDAP JSON over legacy WHOIS for registration lookup evidence

Boundary: administrative verification only; no nonpublic scraping

OperatorCheck: Record RDAP status in operator evidence.