How security decisions get made, written out in full.
No gated PDFs and no webinars. These are the working methods behind a Warden assessment — how findings are ranked, what evidence counts, and how a decision is recorded so it holds up to a board or an auditor.
- Exposure teardown · 9 min read
SPF: too many DNS lookups — and the bigger number underneath it
Fixing a PermError gets mail flowing again; it does not reduce what the record trusts. A worked count on a real chain that authorized 1,086,996 addresses, and how to run the same count on your own domain in five minutes.
- Questionnaires · 8 min read
How to answer a customer security questionnaire without a security team
A questionnaire is an evidence-retrieval test, not a security test. The four answer states, the eleven artifacts that cover most of every questionnaire, and how to write a defensible “no” without stalling the deal.
- Prioritization · 7 min read
How to prioritize security findings when everything is labelled critical
CVSS scores a vulnerability, not the risk it carries in your estate. Three questions — reachability, exploitability, business relevance — with a worked reordering that puts one 9.8 first and an identical 9.8 last.
Exposure check
The two signals anyone can read without your permission — the DNS that says who may send mail as you, and the headers your homepage returns — read and returned as prioritized findings, each with its evidence and one recommended action.
SPF DNS lookup checker
The count from the teardown, run as code: lookups against the limit of 10, and how many IPv4 addresses your record authorizes to send mail as you. Public DNS only, every record shown as evidence.
More are being written. If you would rather see the method applied to your own domain than read about it, get a free Exposure Check.