Security questionnaire
Every domain question on a vendor security questionnaire, answered.
The domain section of a CAIQ, SIG, or custom questionnaire comes down to 15 questions about DNS, email authentication, TLS, and web security. Each page below gives you the exact Yes/No/Partial wording to submit, the SOC 2 and ISO 27001 controls it evidences, and a free check that tells you which answer is true for your domain right now.
Answering these on behalf of clients? Get a free workpaper across five client domains, with your firm on the cover.
DNS
- Are the standard apex DNS records (A/AAAA/NS) published and resolving correctly?
Without authoritative A or AAAA records on the apex, the domain is unreachable. Missing baseline DNS shows up in vendor reviews as evidence of unmanaged infrastructure (SOC 2 CC6.6).
Appears in CAIQ, SIG · SOC 2 CC6.6, ISO 27001 A.8.20, NIST 800-53 SC-20
- Is DNSSEC enabled on the apex domain?
DNSSEC cryptographically signs DNS responses, blocking cache-poisoning attacks. US federal civilian agencies are required to enable it under OMB M-22-09 (NIST SC-20).
Appears in CAIQ, SIG, ISO 27001 · SOC 2 CC6.6, ISO 27001 A.8.20, NIST 800-53 SC-20
- Does the domain publish valid MX records for inbound mail handling?
MX records direct inbound mail. Misconfiguration silently breaks email delivery and lets attackers stand up parallel MX hosts for spoofing campaigns (ISO 27001 A.8.21).
Appears in CAIQ, SIG · SOC 2 CC6.7, ISO 27001 A.8.21, NIST 800-53 SC-8
- Is SPF published with a hardfail (-all) policy on the sending domain?
SPF tells receiving servers which hosts may send mail for the domain. Without it, any sender can forge the envelope-from — the primary mechanism behind business-email-compromise (SOC 2 CC6.7).
Appears in CAIQ, SIG, SOC 2 · SOC 2 CC6.7, ISO 27001 A.8.20, NIST 800-53 SC-8
- Does your domain enforce DMARC with a quarantine or reject policy?
DMARC binds SPF and DKIM into an enforceable policy (quarantine or reject) and surfaces spoofing attempts via aggregate reports. `p=none` or absent means spoofing succeeds silently (SOC 2 CC6.7).
Appears in CAIQ, SIG, SOC 2 · SOC 2 CC6.7, ISO 27001 A.5.14, NIST 800-53 SC-8
- Are DKIM keys published with sufficient key strength (>= 1024 bits)?
DKIM signs outbound mail so receivers can detect tampering. Missing selectors or rotated-away keys break DMARC alignment and let receivers downgrade trust (ISO 27001 A.8.24).
Appears in CAIQ, SIG, SOC 2 · SOC 2 CC6.7, ISO 27001 A.8.24, NIST 800-53 SC-8
- Is MTA-STS published to enforce TLS for inbound SMTP?
MTA-STS forces inbound SMTP to use TLS and refuse downgraded connections. Without it, an in-path attacker can strip TLS and read mail in plaintext (SOC 2 CC6.7).
Appears in CAIQ, SIG, ISO 27001 · SOC 2 CC6.7, ISO 27001 A.8.24, NIST 800-53 SC-8
- Is TLS-RPT (SMTP TLS Reporting) published for failure visibility?
TLS-RPT publishes a reporting address for SMTP-TLS failures. Without it, downgrade attacks on inbound mail go unnoticed (SOC 2 CC7.2).
Appears in CAIQ, SIG · SOC 2 CC7.2, ISO 27001 A.8.16, NIST 800-53 AU-6
TLS
- Is the public web endpoint protected by a valid TLS certificate from a trusted CA?
A valid current TLS certificate is the baseline for data in transit. Expiry, weak chain, or hostname mismatch break HTTPS and fail PCI 4.2.1 / SOC 2 CC6.1.
Appears in CAIQ, SIG, ISO 27001, SOC 2 · SOC 2 CC6.1, ISO 27001 A.8.24, NIST 800-53 SC-8(1)
- Are TLS certificates monitored via Certificate Transparency logs for unauthorised issuance?
Every certificate issued for this domain is published in Certificate Transparency logs — including subdomains you may have forgotten. Unknown subdomains in CT are pre-disclosed attack surface (ISO 27001 A.8.16).
Appears in SIG, ISO 27001 · SOC 2 CC7.2, ISO 27001 A.8.16, NIST 800-53 SI-4
Web security
- Does the public web endpoint redirect HTTP to HTTPS within a single hop?
Bare HTTP requests must redirect to HTTPS without dropping the user mid-chain. Plain-text fallback or open redirects fail PCI 4.2.1 and feed phishing chains (SOC 2 CC6.6).
Appears in CAIQ, SIG, SOC 2 · SOC 2 CC6.6, ISO 27001 A.8.23, NIST 800-53 SC-7
- Are HSTS, CSP, X-Frame-Options, and X-Content-Type-Options set on the public web endpoint?
Security headers — HSTS, CSP, X-Frame-Options, Referrer-Policy — defend against XSS, clickjacking, and downgrade attacks. Absent headers map directly to OWASP ASVS V14 findings (ISO 27001 A.8.23).
Appears in CAIQ, SIG, ISO 27001, SOC 2 · SOC 2 CC6.6, ISO 27001 A.8.23, NIST 800-53 SC-7(8)
- Does the public web endpoint avoid a permissive (wildcard) CORS configuration on credentialed responses?
Overly permissive CORS (wildcard with credentials, or reflected origin) lets any origin read authenticated responses from this domain. OWASP A05 misconfiguration territory (NIST AC-4).
Appears in CAIQ, SIG · SOC 2 CC6.6, ISO 27001 A.8.23, NIST 800-53 AC-4
- Has the public web surface (server identification, exposed paths) been reviewed?
Public files — robots.txt, sitemap.xml, head meta — are what attackers see first during reconnaissance. Misadvertised paths, stale sitemaps, and verbose generators leak more than intended (ISO 27001 A.8.9).
Appears in CAIQ, SIG, ISO 27001 · SOC 2 CC6.6, ISO 27001 A.8.9, NIST 800-53 CM-7
Identity
- Is the domain registration verifiable via WHOIS / RDAP with active status?
Registrar and expiry tell auditors the domain is owned, current, and not about to lapse. An expired or about-to-expire domain fails business-continuity evidence (SOC 2 A1.2).
Appears in SIG, ISO 27001 · SOC 2 CC2.3, ISO 27001 A.5.20, NIST 800-53 PE-2