Domain.Posture

Security questionnaire

Every domain question on a vendor security questionnaire, answered.

The domain section of a CAIQ, SIG, or custom questionnaire comes down to 15 questions about DNS, email authentication, TLS, and web security. Each page below gives you the exact Yes/No/Partial wording to submit, the SOC 2 and ISO 27001 controls it evidences, and a free check that tells you which answer is true for your domain right now.

Answering these on behalf of clients? Get a free workpaper across five client domains, with your firm on the cover.

DNS

  • Are the standard apex DNS records (A/AAAA/NS) published and resolving correctly?

    Without authoritative A or AAAA records on the apex, the domain is unreachable. Missing baseline DNS shows up in vendor reviews as evidence of unmanaged infrastructure (SOC 2 CC6.6).

    Appears in CAIQ, SIG · SOC 2 CC6.6, ISO 27001 A.8.20, NIST 800-53 SC-20

  • Is DNSSEC enabled on the apex domain?

    DNSSEC cryptographically signs DNS responses, blocking cache-poisoning attacks. US federal civilian agencies are required to enable it under OMB M-22-09 (NIST SC-20).

    Appears in CAIQ, SIG, ISO 27001 · SOC 2 CC6.6, ISO 27001 A.8.20, NIST 800-53 SC-20

Email

TLS

Web security

Identity