SPB Git forge

spb/websensor

Public
33commits 1branches 0releases
3.4 MBsize
maindefault branch
10 days agolast push
TypeScript 55.4% Python 43.2% SQL 1.2%
1.5 KB

# Connector: DNS records (dns)

Purpose: the DNS posture of an organization's apex domain — hosting migrations (A/AAAA), DNS-provider changes (NS), mail-provider changes (MX), SPF / DMARC / domain-verification tokens (TXT, _dmarc), CA restrictions (CAA), SOA administrative fields. These are textbook silent changes: nobody announces them. Sensor URL: dns://example.com (only the host is used). Sensor type: DNS, tier D. Config: records? (default A, AAAA, NS, MX, TXT, CAA, SOA, DS-via-ANY), resolvers? (1.1.1.1, 8.8.8.8, 9.9.9.9), includeDmarc? (true). Normalization: JSON snapshot; every record set sorted, hostnames lower-cased, SOA serial excluded (changes on every zone edit), TXT chunks joined. Missing record types are empty arrays (ENODATA), resolver errors are { error: code } per type; the fetch fails only when every query failed. extra: A/AAAA counts, NS, MX, SPF, DMARC, CAA. Safety: the host goes through isBlockedHostname (no cluster / private / single-label names); queries go to public resolvers only, never to the target. Known quirks: node:dns has no DS query — DNSSEC presence is approximated from resolveAny record types when the resolver supports ANY (many refuse it: field absent, not an error). Round-robin A records that rotate on every query (large CDNs) will look like changes: prefer the www host's TLS sensor for those and keep DNS on the apex. Tests: connectors2.test.ts (hostOf). Verified: 2026-09-08 on the 77 tier S/A founding domains.