simpl.
Cybersecurity GRC 14 items

DNS Security Controls Review

Reviews DNS security controls across resolver protection, DNSSEC, protective filtering, logging, and registrar/zone integrity to defend against tunneling, hijacking, and abuse.

NIST 800-81NIST 800-53CIS v8

Free PDF · enter your email to download.

Resolver & Filtering

  • Are endpoints restricted to approved internal or protective DNS resolvers? *
  • Is protective DNS filtering used to block known-malicious domains? *
  • Is outbound DNS to unauthorized external resolvers blocked at the firewall? *
  • Is encrypted DNS (DoH/DoT) governed by policy rather than uncontrolled?

DNSSEC & Integrity

  • Is DNSSEC signing enabled for authoritative zones you control? *
  • Is DNSSEC validation enabled on recursive resolvers? *
  • Are DNSSEC keys rotated and DS records maintained at the registrar?

Registrar & Zone Protection

  • Is registrar/registry lock enabled to prevent unauthorized domain transfers? *
  • Is MFA enforced on registrar and DNS management accounts? *
  • Are zone changes subject to change control and review?
  • Are critical domain expiration dates monitored and auto-renewal enabled?

Monitoring & Detection

  • Are DNS query logs collected and retained for analysis? *
  • Is DNS tunneling and anomalous query behavior monitored? *
  • Are newly registered and typosquat lookalike domains monitored?

Download the full DNS Security Controls Review checklist

Get it as a clean, printable PDF — free.