|
||
|
||
I’m the solo developer behind MarinaDNS, a free DNS and network diagnostics toolkit, and NODA, a DNS scoring framework I built on top of it. NODA isn’t a product I’m trying to sell—it’s an attempt at something closer to what SSL Labs did for TLS or Tranco did for domain ranking: a rigorous, transparent, and public methodology for answering “is this domain’s DNS actually healthy and well-configured,” scored on two separate axes instead of collapsed into one number that hides which question it’s actually answering.
To stress-test that methodology against something bigger than a handful of manually-checked domains, we scored 309 across three very different sectors—104 leading universities, 103 major museums, 102 global sports and outdoor brands—using NODA, a DNS assessment methodology we built to answer two separate questions about any domain: does the DNS actually work right now, and is it configured the way current standards recommend. We deliberately never blend those two into one grade. A domain can be perfectly reliable and badly under-secured at the same time, and collapsing that into a single number hides exactly the distinction that matters most to whoever has to fix it.
Once you can see all three sectors side by side, a pattern emerges that’s consistent enough to be more than coincidence: DNS security investment tracks visibility of the threat, not the resources available to fix it. Whichever control has caused a headline or a support ticket gets funded. The rest waits.
Nowhere is this sharper than in the sports-brand cohort. These are companies with real fraud teams, PCI compliance programs, and bot-mitigation budgets—security is not a resourcing problem for them. And yet:
Read that last point against the first two. The same companies leading every other sector on stopping phishing outright are simultaneously the worst at the control (DKIM) that DMARC’s own reporting depends on, and have essentially opted out of the one (DNSSEC) that protects against DNS-path attacks entirely. DMARC got funded because brand-impersonation phishing—“your order shipped,” counterfeit-goods scams—is a threat with a name, a headline, and a quantifiable cost. DKIM and DNSSEC protect against failure modes that rarely generate a support ticket, so they don’t get the same attention, even at companies that clearly know how to execute on DNS security when the case is made for them.
Universities present almost the inverse problem. Infrastructure-layer checks—nameserver redundancy, glue records, SOA hygiene—pass at rates above 95% across the sample; many of these institutions have held their domains since before DNSSEC or DMARC existed as standards, and that operational maturity shows. What doesn’t show is a matching maturity in the newer security layers: only 24% have DNSSEC enabled, and DMARC sits at `p=none` (monitor-only, blocking nothing) for 45.2% of the sample. The DNS works. The parts of DNS designed after 2005 haven’t fully caught up.
Museums broke the “sites work fine, hygiene is inconsistent” pattern that held for the other two sectors. Health scores here had a genuine floor of 36 out of 100 for at least one institution in the sample—not a configuration gap but actual operational degradation. Combine that with the highest single-AS exposure of any sector measured (73.8% of museums run every nameserver from one autonomous system) and the lowest DNSSEC adoption (15.5%), and the picture is consistent: a meaningful share of museum DNS infrastructure was set up once, by whoever built the original site, and hasn’t been revisited since—even as ticketing, membership, and donation flows increasingly run through the same domain.
None of this is really about universities, museums, or sports brands specifically. It’s about how DNS security investment actually gets allocated in practice, across any organization: reactively, against visible and nameable threats, rather than proactively against the full threat model DNS security tooling is designed to cover. DMARC enforcement is winnable because phishing is a story stakeholders already understand. DNSSEC is a harder sell precisely because a cache-poisoning attack that never happens generates no evidence that the investment mattered.
If there’s a practical takeaway for anyone running DNS for an organization that looks like any of these three—long-lived domain, security treated as invisible plumbing until something breaks—it’s this: audit for the quiet gaps deliberately, not just the ones that show up as tickets. DKIM missing underneath an enforced DMARC policy, or a single-AS nameserver setup that’s never caused an outage yet, are exactly the failure modes that don’t announce themselves until the day they do.
Full methodology (dual-axis scoring, 41-check catalogue, category weighting): https://noda.marinadns.io/methodology
Per-sector data, including top/bottom-five performers and full category breakdowns:
– https://noda.marinadns.io/research/universities
– https://noda.marinadns.io/research/museums
– https://noda.marinadns.io/research/sports-brands
Sponsored byVerisign
Sponsored byCSC
Sponsored byVerisign
Sponsored byDNIB.com
Sponsored byIPv4.Global
Sponsored byRadix
Sponsored byWhoisXML API