Blog
Guides and updates on domains, DNS, SSL, and uptime monitoring.
Post-quantum TLS migration: you're probably already doing it
Post-quantum key exchange is already in a third of real HTTPS traffic and most operators never noticed. What X25519MLKEM768 actually changes, why 'harvest now, decrypt later' makes key exchange urgent today, and a practical migration path — plus the half of the problem nobody has solved yet.
Read article →- SSL
ACME + ARI: automation that survives 47-day certificates
Surviving short-lived certificates means renewal automation that never blinks. A deep dive into ACME's challenge types and the ARI extension (RFC 9773) — how CAs now tell your client exactly when to renew, how to avoid thundering herds, and how mass revocation stops being a fire drill.
- DNS
What happens behind the scenes when you type a domain name
You type a domain, hit enter, and a page appears in under a second. In between, a dozen systems hand off to each other across the internet. Here's the whole journey — DNS, TCP, TLS, and HTTP — explained step by step.
- SSL
The 47-day certificate era
Public TLS certificate lifetimes are collapsing: 200 days today, 100 in 2027, 47 by 2029. Here's the schedule, why it's happening, and what an 8x jump in renewal frequency actually changes for the teams who run certificates.
- Domains
7 mistakes we see teams make with domain management
After watching how teams manage domains, the same expensive mistakes show up again and again — lapsed renewals, scattered registrars, expired certificates, and silent DNS changes. Here are the seven worst, and exactly how to fix each one.
- Uptime
Uptime monitoring: HTTP vs TCP checks, and how often to run them
Not all uptime checks are equal. Here's the difference between HTTP and TCP monitoring, how to pick check intervals, and what actually counts as "down."
- SSL
Your SSL certificate is about to expire: a calm checklist
An expired TLS certificate throws a full-page security warning and can take a site down outright. Here's what to check, and how to stop it from happening by surprise.
- DNS
DNS propagation explained: why your change isn't live yet
You updated a DNS record an hour ago and it's still serving the old value. Here's what "propagation" actually is, why TTL controls it, and how to check.
- DNS
DNS change monitoring: catch the change before it breaks something
A single edited DNS record can take a site offline or silently reroute your email. Here's why DNS changes are so easy to miss, and how monitoring catches them early.
- Domains
WHOIS and RDAP: what your domain record actually tells you
WHOIS is more than a registrar name. Here's how to read a domain record — expiry, status codes, nameservers — and why RDAP is quietly replacing it.
- Renewals
How to never miss a domain renewal again
A lapsed domain can take a site offline, break email, and even put your name on the open market. Here's a simple system for tracking renewals across every registrar.
- News
Introducing the Domnr blog
Why we built a fast, crawlable public surface with Astro — and what you can expect to read here.
No articles match your search.