FIELD NOTES · UPDATED WEEKLY

DomainScan blog — field notes from the diagnostic layer of the web.

Deep-dives on AI readiness, DNS, SSL, email authentication and the small engineering choices that make domain tooling actually trustworthy. Written by the team that builds the platform. New posts most weeks.

01 · CATEGORIES

What we write about

Seven recurring topic threads. Skim by tag from the index page or read in chronological order:

Fraud & scam infrastructure (Fraud)

Fake courier sites, UPI scams, fake checkout pages, the ₹25 redelivery con — how scam campaigns are built, what they have in common, and how to break them down.

Lookalike domains (Domains)

Typosquatting, homograph attacks, punycode spoofing, dashed brand impersonation — the URL tricks behind most payment phishing, and the WHOIS checks that catch them.

AI readiness & GEO (AI)

How GPTBot, ClaudeBot and PerplexityBot read the web. llms.txt format, robots.txt AI policies, structured data for AI, brand mention signals, passage-level citability.

DNS deep-dives (DNS)

DNSSEC, propagation, resolver behavior, anycast, NSEC walks, CAA records, EDNS Client Subnet, the long tail of edge cases nobody documents.

TLS & web security (Security)

Certificate transparency, OCSP stapling, post-quantum readiness, HSTS preload, mTLS, the tricky parts of CSP and Permissions-Policy. Plus the HTTPS padlock myth — why valid SSL doesn't mean safe.

Email authentication (Email)

SPF lookup arithmetic, DKIM key rotation, DMARC reporting analysis, BIMI, ARC chains and why your perfectly configured stack still hits spam.

Engineering posts (Build)

How we build DomainScan — edge architecture, caching strategy, observability, performance budgets and the small choices that compound.

02 · LATEST

Recent posts

How to verify a website is safe before you pay (Security · 11 min · Jun 14, 2026)

Before you type a card number or scan a UPI QR, run a site through these seven checks: domain age, SSL, nameservers, blacklist, reverse IP, HTTP headers, brand cross-check.

Payment scam websites — 12 red flags fraudsters hope you miss (Fraud · 10 min · Jun 12, 2026)

Exact patterns on fake checkout pages — new domains, hidden WHOIS, suspicious nameservers, fake trust badges and the QR-code tricks costing Indians ₹400 crore a year.

Lookalike domains & typosquatting — how scammers hijack your checkout (Domains · 9 min · Jun 9, 2026)

Walkthrough of the URL tricks behind payment phishing — typo swaps, dash insertions, homograph attacks and punycode spoofs — with real examples and the WHOIS checks that catch them.

The HTTPS padlock lie — why SSL doesn't mean safe (Security · 8 min · Jun 6, 2026)

The padlock only proves the connection is encrypted, not that the site is legit. Most phishing pages in 2026 have valid SSL — what to actually check instead.

Fake courier & delivery scam sites — the 2026 playbook (Fraud · 10 min · Jun 3, 2026)

Inside the ₹25 redelivery scam: how fraudsters impersonate India Post, DHL, FedEx and Blue Dart, the SMS hooks they use, and how to verify a courier URL in 60 seconds.

AI Readiness: the new SEO surface area in 2026 (AI · 12 min · May 22, 2026)

Why every domain needs to think about how GPTBot, Claude-Web and PerplexityBot see it — and the five signals (JSON-LD, llms.txt, SSR, bot-aware robots.txt, canonical hygiene) that actually move the needle.

llms.txt explained — a markdown TOC for LLMs (AI · 11 min · May 18, 2026)

The emerging convention for telling AI systems which of your pages matter most. Format spec, ship-it-this-afternoon playbook, and real-world examples from GitHub, Anthropic, Cloudflare, Stripe and Vercel.

03 · SUBSCRIBE

Get new posts by email

Roughly one post per week. No drip campaigns, no upsell emails, no third-party tracking pixels — just the post in your inbox.

  • Cadence One email per published post. Skip a week if there's no new post — never a filler send.
  • Format Title, excerpt, link. Plain text version available — pick from the subscribe form.
  • Unsubscribe One-click in every email. No login required. Removed from the list within minutes.