Reference guides
Guides
Practical reference material for self-hosters watching the edge of their domain. Certificate Transparency, typosquat detection, TLS cert expiry, and domain ownership verification — real answers, not keyword filler.
How to monitor your subdomains with Certificate Transparency
Every certificate issued to a subdomain of your domain is published to a public CT log within minutes. Continuous diffing against a baseline catches forgotten staging boxes and shadow IT the moment they get a cert.
Read the guide →How to detect typosquat and lookalike domains targeting you
A registered acme-support.net or аcme.com (with a Cyrillic 'а') is phishing infrastructure being assembled before the attack. Learn how to enumerate permutations, check them via RDAP, and respond when you find one.
Read the guide →How to stop a TLS certificate from expiring (Caddy & certbot)
Caddy and certbot both auto-renew — but failed ACME challenges, rate limits, and unmaintained subdomains still let certs expire. External monitoring catches what your box cannot report when it is down.
Read the guide →Verifying domain ownership with a DNS TXT record or well-known file
Before monitoring your domain, Perimeter verifies you control it — the same way ACME, Google Search Console, and dozens of other services do. Here is how both methods work and what to do if verification fails.
Read the guide →See what the internet already knows about your domain
Free one-shot report — no signup, no credit card. Built entirely on public data.
Run the free report