Documentation
Changes & incidents
How individual differences become one reviewable item, and what the severity and confidence on it mean.
From change to incident
Each conclusive observation is compared against known state. A difference becomes a change event. Change events for a zone inside a correlation window are then evaluated against a set of risk rules; when one matches, the events are grouped into an incident.
Risk patterns
- Possible domain takeover — nameservers changed, DS removed, addresses moved to a previously unseen ASN, new certificate issued, MX changed. Two or more indicators raise it to HIGH; more raise it to CRITICAL.
- Mail interception risk — MX changed, SPF weakened or DMARC relaxed, strengthened by a new TLS certificate on the mail path.
- Routing anomaly — DNS unchanged but origin ASN changed, RPKI became invalid, or endpoint reachability shifted.
- Unexpected certificate issuance — a certificate seen in CT for your domain that you did not expect.
Severity and confidence
Severity is how bad it would be if real: info, low, medium, high, critical. Confidence is how sure the correlation is: low through very_high. A change inside a declared maintenance window is dampened one severity level rather than suppressed.
Review workflow
Every change and incident carries a review state, so triage is recorded rather than remembered:
- Unreviewed — the default; the actionable state.
- Investigating — picked up by someone.
- Expected — a known, authorised change.
- Unauthorized — confirmed bad; the one state that stays visually loud.
- False positive / Resolved — terminal states.
Set them from the Events or Investigate views, or from a zone's own Timeline and Incidents tabs.