Domain Governance

Every domain owned, renewed and provably healthy.

Domains are the quietest asset class you have: cheap to buy, easy to forget, catastrophic to lose. Lojycal puts each one in the operational graph with an owner, a renewal cost, a DNS posture and an evidence trail.

Why domains belong in the operational graph

A registrar invoice tells you what renews. It does not tell you who owns the domain, whether mail from it can be spoofed, whether a certificate lapses next month, or whether a forgotten subdomain still points at a service you shut down two years ago. Lojycal reconciles domains against the same records that already carry people, assets and contracts, so every name has an owner, a budget line and an audit trail.

What the module does today

Domain vault and ownership

Every apex and subdomain is registered with a named owner from the employee directory, a registrar and a renewal date — one list instead of several registrar logins.

Mail authentication health

MX, SPF, DKIM and DMARC are checked per domain, so a name that can be spoofed is visible as a finding rather than discovered through a phishing report.

Certificate and SSL posture

Certificates are inventoried with issuer, validity window and days remaining, and approaching expiry is raised ahead of time with the attributed owner.

Subdomain takeover risk

Dangling delegations that still point at decommissioned services are flagged so they are removed or re-pointed before someone else claims them.

Renewal cost forecasting

Registrar cost and renewal dates roll up into a forward view, putting domain spend next to licences, hardware and cloud in the same financial picture.

Evidence and decision history

Ownership changes, exemptions and remediation decisions are written with actor, reason and timestamp, and export as a record for an auditor.

How it works

  1. 1. Load the portfolio

    Domains are imported or entered once, with registrar, renewal date and cost. Nothing in your DNS is modified.

  2. 2. Attach an owner

    Each domain is bound to an employee, mailbox or distribution group, so accountability survives a change of team.

  3. 3. Run the health checks

    DNS records, certificates and delegation posture are read on a schedule, and each observation is dated.

  4. 4. Decide under governance

    Findings are accepted, remediated or exempted as recorded decisions — never resolved silently.

Evidence, not screenshots

When an auditor asks who owns a domain, when its certificate last renewed, or why a DMARC policy is set to none, the answer is a dated record with an actor and a reason attached — not a reconstruction from registrar emails.

Every observation is dated — reports point at an observation window.

Frequently asked questions

See domain governance on your own portfolio

We walk your domains, DNS posture and renewal exposure through the graph in a live session.