> ## Documentation Index
> Fetch the complete documentation index at: https://docs.rad.security/llms.txt
> Use this file to discover all available pages before exploring further.

# Domain Security Integrations

> Connect your domain registrar and DNS platforms to RAD Security for domain portfolio, DNS posture, and TLS visibility.

# Domain Security Integrations

Integrate your domain and DNS platforms with RAD Security to bring your domain portfolio, DNS security posture, DNS zone records, and TLS certificates into a single view for external attack-surface and brand-protection analysis.

These integrations are **read-only**. RAD Security pulls domain, DNS, and certificate data from your provider on a scheduled basis. RAD never registers, modifies, or deletes domains, DNS records, or certificates in your provider.

## Benefits

<CardGroup cols={2}>
  <Card title="Domain Portfolio Visibility" icon="globe">
    Inventory your domains and track registrar locks, DNSSEC, and key DNS posture signals.
  </Card>

  <Card title="DNS Posture Monitoring" icon="shield-check">
    Surface DKIM/SPF/DMARC presence, DNSSEC status, and record configuration across your zones.
  </Card>

  <Card title="TLS Certificate Tracking" icon="certificate">
    Monitor certificate common names, validity windows, and status to catch expiry and misconfiguration.
  </Card>

  <Card title="Brand Protection" icon="shield-halved">
    Reduce external attack surface and support brand-protection analysis across your domain footprint.
  </Card>
</CardGroup>

## Supported Integrations

<AccordionGroup>
  <Accordion title="CSC Global" icon="globe">
    **Status:** Available

    [View Setup Guide →](/rad-security/integrations/domain-security/csc-global-setup)

    Connect CSC Global DomainManager to ingest your domain portfolio, DNS security posture, DNS zone records, and TLS certificates. CSC Global covers domain **registration** and **TLS**.

    **Key Features:**

    * Domain portfolio and DNS security posture
    * DNS zone records (A/AAAA/CNAME/MX/TXT/NS/SRV/CAA)
    * TLS certificates
    * Dual-credential (API token + API key) authentication
  </Accordion>

  <Accordion title="DNS Made Easy" icon="server">
    **Status:** Available

    [View Setup Guide →](/rad-security/integrations/domain-security/dns-made-easy-setup)

    Connect DNS Made Easy to ingest your managed domains/zones and DNS records, including GTD/failover configuration. DNS Made Easy covers **operational DNS** (DNS-only — no registration or TLS issuance).

    **Key Features:**

    * Managed domains/zones as domain assets
    * DNS records (A/AAAA/CNAME/MX/TXT/NS/SRV/CAA)
    * GTD/failover configuration and DNSSEC status
    * API key + secret (HMAC-signed) authentication
  </Accordion>

  <Accordion title="EasyDMARC" icon="envelope-circle-check">
    **Status:** Available

    [View Setup Guide →](/rad-security/integrations/domain-security/easydmarc-setup)

    Connect EasyDMARC to ingest DMARC domain posture and email-authentication telemetry. EasyDMARC covers **email authentication** (DMARC/SPF/DKIM) — aggregate (RUA) reports plus optional, PII-redacted failure (RUF) reports.

    **Key Features:**

    * DMARC/SPF/DKIM posture and enforcement policy per domain
    * Aggregate (RUA) reports with findings on authentication failures
    * Optional failure (RUF) reports — opt-in, addresses hashed and subjects redacted
    * OAuth2 client-credentials (Client ID + Secret Key) authentication
  </Accordion>

  <Accordion title="Mimecast DMARC Analyzer" icon="envelope-circle-check">
    **Status:** Available (Beta)

    [View Setup Guide →](/rad-security/integrations/domain-security/mimecast-dmarc-analyzer-setup)

    Connect Mimecast DMARC Analyzer to ingest DMARC domain posture and DNS record-change/issue events, plus DMARC reports. Mimecast DMARC Analyzer covers **email authentication** (DMARC/SPF/DKIM) via the Mimecast API 2.0.

    **Key Features:**

    * DMARC/SPF/DKIM posture and enforcement policy per domain
    * DNS record-change/issue events, ingested incrementally
    * Aggregate (RUA) reports plus optional, PII-redacted failure (RUF) reports
    * OAuth2 client-credentials (Client ID + Client Secret) authentication, requires the DMARC Analyzer Product entitlement
  </Accordion>
</AccordionGroup>

## What Data is Collected

<AccordionGroup>
  <Accordion title="Domain Portfolio & Posture" icon="globe">
    * Domains and their DNS security posture
    * Registrar locks, DNSSEC status, and protection flags
    * Nameserver and reachability signals
  </Accordion>

  <Accordion title="DNS Zone Records" icon="server">
    * A/AAAA/CNAME/MX/TXT/NS/SRV/CAA records
    * GTD/failover configuration (where supported)
  </Accordion>

  <Accordion title="TLS Certificates" icon="certificate">
    * Common name and subject
    * Validity dates and status
  </Accordion>
</AccordionGroup>

## Use Cases

<CardGroup cols={2}>
  <Card title="Attack Surface Analysis" icon="diagram-project">
    Map your external footprint across domains, DNS records, and certificates.
  </Card>

  <Card title="DNS Posture Hygiene" icon="shield-check">
    Track DKIM/SPF/DMARC, DNSSEC, and registrar locks across your portfolio.
  </Card>

  <Card title="Certificate Lifecycle" icon="certificate">
    Catch expiring or misconfigured TLS certificates before they cause outages.
  </Card>

  <Card title="Brand Protection" icon="shield-halved">
    Monitor your domain portfolio to support brand-protection workflows.
  </Card>
</CardGroup>

## Getting Started

<Steps>
  <Step title="Choose Your Platform">
    Select your domain or DNS platform from the supported integrations above. CSC Global and DNS Made Easy are complementary — registration/TLS versus operational DNS.
  </Step>

  <Step title="Generate API Credentials">
    Create API credentials with read access in your provider.
  </Step>

  <Step title="Configure in RAD Security">
    Add the integration in your RAD Security workspace with the generated credentials.
  </Step>

  <Step title="Verify Connection">
    Confirm the integration is active and data is being synced.
  </Step>
</Steps>

## Next Steps

<CardGroup cols={2}>
  <Card title="CSC Global Setup" icon="globe" href="/rad-security/integrations/domain-security/csc-global-setup">
    Connect CSC Global for domain registration and TLS
  </Card>

  <Card title="DNS Made Easy Setup" icon="server" href="/rad-security/integrations/domain-security/dns-made-easy-setup">
    Connect DNS Made Easy for operational DNS
  </Card>

  <Card title="Data Sources Overview" icon="database" href="/rad-security/integrations/data-sources">
    Explore all available data sources
  </Card>
</CardGroup>
