惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

美团技术团队
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Martin Fowler
Martin Fowler
雷峰网
雷峰网
IT之家
IT之家
小众软件
小众软件
M
MIT News - Artificial intelligence
博客园 - 聂微东
J
Java Code Geeks
Blog — PlanetScale
Blog — PlanetScale
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
A
About on SuperTechFans
G
Google Developers Blog
Engineering at Meta
Engineering at Meta
Recent Announcements
Recent Announcements
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
The GitHub Blog
The GitHub Blog
F
Fortinet All Blogs
C
Check Point Blog
云风的 BLOG
云风的 BLOG
腾讯CDC
H
Help Net Security
Y
Y Combinator Blog
I
InfoQ

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
I analyzed stripe.com and github.com — their DNS reveals ...
John Leslie · 2026-05-19 · via DEV Community

John Leslie

I can tell you Stripe uses Greenhouse for hiring before they have posted a job listing. I can tell you GitHub runs Zendesk for support and Marketo for marketing automation. All from a single DNS query.

Every domain broadcasts its infrastructure to the world through DNS records, SSL certificates, and HTTP headers. Most people never look. I built DomainIntel — a free API that reads all of it in one call. No API key, no signup.

Try it on your own company right now:

curl "https://domainintel.vercel.app/api/lookup?domain=yourcompany.com"

Enter fullscreen mode Exit fullscreen mode

Here is what it found on two companies everyone knows.

Stripe.com: lean stack, strict security

Mail provider: Google Workspace

SPF record reveals their outbound email stack:

  • spf1.stripe.com — transactional email (their own infrastructure)
  • greenhouse-outbound-mail.stripe.comGreenhouse (applicant tracking for hiring)
  • _spf.qualtrics.comQualtrics (surveys and feedback collection)

Three services. That is a deliberately lean setup for a company processing billions in payments.

DMARC policy: p=reject — the strictest setting possible. Any email claiming to be from stripe.com that fails authentication gets rejected outright, never delivered. This is what you want to see from a company handling your payment data.

GitHub.com: massive footprint, softer security

Mail provider: Microsoft 365

SPF record tells a very different story:

  • spf.protection.outlook.com — Microsoft 365 (primary email)
  • _netblocks.google.com — Google (likely legacy or marketing)
  • mail.zendesk.comZendesk (customer support)
  • _spf.salesforce.comSalesforce (CRM)
  • servers.mcsv.netMailchimp (newsletters)
  • mktomail.comMarketo (marketing automation)
  • sendgrid.netSendGrid (transactional email)

Seven authorized email senders. Each one is a potential phishing vector — an attacker who compromises any of these services can send email that passes GitHub's SPF checks. This is the tradeoff of a large enterprise stack: more capability, more surface area.

DMARC policy: p=quarantine — suspicious emails get flagged but not rejected. Less strict than Stripe. For a company that is the target of constant phishing campaigns (fake GitHub security alerts are one of the most common phishing templates), this is a notable choice.

WHOIS: MarkMonitor registrar (the enterprise-grade registrar used by most Fortune 500 companies). Domain age: 18+ years, created October 2007.

SSL: Sectigo certificate with 75 days until expiry.

The comparison matters

Stripe authorizes 3 email senders with a reject policy. GitHub authorizes 7 with a quarantine policy. This is not random — it reflects fundamentally different security philosophies. Stripe optimizes for minimum attack surface. GitHub optimizes for operational flexibility at the cost of a wider trust perimeter.

If you were evaluating either company as a vendor, this single API call tells you more about their security posture than their marketing page does.

A practical walkthrough: vendor evaluation

Say you are evaluating a B2B SaaS company as a potential vendor. You run their domain:

curl "https://domainintel.vercel.app/api/lookup?domain=example-vendor.com"

Enter fullscreen mode Exit fullscreen mode

What to look for:

  • Google Workspace or Microsoft 365 in the mail providers — real company with proper email infrastructure
  • Marketo or HubSpot in SPF — they have a marketing team, likely 50+ employees
  • DMARC set to none or missing — red flag, not protecting against email spoofing
  • SSL certificate expiring in under 30 days — operational hygiene issue
  • Domain age under 1 year — proceed with extra caution

One call, 5 data points, a much clearer picture than a LinkedIn search.

Connect it

REST API (no auth, free):

curl "https://domainintel.vercel.app/api/lookup?domain=stripe.com"

Enter fullscreen mode Exit fullscreen mode

MCP server for Claude, Cursor, or VS Code — add to your config:

{
  "mcpServers": {
    "domainintel": {
      "url": "https://domainintel.vercel.app/api/mcp"
    }
  }
}

Enter fullscreen mode Exit fullscreen mode

5 tools available: whois_lookup, dns_lookup, ssl_check, tech_stack, full_report

Free. No API key. Try it on any domain.