feat: add posture dashboard playbooks
This commit is contained in:
@@ -222,6 +222,7 @@ Planned:
|
||||
- MTA-STS posture: delivered cached `_mta-sts` TXT checks, HTTPS policy validation, domain-detail evidence, and operator guidance for missing, invalid, or non-enforcing policies. Optional helper tooling remains a future enhancement.
|
||||
- TLS reporting posture: delivered authenticated TLS-RPT upload for `.json`, `.json.gz`, and `.zip` attachments; duplicate-safe persistence by report ID and policy domain; daily session trends; top failure-cause grouping; affected-domain summaries; and explicit privacy controls that avoid storing message content or recipient data.
|
||||
- BIMI posture: delivered default-selector BIMI TXT validation, HTTPS logo/certificate URL checks, DMARC enforcement readiness checks, domain-detail evidence, and operator guidance for missing or blocked BIMI prerequisites.
|
||||
- Posture dashboard and operator playbooks: delivered a per-domain posture score, coverage cards for DMARC/SPF/DKIM/MTA-STS/BIMI, evidence-linked recommendations, provider-backed DNS drift summaries, and short remediation playbooks.
|
||||
- Extended DNS checks that support the posture surface (e.g., MX/BIMI; optional DANE/TLSA where relevant).
|
||||
|
||||
Exit criteria:
|
||||
|
||||
@@ -105,6 +105,18 @@ GET /domains/{domain_id}/dns/bimi
|
||||
Returns the cached BIMI TXT posture for the default selector, including the
|
||||
queried DNS name, record text, logo URL, certificate URL, warnings, and errors.
|
||||
|
||||
#### Get Posture Dashboard
|
||||
|
||||
```
|
||||
GET /domains/{domain_id}/posture
|
||||
```
|
||||
|
||||
Returns the evidence-first posture dashboard for one domain. The response
|
||||
contains the posture score, coverage for DMARC, SPF, DKIM, MTA-STS, and BIMI,
|
||||
actionable recommendations, recent provider-backed DNS drift summaries, and
|
||||
short operator playbooks. Recommendation and playbook evidence links point back
|
||||
to the page section that triggered the finding.
|
||||
|
||||
#### Add Domain
|
||||
|
||||
```
|
||||
|
||||
@@ -63,6 +63,22 @@ DMARQ provides a health check feature for each domain:
|
||||
- MX record confirmation
|
||||
- BIMI record validation (if applicable)
|
||||
|
||||
### Posture Dashboard
|
||||
|
||||
The domain detail page starts with an evidence-first posture dashboard. It
|
||||
summarizes coverage for DMARC, SPF, DKIM, MTA-STS, and BIMI, assigns a simple
|
||||
posture score, and shows each recommendation with links back to the DNS record,
|
||||
report trend, sending-source table, or posture evidence that triggered it.
|
||||
|
||||
The same surface includes a **What Changed** panel when provider-backed DNS
|
||||
change tracking has observed additions, edits, or removals. Those summaries are
|
||||
designed for drift review: operators can see the previous and current values
|
||||
without reading logs.
|
||||
|
||||
Operator playbooks sit beside the recommendations. They are short remediation
|
||||
checklists for common gaps such as missing SPF, missing DKIM, policy enforcement
|
||||
readiness, MTA-STS setup, or BIMI prerequisites.
|
||||
|
||||
### MTA-STS Posture
|
||||
|
||||
The domain detail page checks `_mta-sts.<domain>` and fetches the policy from `https://mta-sts.<domain>/.well-known/mta-sts.txt`.
|
||||
|
||||
Reference in New Issue
Block a user