Glossary

The acronyms behind your findings

Every trust signal SkyQon checks, defined in plain language: what it is, which standard defines it, and the way it actually breaks in production. One page per term.

Written by the SkyQon engineering team · Last verified 4 August 2026

Email authentication

  • DKIMDomainKeys Identified Mail — a cryptographic signature proving a message was not altered in transit.
  • DMARCTells inboxes what to do with mail that fails SPF or DKIM, and where to send reports.
  • MTA-STSForces inbound mail to your domain over authenticated, encrypted TLS.
  • SPFSender Policy Framework — lists which servers may send mail for your domain.
  • TLS-RPTDelivers reports when TLS delivery to your mail servers fails.

DNS

  • CAAA DNS record naming the certificate authorities allowed to issue certificates for your domain.
  • DNSSECSigns your DNS records so resolvers can detect forged or tampered answers.

Certificates & TLS

  • Certificate TransparencyCertificate Transparency — public logs of every certificate issued, used to spot lookalikes and mis-issuance.
  • OCSPOnline Certificate Status Protocol — a live check of whether a certificate has been revoked.
  • OV / EV certificatesOrganisation- and Extended-Validation certificates that bind a verified legal identity to a domain.

Identity & cryptography

  • Post-quantum cryptographyPost-Quantum Cryptography — algorithms designed to resist attacks from quantum computers.
  • QWACQualified Website Authentication Certificate — an eIDAS-qualified certificate proving website identity in the EU.