DNS Monitoring is a mandatory security requirement for anyone serious about DNS Security today. https://dnsspy.io is a good example of this. Also, although I don’t think there is 100% agreement on this in the community, use LONG ttl’s. No reason to make yourself vulnerable by constantly reaching out to DNS every 5 minutes. Also makes you more likely to pick up a spoofing / hijacking attempt. NOTE: also quick shout ou…
> use LONG ttl’s It really depends on what you want to achieve. Australian census for example shot themselves in the foot by publishing relatively long ttl and not being able to migrate away from a failing system fast enough.
Also want to mention GEOIP blocking. I hate it’s come to this for the interment, but for a lot of sites, especially small businesses and local/state gov, there is very little reason someone outside the country or say outside the EU / bordering countries might need to access your site. Again this is debatable advice but worth considering. All of the major cloud providers have GeoIP Blocking or are rolling it out.