Check: resolver configuration, A/AAAA/CNAME records, TTL, split DNS and authoritative responses.
Evidence: query result, resolver, timestamp and affected scope.
Four compact diagnostic playbooks for the infrastructure dependencies behind many enterprise incidents.
Check: resolver configuration, A/AAAA/CNAME records, TTL, split DNS and authoritative responses.
Evidence: query result, resolver, timestamp and affected scope.
Check: destination name, certificate chain, expiry, SNI, protocol/cipher compatibility and interception.
Evidence: certificate details, handshake error and endpoint time.
Check: MX resolution, connection, SMTP response, authentication, egress identity and reputation.
Evidence: message ID, UTC timestamp, response code and observed public IP.
Check: service state, recent logs, listening socket, disk/memory, permissions and dependencies.
Evidence: exact error, service status, log timestamp and configuration change.
Capture evidence before remediation. Make one controlled change at a time, then repeat the original test. This preserves causality and makes escalation materially easier.