DATAZAG
CROSS-ESTATE DOMAIN RISK REPORT
Cross-Estate Domain Risk Report · 2 July 2026
Acme Group9 declared domains · 3 segments · corp / retail / acquired

You declared 9 domains. Datazag's discovery walked certificate, mail and registration relationships across the 340M-domain corpus and found 15 more connected to Acme Group — 5 you almost certainly own, 4 to review, and 6 attackers would favour. Across the true estate, risk is systemic, not isolated: the weaknesses cluster in the acquired and retail segments, and one expired acquisition domain is a live takeover window today.

Estate discovered
9 → 24
15 undeclared domains found — 5 strongly associated, 4 to review, 6 defensive.
Estate grade
C · 47/100
Declared + strongly-associated. Two domains at E/F drag the whole estate.
Active exposure
9 in 30d
Impersonations targeting your platform stack — 100% concentrated on Microsoft 365.
Live lapses
2 overdue
oldco.com registration and certificate both expired — an open takeover window.
What a cyber insurer would note
An underwriter reading this estate would see the classic acquisition-integration gap: the corp segment holds a defensible C, while the acquired segment sits at median F with expired registrations and unenforced email controls. The exposure that matters is not any single domain — it is that 62% of the estate routes through one registrar and one mailbox provider, and the weakest domains still carry the group's name.
Scope: externally observable DNS, certificate, mail and registration evidence for 24 domains (9 declared, 15 discovered). No internal systems accessed. Snapshot 2 July 2026; discovery confidence tiers defined on the next page.
Datazag · datazag.com · intelligence@datazag.com
Prepared for Acme Group · Confidential · 1 / 6
DATAZAG
acme group · estate discovery
The estate you actually own.
Starting from your 9 declared domains, Datazag walked certificate SAN relationships, shared mail and DNS infrastructure, registration patterns and Companies House records to surface the rest.
Found
+15
9
Domains you declared — the list your teams hold today.
24
The estate Datazag can evidence. Every additional domain below carries the connection that surfaced it — a certificate, a mail route, a registration record — not a guess.

Everything found is sorted into the four confidence tiers you saw promised in the single-domain report — now populated with your domains and the evidence for each:

Declared · 9
The domains you told us about
Your starting list — graded and assessed throughout this report.
Strongly associated · 5
High-confidence: you own these
Shared certificate SANs, same MX + SPF, matching registrar patterns, redirects to your primary sites. Included in the estate grade.
Possible · 4
Medium-confidence: review these
Lexical brand similarity, shared infrastructure, historic links. Listed for confirmation — not graded until you claim them.
Defensive / acquisition · 6
Consider recovering or monitoring
Expired acquisition names, for-sale lookalikes, and the login/payroll/invoice patterns attackers favour.
DomainTierConnection evidence
acmegroup.co.ukStrongSame MX + SPF as acme.com · redirects to acme.com · same registrar account pattern
acme-payments.comStrongShares certificate SAN with acmeshop.com · same nameservers
acmecareers.comStrong301 redirect to acme.com/careers · GoDaddy account pattern match
oldco.ioStrongSubsidiary-name match (OldCo Ltd, CRN 0842…) · same registrant organisation as oldco.com
acme.devStrongShared Cloudflare NS pair with corp segment · TXT ownership token matches
acmegrp.comReviewLexical match · parked · historically resolved to AS13335 alongside corp estate
acme-events.netReviewCampaign-microsite pattern · registered same week as 2024 product launch · now parked
acme-logistics.comReviewShared hosting network with retail segment · no mail configured
theacmestore.comReviewHistoric redirect to acmeshop.com (2023, certificate-transparency evidence) · now lapsed to third party
oldco.netDefensiveExpired acquisition name — available for registration by anyone, including attackers
acmegroup.comDefensiveListed for sale on aftermarket · exact brand match
acmepayroll.comDefensiveUnregistered · payroll-lure pattern attackers favour against your staff
acme-invoices.netDefensiveUnregistered · invoice-fraud pattern targeting your suppliers
acme-portal.comDefensiveUnregistered · login-portal lure pattern
acrne.comDefensiveTypo-adjacent (rn→m homoglyph) · unregistered
Why the grade includes strongly-associated domains. A domain you own but forgot is still yours when it expires, gets hijacked, or serves malware under your name. The estate grade on the next pages therefore covers declared + strongly associated (14 domains). Possible-tier domains are listed for your confirmation; defensive-tier domains are recovery and monitoring candidates, not graded assets.
Estate discovery
Datazag · Confidential · 2 / 6
DATAZAG
acme group · systemic risk
Where the estate is single-threaded.
Concentration is the risk no single-domain report can see: if one provider falls, what share of Acme Group falls with it. Computed across the graded estate of 14 domains.
Estate grade
C
Estate grade
C
47.3 / 100 · 14 domains
Grade distribution — declared + strongly associated
A
2
B
2
C
4
D
3
E
1
F
2

Provider concentration across the estate. Each row reads: "if this provider suffers an outage or compromise, this share of Acme Group is affected at once." The share is the fact; the severity weighs who the provider is — a majority on a hyperscale platform with contingency depth is a different risk from the same share on a commodity provider that is slow to leave under duress. Discovery moved these numbers: shares are computed over the true estate, not the declared list. Mailbox shares are resolved through vanity MX records to the operating provider — a domain fronting Google Workspace behind its own MX counts as Google Workspace concentration.

Registrar
GoDaddy
64%was 62% pre-discovery
High
Commodity, high exit friction — reduce: migrate acquired zones to the corp registrar as re-platformed
Email / mailbox platform
Google Workspace
62%unchanged
Watch
Hyperscale — acceptable if deliberate: verify admin MFA and recovery paths
Certificate authority
Let's Encrypt
79%was 75% pre-discovery
Watch
Hyperscale, low exit friction — pin it deliberately with CAA (worksheet Fix 6)
Nameserver / DNS
Cloudflare
43%was 38% pre-discovery
Watch
Hyperscale — below the 50% floor; tier context only
Hosting network (ASN)
AS13335 Cloudflare
43%was 38% pre-discovery
Watch
Hyperscale — below the 50% floor; tier context only
How to read this. The biggest bar is not the biggest finding — Let's Encrypt at 79% is a Watch (leaving is a config change; pin it with CAA), while GoDaddy at 64% is the High (commodity registrar, days to exit under duress, transfers attacker-abusable). Concentration becomes an exposure when it is unplanned (accumulated through acquisitions), unlocked (no registrar locks, as on the oldco domains), or invisible (nobody knew the estate was this size until discovery). All three apply to the registrar position.

Posture variance by segment. The estate baseline is C — but the baseline is not the signal. The variance is: which parts of the group sit materially below the standard the rest maintains.

SegmentDomainsMedian gradevs baseline
corp6Cat baseline
retail4D−1 band
acquired4F−3 bandsOutlier
The classic integration gapThe acquired segment sits three grade bands below the group standard — expired registrations, no registrar locks, unenforced email controls. This is the standard post-acquisition pattern: the deal closed, the domains transferred, and nobody inherited operational ownership. It is also where discovery added the most: oldco.io (strongly associated) and oldco.net (expired, available to anyone) both belong to this segment and were not on the declared list.
Concentration & posture variance
Datazag · Confidential · 3 / 6
DATAZAG
acme group · systemic risk
What's wrong in the same way, everywhere.
A weakness on one domain is a ticket. The same weakness on 44% of the estate, clustered in two segments, is a policy gap — and it gets fixed at policy level, not ticket level.
Patterns
6
DMARC not enforced
Clustered in acquired, retail — corp segment is clean
44%6 / 14 domains
SPF not strict
Clustered in acquired
36%5 / 14 domains
DNSSEC not enabled
Clustered in acquired, retail
36%5 / 14 domains
CAA record missing
Clustered in acquired, retail
36%5 / 14 domains
Internal-IP leak in public DNS
Clustered in acquired, retail
21%3 / 14 domains
Dangling subdomain (takeover exposure)
Isolated to retail
7%1 / 14 domains
The segment clustering is the actionable finding. Every pattern above concentrates in acquired and retail — the corp segment meets baseline on all six controls. That means the fix is not fourteen tickets: it is one control standard applied to two segments, most efficiently at the point where those segments' DNS is administered.

Active exposure — what is already reaching toward the estate. Configuration weakness is potential; this is kinetic. Standing impersonation snapshot, exact-match confidence only:

9
active impersonations in the last 30 days — 100% targeting Microsoft 365 login journeys
external_threat.impersonations · confidence = "exact"
The concentration is the finding: attackers aren't choosing between your platforms — they have found the one your staff sign in to and are producing variations of it. Two of the nine reference the acquired OldCo brand, whose expired domain and lapsed certificate make impersonation cheapest.
Impersonating domainTargetFirst seenPattern
acme-m1cros0ft.comMicrosoft 36530d window · 4 certsHomoglyph + platform-name composite
acme365-login.comMicrosoft 36530d window · 3 certsBrand + platform login composite
0ldco-login.comMicrosoft 365 · OldCo brand30d window · 2 certsAcquired-brand lure against staff mid-migration
This report is the map — the feed is the tripwireA report shows the standing exposure at snapshot time. Certificates for pages like these are typically issued minutes before the phishing wave sends — detection that matters happens at issuance, not at the next report. Platform & Brand Impersonation Watch (page 6) delivers each of these as an event within seconds of the certificate appearing.
Correlated weakness & active exposure
Datazag · Confidential · 4 / 6
DATAZAG
acme group · exceptions
What to act on, in order.
The operational calendar is time-driven; the exception register is severity-driven. Together they are the estate's work queue — each correlated pattern appears once, not once per domain.
Overdue
2

Operational calendar. Expiries and lapses across all 24 domains — overdue items are live outages or open takeover windows, not future risk.

DomainSegmentItemDueDetail
oldco.comacquiredDomain registrationOverdueRegistration expired — renew or the name drops to open registration
oldco.comacquiredCertificateOverdueCertificate expired — any remaining service is throwing browser errors now
acmeshop.comretailCertificate12 daysRenewal not yet observed in certificate transparency
acmeretail.comretailDomain registration15 daysRegistration expires — confirm auto-renew at GoDaddy
oldco.comacquiredRegistrar lockStandingNo transfer/delete prohibition — hijack-transfer possible
oldco-portal.comacquiredRegistrar lockStandingNo transfer/delete prohibition — hijack-transfer possible

Exception register. Everything above and everything found earlier, ranked. Six exceptions, most severe first — the correlated-weakness patterns collapse into one entry because they share one fix.

1
oldco.com is expired and unlocked — an open takeover window on an acquired brand
High
Registration and certificate both lapsed, no registrar lock, and attackers are already producing OldCo-branded Microsoft 365 lures (0ldco-login.com). Recover the registration this week; oldco.net (also expired, found in discovery) should be re-registered defensively at the same time.
calendar.overdue × 2 · registrar_lock = none · external_threat.impersonations ∋ 0ldco-login.com
2
9 active Microsoft 365 impersonations across the estate in 30 days
High
100% concentration on the platform your staff sign in to daily. Standing snapshot only — issuance-time detection requires the live feed. Block the three named domains at your mail and web gateways today.
external_threat.impersonations · confidence = "exact" · 30d window
3
Registrar concentration: 64% on GoDaddy, unplanned and partially unlocked
High
The one concentration that warrants action rather than acknowledgement: a commodity registrar, high exit friction, accumulated through acquisitions, with locks absent on the acquired names. Lock everything now (worksheet Fix 1); migrate acquired zones to the corp registrar as they re-platform. The mailbox (62%, Google Workspace) and CA (79%, Let's Encrypt) positions are hyperscale — accept deliberately: verify admin MFA/recovery, and pin the CA with CAA (Fix 6).
registrar = .64 commodity/high-friction → HIGH · mailbox = .62 hyperscale → WATCH · ca = .79 hyperscale → WATCH
4
Six control gaps clustered in acquired + retail — one standard, two segments
Elevated
DMARC, SPF, DNSSEC, CAA, internal-IP hygiene and one dangling subdomain all cluster in the same two segments while corp meets baseline. Apply the corp DNS control standard to the acquired and retail zones — one change window, not fourteen tickets. The dangling subdomain (retail) is the only item needing immediate individual attention: it is claimable by a third party now.
correlated_weakness × 6 · segments = {acquired, retail} · corp = clean
5
4 possible-tier domains need an ownership decision
Elevated
acmegrp.com, acme-events.net, acme-logistics.com and theacmestore.com carry evidence linking them to the group. Confirm or disclaim each: confirmed domains join the graded estate; disclaimed ones move to the impersonation watchlist — theacmestore.com has already lapsed to a third party while still carrying redirect history to your retail site.
discovery.tier = possible × 4 · theacmestore.com registrant ≠ Acme since 2025-11
6
5 defensive registrations recommended
Watch
oldco.net, acmepayroll.com, acme-invoices.net, acme-portal.com and acrne.com are unregistered and match the lure patterns already in use against you. Registering them costs less per year than one incident-response hour; acmegroup.com (for sale) is a commercial decision worth pricing.
discovery.tier = defensive × 6 · patterns: payroll / invoice / portal / typo
How to executeEvery exception above maps to a worksheet entry in Appendix A — the remediation worksheet at the back of this report: exact records, per domain, grouped by the team that administers each zone. Hand it directly to whoever runs your DNS.
Calendar & exception register
Datazag · Confidential · 5 / 6
DATAZAG
acme group · what happens next
What a snapshot can't do.
This report is the map of your estate on 2 July 2026. Two things change without warning: attackers issue new certificates, and your estate keeps growing.
01
The certificates issued after this snapshot
Nine impersonations existed at snapshot time. The tenth will be issued minutes before it is used.

Every fake login page needs a certificate, and certificate issuance is public the moment it happens. Platform & Brand Impersonation Watch monitors issuance in real time against your platforms and brands — including the OldCo names attackers are already using — and delivers each match as an event to your SIEM, gateway or ticket queue within seconds.

Same graph, different tempo: this report and the feed read identical evidence. The report is quarterly governance; the feed is the tripwire between reports. Estates already under watch receive the three domains on page 4 as blocking events, not report findings.
02
The estate keeps growing without telling you
Discovery found 15 domains your teams didn't list. Next quarter there will be more.

Campaign microsites, acquisition names, regional registrations and shadow IT accumulate continuously. On a monitored estate, each report run re-walks discovery — new strongly-associated domains join the graded estate automatically, possible-tier candidates queue for your confirmation, and the grade trend line shows whether the integration work is landing.

Runs over time is the product: a single snapshot proves the gap; the quarterly series proves the remediation. The acquired segment moving from F to C over two quarters is the chart your board and your insurer both want.
Put the estate under watch.
Quarterly cross-estate reports with continuous discovery, plus real-time impersonation events to your stack — priced by estate band, from £500/month for founding partners.
Talk to Datazag →
Limits of this assessment
External evidence only. Everything here is observable from outside — DNS, certificate transparency, registration records, mail configuration. No internal system was accessed or scanned.
Discovery is evidence-bound. Domains appear only with a stated connection (SAN, mail route, registration, redirect, CRN). Absence from this report is not proof of absence from your estate.
Grades cover declared + strongly associated. Possible-tier domains are ungraded pending your confirmation; defensive-tier names are unregistered or third-party held and cannot be graded.
Impersonation counts are exact-match only. Confidence = "exact" against your platform and brand fingerprints. Lower-confidence typosquat candidates are tracked separately and excluded from headline figures.
Key terms: Certificate SAN — the list of domains sharing one certificate; a declared link between them. Concentration — the share of the estate depending on one provider. Posture variance — the grade spread between segments; the integration-gap signal. Defensive registration — buying a domain so an attacker can't.
Datazag · datazag.com · intelligence@datazag.com
Cross-Estate Domain Risk Report · 6 / 6
DATAZAG
acme group · appendix a · remediation worksheet
Appendix A — Remediation worksheet.
The report told you what's wrong; this is the sheet that fixes it. Exact records per domain, grouped by fix pattern and ordered by the account that administers each zone — hand it to the team that runs your DNS and work down the checkboxes.
Fixes
7

Three admin points cover the whole estate — each fix table is ordered so one team's work batches together into a single change window:

Admin point 1
Cloudflare · corp zones
6 domains · already at baseline on most controls
Admin point 2
GoDaddy · retail zones
4 domains · DMARC, CAA, DNSSEC work
Admin point 3
GoDaddy · acquired (OldCo)
4 domains · recovery first, then the full control set
1
Recover and lock the acquired names
Now
This is the open takeover window — do it before any DNS work. oldco.com's registration has lapsed; oldco.net (found in discovery) already dropped to open availability. Attackers are producing OldCo-branded lures now (0ldco-login.com, page 4). Renew, re-register, then set every registrar lock on all acquired names.
# at GoDaddy (acquired account) — registrar console, not DNS oldco.com renew registration immediately · enable auto-renew oldco.net re-register (currently available to anyone) all OldCo names set clientTransferProhibited + clientDeleteProhibited + clientUpdateProhibited
DomainAdmin pointNowAction
oldco.comGoDaddy · acquiredexpired · unlockedrenew + all locks + auto-renew
oldco.netGoDaddy · acquireddropped · availablere-register defensively + locks
oldco-portal.comGoDaddy · acquiredno locksall three client locks
oldco.ioGoDaddy · acquiredno locksall three client locks
2
Reclaim the dangling subdomain
Now
One retail subdomain CNAMEs to a deleted third-party resource — claimable by anyone right now, which turns your subdomain into their content. Remove the record or re-provision the target.
RecordAdmin pointNowFix
promo.acmeshop.comGoDaddy · retailCNAME → deleted azure resourcedelete record (or re-provision target first)
Appendix A · Remediation worksheet
Datazag · Confidential · A1 / A4
DATAZAG
acme group · appendix a · remediation worksheet
3
Remove internal endpoints from public DNS
Now
Hostnames resolving to private 10.x.x.x addresses in public DNS confirm internal network structure to an attacker. Remove the public records or move them to split-horizon (internal-only) resolution.
RecordAdmin pointNowFix
vpn.acmeretail.comGoDaddy · retailA 10.14.2.11remove — internal resolution only
intranet.acmeretail.comGoDaddy · retailA 10.14.2.40remove — internal resolution only
gw.oldco-portal.comGoDaddy · acquiredA 10.30.1.1remove — internal resolution only
4
Enforce DMARC across acquired and retail
Now
Staged, not straight to reject. A domain with no record starts at p=none with reporting to learn its senders; a domain already monitored moves to quarantine. End state for every domain is p=reject once reports confirm all legitimate senders — the corp zones are already there, so this is applying the group standard, not inventing one. Send all reports to one group inbox so the estate is monitored centrally.
# record template — _dmarc.<domain> TXT step 1 (no record today): "v=DMARC1; p=none; rua=mailto:dmarc@acme.com" step 2 (after ~4 weeks): "v=DMARC1; p=quarantine; rua=mailto:dmarc@acme.com" end state (group standard): "v=DMARC1; p=reject; rua=mailto:dmarc@acme.com"
DomainAdmin pointNowFix (next step)
acmeshop.comGoDaddy · retailp=none, no ruap=quarantine; rua=mailto:dmarc@acme.com
acmeretail.comGoDaddy · retail(no record)p=none; rua=mailto:dmarc@acme.com
oldco.comGoDaddy · acquired(no record)p=none; rua=mailto:dmarc@acme.com
oldco-portal.comGoDaddy · acquired(no record)p=none; rua=mailto:dmarc@acme.com
oldco.ioGoDaddy · acquiredp=none, no ruap=quarantine; rua=mailto:dmarc@acme.com
acme-payments.comCloudflare · corpp=none, no ruap=quarantine; rua=mailto:dmarc@acme.com
Appendix A · Remediation worksheet
Datazag · Confidential · A2 / A4
DATAZAG
acme group · appendix a · remediation worksheet
5
Tighten SPF to hard-fail
Now
Move from soft-fail (~all) to hard-fail (-all) once each domain's DMARC reports confirm all legitimate senders are listed — sequence this after Fix 4's reporting has run. Domains that send no mail at all get the null-sender record instead, which closes them to spoofing entirely.
# sending domains — after DMARC reports confirm senders "v=spf1 include:_spf.google.com -all" # non-sending domains — null SPF, closes the domain to spoofing "v=spf1 -all"
DomainAdmin pointNowFix
acmeshop.comGoDaddy · retail~all-all after DMARC report review
oldco.comGoDaddy · acquired~all-all after DMARC report review
oldco-portal.comGoDaddy · acquired(no SPF)"v=spf1 -all" — domain sends no mail
oldco.ioGoDaddy · acquired~all-all after DMARC report review
acmecareers.comCloudflare · corp(no SPF)"v=spf1 -all" — redirect-only domain
6
Publish CAA records
Soon
Advanced control — do after the Now items. CAA restricts which certificate authorities may issue for each domain, removing one route to a fraudulently-obtained certificate. It also converts the estate's 79% Let's Encrypt concentration from an accident into a pinned, deliberate choice (page 3, exception 3).
# record template — <domain> CAA <domain>. IN CAA 0 issue "letsencrypt.org" <domain>. IN CAA 0 iodef "mailto:security@acme.com"
DomainAdmin pointNowFix
acmeshop.comGoDaddy · retail(no CAA)issue "letsencrypt.org" + iodef
acmeretail.comGoDaddy · retail(no CAA)issue "letsencrypt.org" + iodef
oldco.comGoDaddy · acquired(no CAA)issue "letsencrypt.org" + iodef
oldco-portal.comGoDaddy · acquired(no CAA)issue "letsencrypt.org" + iodef
oldco.ioGoDaddy · acquired(no CAA)issue "digicert.com" + iodef — this zone uses DigiCert
Appendix A · Remediation worksheet
Datazag · Confidential · A3 / A4
DATAZAG
acme group · appendix a · remediation worksheet
7
Enable DNSSEC
Maturity
Gold-standard control — plan it, don't alarm over it. DNSSEC cryptographically signs DNS responses; its absence is normal across most estates and creates no exploitable risk today. Enable at the registrar/zone host and publish DS records — the corp Cloudflare zones make this a toggle; GoDaddy zones need DS records published manually.
DomainAdmin pointNowFix
acmeshop.comGoDaddy · retailunsignedenable at zone host · publish DS
acmeretail.comGoDaddy · retailunsignedenable at zone host · publish DS
oldco.comGoDaddy · acquiredunsignedenable at zone host · publish DS
oldco-portal.comGoDaddy · acquiredunsignedenable at zone host · publish DS
oldco.ioGoDaddy · acquiredunsignedenable at zone host · publish DS

Worksheet terms — for the person executing, not the person who bought the report:

DMARC
Tells receiving mail servers what to do with unauthenticated mail claiming to be from you: none (monitor), quarantine (spam folder), reject (refuse).
SPF
Lists which mail servers may send email as your domain. ~all suggests rejection; -all demands it. "v=spf1 -all" closes a non-sending domain entirely.
CAA
Restricts which certificate authorities may issue SSL/TLS certificates for your domain. iodef sets where violation reports go.
DNSSEC / DS record
Cryptographically signs DNS responses so they can't be tampered with in transit. The DS record at the registry links your signed zone into the chain of trust.
Registrar locks
clientTransferProhibited / clientDeleteProhibited / clientUpdateProhibited — registrar-side switches preventing a domain being moved or destroyed without authorisation.
Dangling CNAME
A subdomain pointing at a deleted third-party resource. Anyone can claim the abandoned resource and serve their content from your name.
Split-horizon DNS
Serving different answers internally and externally — internal hostnames resolve on your network but do not appear in public DNS.
rua reporting
The DMARC aggregate-report address. Reports reveal every source sending as your domain — the evidence for safely moving to quarantine, then reject.
VerificationEach completed fix is externally observable — Datazag's next report run (or the live feed, if the estate is under watch) confirms the change independently, which is the evidence trail your insurer or auditor wants. Sequence: Fix 1 today · Fixes 2–3 this week · Fix 4 staged over ~8 weeks · Fix 5 follows 4 · Fixes 6–7 in the next planned change window.
Appendix A · Remediation worksheet
Datazag · Confidential · A4 / A4