ClaraWideProvider DNS egress guard QA
v0.12.35 · DNS + PRIVATE-NETWORK EGRESS GUARD

Trust the approved hostname. Verify where it actually resolves.

This layer classifies DNS answers immediately before the future provider network adapter. Public addresses may proceed to the next gate; loopback, private, carrier-NAT, link-local, metadata, documentation, multicast, reserved and local IPv6 space are blocked. A changed answer set between materialization and pre-dispatch verification is treated as possible rebinding/drift and stopped.

SCHEMA + ATTACK PATHS

Automated DNS checks

Confirms schema v34, IPv4/IPv6 classification, mixed-answer blocking, IP-literal rejection, stable pre-dispatch verification, drift/rebinding defense and immutable DNS evidence.

NOT RUNSchema check has not run yet.
NOT RUNSelf-test has not run yet.
VISIBLE SECURITY FLOW

Resolve safely, then attack the resolver boundary

READYStart with a QA DNS Admin session.
QA DNS policyLoad DNS state to inspect public-address and stability rules.
RESOLUTION EVIDENCE

Public vs blocked answers

No DNS resolutions loaded yet.

IMMUTABLE EVIDENCE

DNS guard history

No DNS events loaded yet.

PRODUCTION GATE — DO NOT FAKE

Real resolver + rebinding evidence

Leave these open until a reviewed production DNS-resolution strategy exists for the selected provider, public-only address enforcement is demonstrated against real infrastructure, monitoring is connected, and public QA endpoints are disabled.

Recent DNS QA runs

No QA runs recorded yet.

Evidence tools

Clearing browser evidence never rewrites server-owned DNS resolution or event records.