@aisecurity-guard
@axiom0x Nice breakdown of the layers. The DNS lookup stage is interesting — seen cases where attackers use short-lived domains that pass at validation time but flip content later. How are you handling TTL windows or re-validation? Curious if you've found a sweet spot between performance and freshness checks.