Every connection starts with a DNS query. Attackers have known this for years. Most defenders still haven't acted.

DNS-based attacks account for 88% of all malware command-and-control activity.
You are watching the wrong protocol.
What DNS does: The Domain Name System translates human-readable names into IP addresses. Every device, every application, every connection begins with DNS. It is the phonebook of the internet — and it was designed with zero security.
How attackers weaponize DNS
- DNS TUNNELING Malware encodes command-and-control traffic inside DNS queries and responses. Firewalls allow DNS unconditionally. Data exfiltrates through port 53 while perimeter controls see nothing but routine lookups.
- DNS FAST FLUX Botnets rotate thousands of IP addresses behind a single domain within seconds. Traditional IP blocklists become useless. Infrastructure stays untraceable. Takedowns consistently fail.
- DNS CACHE POISONING Corrupted resolver caches silently redirect users to attacker infrastructure. Banking portals. VPN login pages. Authentication systems. Users see a legitimate URL and trust it completely.
- DANGLING DNS Abandoned records still pointing to decommissioned resources. Attackers register the expired asset. Instant subdomain takeover. Phishing campaigns launch under your brand with zero system access required.
- NXDOMAIN HARVESTING Mass queries for non-existent domains map internal naming conventions, enumerate active hosts, and fingerprint your environment — all before the intrusion formally begins.
Real consequences: In 2025, a DNS tunneling campaign exfiltrated 40 GB of financial records from a European bank over six months. Every packet was DNS. Every packet passed the firewall unchallenged. No DNS monitoring existed. Discovery came during a compliance audit — months after initial compromise.
How to defend
DNS OVER HTTPS/TLS — Encrypt all resolution queries. Eliminate passive interception of DNS traffic at the network layer.
PROTECTIVE DNS — Route queries through real-time threat intelligence. Block malicious domains before connections are ever established.
DNS MONITORING — Establish query volume baselines per host. High query rates, unusual TXT requests, and high-entropy domain names are active attack signals.
DNSSEC — Cryptographically sign your zone data. Prevent cache poisoning at the authoritative level. Validate signatures at every resolver.
INTERNAL HYGIENE — Audit and decommission stale DNS records every quarter. Automate record lifecycle management to eliminate dangling exposure permanently.
DNS is not a security control. It was never designed to be. But it is a surveillance and enforcement point most organizations are not using.
Does your organization monitor DNS traffic for behavioral anomalies? When did you last audit your external zones for dangling records?