Every connection starts with a DNS query. Attackers have known this for years. Most defenders still haven't acted.

DNS-based attacks account for 88% of all malware command-and-control activity. You are watching the wrong protocol. What DNS does: The Domain Name System translates human-readable names into IP addresses. Every device, every application, every connection begins with DNS. It is the phonebook of the internet — and it was designed with zero security.

How attackers weaponize DNS

  • DNS TUNNELING Malware encodes command-and-control traffic inside DNS queries and responses. Firewalls allow DNS unconditionally. Data exfiltrates through port 53 while perimeter controls see nothing but routine lookups.
  • DNS FAST FLUX Botnets rotate thousands of IP addresses behind a single domain within seconds. Traditional IP blocklists become useless. Infrastructure stays untraceable. Takedowns consistently fail.
  • DNS CACHE POISONING Corrupted resolver caches silently redirect users to attacker infrastructure. Banking portals. VPN login pages. Authentication systems. Users see a legitimate URL and trust it completely.
  • DANGLING DNS Abandoned records still pointing to decommissioned resources. Attackers register the expired asset. Instant subdomain takeover. Phishing campaigns launch under your brand with zero system access required.
  • NXDOMAIN HARVESTING Mass queries for non-existent domains map internal naming conventions, enumerate active hosts, and fingerprint your environment — all before the intrusion formally begins.

Real consequences: In 2025, a DNS tunneling campaign exfiltrated 40 GB of financial records from a European bank over six months. Every packet was DNS. Every packet passed the firewall unchallenged. No DNS monitoring existed. Discovery came during a compliance audit — months after initial compromise.

How to defend

DNS OVER HTTPS/TLS — Encrypt all resolution queries. Eliminate passive interception of DNS traffic at the network layer.

PROTECTIVE DNS — Route queries through real-time threat intelligence. Block malicious domains before connections are ever established.

DNS MONITORING — Establish query volume baselines per host. High query rates, unusual TXT requests, and high-entropy domain names are active attack signals.

DNSSEC — Cryptographically sign your zone data. Prevent cache poisoning at the authoritative level. Validate signatures at every resolver.

INTERNAL HYGIENE — Audit and decommission stale DNS records every quarter. Automate record lifecycle management to eliminate dangling exposure permanently.

DNS is not a security control. It was never designed to be. But it is a surveillance and enforcement point most organizations are not using.

Does your organization monitor DNS traffic for behavioral anomalies? When did you last audit your external zones for dangling records?
Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.