Forrester Total Economic Impact™ study finds Edwin AI delivered a 313% ROI for composite organization.

Read more

Partners

Docs

LM Academy

LM Community

Platform

Solutions

Pricing

Resources

Company

Platform
  • Infrastructure
  • Cloud & Multi-Cloud
  • Log Management
  • Edwin AI
Solution
  • Automation
  • Tool Consolidation
  • Reduce MTTR
  • Cost Optimization
Industry
  • Healthcare
  • Financial Services
  • Public Sector
  • MSP
Role
  • CIO
  • ITOps
  • CloudOps
  • AIOps
There is no result.
Try it free

14-day access to the full LogicMonitor platform

Explore Platform

One platform, one system for observability, intelligence, and action.

Agentic AIOps

Infrastructure Observability

Cloud Observability

Internet Performance Monitoring

Digital Experience Monitoring

Log Management

Agentic AIOps Overview

Autonomously detect, diagnose, and resolve issues across your environment.

Meet Edwin AI

Turn fragmented cross-domain event noise into explainable, guided action.

AI Agent

Deploy specialized AI agents to handle investigation across the incident lifecycle.

Event Intelligence

Compress raw alert storms into high-fidelity, prioritized insights.

AI Automation

Execute governed, closed-loop remediation across automation playbooks.

ITOps Context Graph

NEW

Unify topology, telemetry, and changes into an AI-ready context layer.

MCP

NEW

Establish traceable, secure governance boundaries for AI tool integrations.

Infrastructure Observability Overview

Full visibility across your entire hybrid estate to eliminate tool sprawl.

Network Monitoring

Accelerate time to innocence with deep network path and device visibility.

Server Monitoring

Track server health, OS metrics, and resource utilization across environments.

Remote Monitoring

Monitor distributed endpoints, branch networks, and remote facility health.

VM Monitoring

Maximize hypervisor performance and streamline compute capacity planning.

SD-WAN Monitoring

Keep multi-site cloud networks connected with real-time edge visibility.

Database Monitoring

Pinpoint database query bottlenecks to keep business applications fast.

Configuration Monitoring

Minimize change failure rates by tracking device configuration drift.

Storage Monitoring

Track SAN/NAS arrays, IOPS bottlenecks, and storage capacity trends.

Cloud Observability Overview

Multi-cloud and hybrid environments unified into a single operational pane.

Container Monitoring

Automated, real-time visibility for Kubernetes and ephemeral microservices.

AWS Monitoring

Track AWS services, scaling, and costs alongside on-premises data.

Google Cloud Monitoring

Monitor native GCP infrastructure, compute, and serverless resources.

Azure Monitoring

Comprehensive visibility into Azure environments, gateways, and workloads.

AI Monitoring

Track LLM infrastructure, GPU utilization, and AI application stack health.

Oracle Cloud Monitoring

Track OCI native compute, enterprise databases, and cloud storage.

SaaS Monitoring

Validate availability and workforce productivity for critical SaaS apps.

Internet Performance Monitoring Overview

Understand performance across the full stack wherever users depend on it.

Internet Health

NEW

Use global vantage points to independently validate internet outages.

Real User Monitoring

NEW

Capture actual customer journeys and frontend performance in real time.

Synthetic Monitoring

NEW

Emulate user transactions and SaaS workflows to catch problems early.

Endpoint Monitoring

NEW

Diagnose remote workforce digital experience across devices and networks.

Digital Experience Monitoring

See every dependency, regardless of ownership or location.

Website Monitoring

Protect revenue journeys with proactive synthetic checks and uptime tracking.

CDN Monitoring

NEW

Audit edge performance and latency variance across your CDN providers.

API Monitoring

NEW

Test endpoints and third-party API reliability for critical app integrations.

Application Performance Monitoring

Connect code execution and traces directly to infrastructure health.

DNS Monitoring

NEW

Speed up time-to-innocence by tracking global nameserver resolution times.

DevOps Lifecycle Monitoring

NEW

Protect release velocity by validating dependencies during deployments.

BGP Monitoring

NEW

Trace global routing changes and path leaks to secure internet reachability.

Log Management Overview

Centralize and correlate log data to resolve incidents before they escalate.

Log Analytics & Intelligence

Correlate contextual log data with metrics to speed up root-cause analysis.

3,000+ Integrations

Quickly deploy and manage 3,000+ collector-based and API-friendly integrations.

Learn more
Explore Solutions

Proactively manage modern hybrid environments with predictive insights, intelligent automation, and full-stack observability.

By Business Outcome

By Role

By Industry

Professional Services

Autonomous IT

Predictive, autonomous IT built

for resilience.

Automation

Eliminate operational toil with safe, policy-governed remediation workflows.

Modernization and Transformation

Accelerate complex technology transitions while protecting core enterprise resilience.

Cloud Migration

Maintain workload performance throughout migration.

Tool Consolidation

Reduce licensing costs and silos by replacing fragmented monitoring tools.

Cost Optimization

Lower your total cost-to-serve by finding cloud waste and underused resources.

Operational Efficiency

Maximize team capacity by reducing alert storms and shift-handoff friction.

Reduce MTTR

Shorten war-rooms by surfacing topology-aware probable cause in mins.

Network Reachability

NEW

Independently audit external BGP, ISP, and SaaS provider connectivity boundaries.

Edge Deployment Optimization

NEW

Monitor SLOs, compare providers, and validate cloud and edge delivery.

Web Performance Optimization

NEW

Maximize digital checkout conversions by tracking global frontend latency metrics.

Application Resilience

NEW

Safeguard business services against transaction failures and costly downtime.

Workforce Productivity

NEW

Troubleshoot remote hardware and network issues to protect productivity.

CIO

Maximize enterprise resilience and align AI investments to measurable business ROI.

AIOps

Compress cross-domain event noise into explainable, automated ops leverage.

DevOps

Speed up releases by protecting engineering roadmaps from toil.

ITOps

Standardize incident response to reduce alert fatigue and after-hours work.

CloudOps

Unify multi-cloud visibility to optimize costs and track hybrid blast radius.

Healthcare

Protect continuity of care and EHR availability across clinical workflows.

Public Sector

Ensure mission continuity and audit readiness for citizen-facing services.

MSP

Protect service margins and scale ops using multi-tenant, AI-assisted triage.

Retail & E-commerce

Safeguard peak retail campaigns, POS uptime, and digital customer journeys.

Technology

Protect customer trust and engineering velocity with SLA-driven visibility.

Hospitality

Deliver frictionless guest experiences and keep booking engines online.

Education

Maintain always-on student portals, learning platforms, and campus networks.

Manufacturing

Prevent production downtime by unifying IT, OT-adjacent, and edge systems.

Financial Services

Secure transaction trust and meet strict resilience compliance requirements.

Why LogicMonitor?

Discover why leading IT teams trust us to unify hybrid observability and eliminate tool sprawl.

Learn more
Explore Resources

Check out our resource library for IT pros, featuring expert guides, strategies, and insights for smarter, AI-driven operations.

Resources

Upcoming Events

Platform Help

Blog

Insights and advice from the experts on all things observability and AI.

Case Studies

See what real users have to say about the LogicMonitor platform.

Webinars

Live and on-demand learning, all in one place.

IT Guides

Learn from expert guides on the topics that matter most to IT teams.

How We Compare

See how our platform stacks up against other solutions.

Viee of a bridge over a river leading to Cologne cathedral rising against the skyline and a blue sky
CONFERENCE

Digital X Cologne

September 8, 2026

Cologne

CONFERENCE

SWORD Day

September 17, 2026

Geneva

View all events

Join us at innovation-focused conferences, tech talks, webinars, and other events.

Support Docs

Access product docs, release notes, and support resources.

LM Community

Join the community to learn from peers, ask questions, and connect with experts.

Customer Education

Learn more about our platform through resources and live trainings.

2026 The Year of Autonomous IT

NEW

Discover the trends, benchmarks, and strategies driving the industry shift to Autonomous IT.

Read the report
About LogicMonitor

Our observability platform proactively delivers the insights and automation CIOs need to accelerate innovation.

Leadership

Meet the leaders building the future of observability and AI.

Our Customers

See the proof of how IT teams win with LogicMonitor.

Careers

Find job openings and learn about our employee benefits.

Newsroom

Stay current with our latest mentions, press releases, and events.

Culture

NEW

Join a collaborative, values-driven culture built on innovation and growth.

Security

Purpose-built security for the hybrid observability and AI era.

Contact & Locations

Connect with our experts to explore AI-powered observability solutions.

Sustainability

Our commitment to the environment and the people in it.

Forrester Total Economic Impact™ study finds Edwin AI delivered a 313% ROI for composite organization.

Read more
Try it free

Platform

Explore Platform

One platform, one system for observability, intelligence, and action.

Agentic AIOps

Infrastructure Observability

Cloud Observability

Internet Performance Monitoring

Digital Experience Monitoring

Log Management

3,000+ Integrations

Quickly deploy and manage 3,000+ collector-based and API-friendly integrations.

Solutions

Explore Solutions

Proactively manage modern hybrid environments with predictive insights, intelligent automation, and full-stack observability.

By Business Outcome

By Role

By Industry

Professional Services

Why LogicMonitor?

Discover why leading IT teams trust us to unify hybrid observability and eliminate tool sprawl.

Pricing

Resources

Explore Resources

Check out our resource library for IT pros, featuring expert guides, strategies, and insights for smarter, AI-driven operations.

Resources

Upcoming Events

Platform Help

NEW

2026 The Year of Autonomous IT

Discover the trends, benchmarks, and strategies driving the industry shift to Autonomous IT.

Company

About LogicMonitor

Our observability platform proactively delivers the insights and automation CIOs need to accelerate innovation.

Leadership

Meet the leaders building the future of observability and AI.

Careers

Find job openings and learn about our employee benefits.

Culture

NEW

Join a collaborative, values-driven culture built on innovation and growth.

Contact & Locations

Connect with our experts to explore AI-powered observability solutions.

Our Customers

See the proof of how IT teams win with LogicMonitor.

Newsroom

Stay current with our latest mentions, press releases, and events.

Security

Purpose-built security for the hybrid observability and AI era.

Sustainability

Our commitment to the environment and the people in it.

Partners

Docs

LM Academy

LM Community

Agentic AIOps

Agentic AIOps Overview

Autonomously detect, diagnose, and resolve issues across your environment.

Meet Edwin AI

Turn fragmented cross-domain event noise into explainable, guided action.

AI Agent

Deploy specialized AI agents to handle investigation across the incident lifecycle.

Event Intelligence

Compress raw alert storms into high-fidelity, prioritized insights.

AI Automation

Execute governed, closed-loop remediation across automation playbooks.

ITOps Context Graph

NEW

Unify topology, telemetry, and changes into an AI-ready context layer.

MCP

NEW

Establish traceable, secure governance boundaries for AI tool integrations.

Infrastructure Observability

Infrastructure Observability Overview

Full visibility across your entire hybrid estate to eliminate tool sprawl.

Network Monitoring

Accelerate time to innocence with deep network path and device visibility.

Server Monitoring

Track server health, OS metrics, and resource utilization across environments.

Remote Monitoring

Monitor distributed endpoints, branch networks, and remote facility health.

VM Monitoring

Maximize hypervisor performance and streamline compute capacity planning.

SD-WAN Monitoring

Keep multi-site cloud networks connected with real-time edge visibility.

Database Monitoring

Pinpoint database query bottlenecks to keep business applications fast.

Configuration Monitoring

Minimize change failure rates by tracking device configuration drift.

Storage Monitoring

Track SAN/NAS arrays, IOPS bottlenecks, and storage capacity trends.

Cloud Observability

Cloud Observability Overview

Multi-cloud and hybrid environments unified into a single operational pane.

Container Monitoring

Automated, real-time visibility for Kubernetes and ephemeral microservices.

AWS Monitoring

Track AWS services, scaling, and costs alongside on-premises data.

Google Cloud Monitoring

Monitor native GCP infrastructure, compute, and serverless resources.

Azure Monitoring

Comprehensive visibility into Azure environments, gateways, and workloads.

AI Monitoring

Track LLM infrastructure, GPU utilization, and AI application stack health.

Oracle Cloud Monitoring

Track OCI native compute, enterprise databases, and cloud storage.

SaaS Monitoring

Validate availability and workforce productivity for critical SaaS apps.

Internet Performance Monitoring

Internet Performance Monitoring Overview

Understand performance across the full stack wherever users depend on it.

Internet Health

NEW

Use global vantage points for independent validation of internet outages.

Real User Monitoring

NEW

Capture actual customer journeys and frontend performance in real time.

Synthetic Monitoring

NEW

Emulate user transactions and SaaS workflows to catch problems early.

Endpoint Monitoring

NEW

Diagnose remote workforce digital experience across devices and networks.

Digital Experience Monitoring

Digital Experience Monitoring

See every dependency, regardless of ownership or location.

Website Monitoring

Protect revenue journeys with proactive synthetic checks and uptime tracking.

CDN Monitoring

NEW

Audit edge performance and latency variance across your CDN providers.

API Monitoring

NEW

Test endpoints and third-party API reliability for critical app integrations.

Application Performance Monitoring

Connect code execution and traces directly to infrastructure health.

DNS Monitoring

NEW

Speed up time to innocence by tracking global nameserver resolution times.

DevOps Lifecycle Monitoring

NEW

Protect release velocity by validating dependencies during deployments.

BGP Monitoring

NEW

Trace global routing changes and path leaks to secure internet reachability.

Logs

Log Management Overview

Centralize and correlate log data to resolve incidents before they escalate.

Log Analytics & Intelligence

Correlate contextual log data with metrics to speed up root-cause analysis.

By Business Outcome

Autonomous IT

Predictive, autonomous IT built for resilience.

Automation

Eliminate repetitive operational toil with safe, policy-governed remediation workflows.

Modernization and Transformation

Accelerate complex technology transitions while protecting core enterprise resilience.

Cloud Migration

Maintain workload performance throughout migration.

Tool Consolidation

Reduce licensing costs and data silos by replacing fragmented monitoring tools.

Cost Optimization

Lower your total cost-to-serve by finding cloud waste and underused resources.

Operational Efficiency

Maximize team capacity by reducing alert storms and shift-handoff friction.

Reduce MTTR

Shorten war-room by surfacing topology-aware probable cause in mins.

Network Reachability

NEW

Independently audit external BGP, ISP, and SaaS provider connectivity boundaries.

Edge Deployment Optimization

NEW

Monitor SLOs, compare providers, and validate cloud and edge delivery.

Web Performance Optimization

NEW

Maximize digital checkout conversions by tracking global frontend latency metrics.

Application Resilience

NEW

Safeguard business services against transaction failures and costly downtime.

Workforce Productivity

NEW

Troubleshoot remote hardware and network issues to protect productivity.

By Role

CIO

Maximize enterprise resilience and align AI investments to measurable business ROI.

AIOps

Compress cross-domain event noise into explainable, automated ops leverage.

DevOps

Speed up releases by protecting engineering roadmaps from toil.

ITOps

Standardize incident response to reduce alert fatigue and after-hours work.

CloudOps

Unify multi-cloud visibility to optimize costs and track hybrid blast radius.

By Industry

Healthcare

Protect continuity of care and EHR availability across clinical workflows.

Public Sector

Ensure mission continuity and audit readiness for citizen-facing services.

MSP

Protect service margins and scale ops using multi-tenant, AI-assisted triage.

Retail & E-commerce

Safeguard peak retail campaigns, POS uptime, and digital customer journeys.

Technology

Protect customer trust and engineering velocity with SLA-driven visibility.

Hospitality

Deliver frictionless guest experiences and keep booking engines online.

Education

Maintain always-on student portals, learning platforms, and campus networks.

Manufacturing

Prevent production downtime by unifying IT, OT-adjacent, and edge systems.

Financial Services

Secure transaction trust and meet strict operational resilience compliance requirements.

Resources

Blog

Insights and advice from the experts on all things observability and AI.

Case Studies

See what real users have to say about the LogicMonitor platform.

Webinars

Live and on-demand learning, all in one place.

IT Guides

Learn from expert guides on the topics that matter most to IT teams.

How We Compare

See how our platform stacks up against other solutions.

Upcoming Events

Viee of a bridge over a river leading to Cologne cathedral rising against the skyline and a blue sky

CONFERENCE

Digital X Cologne

September 8, 2026

CONFERENCE

SWORD Day

September 17, 2026

View all events

Join us at innovation-focused conferences, tech talks, webinars, and other events.

Platform Help

Support Docs

Access product docs, release notes, and support resources.

LM Community

Join the community to learn from peers, ask questions, and connect with experts.

Customer Education

Learn more about our platform through resources and live trainings.

DNS MONITORING

DNS Attacks: Tutorial & Prevention Best Practices

DNS is critical infrastructure — and a high-value target. Cache poisoning, tunneling, floods, and hijacking each exploit different weaknesses. Here’s how each works and how to defend against them.

11–16 minutes
June 3, 2026
Denton Chikura

IN THIS DEEP DIVE

CHAPTERS

    NEWSLETTER

    Subscribe to our newsletter

    Get the latest blogs, whitepapers, eGuides, and more straight into your inbox.

    SHARE

    The quick download:

    DNS attacks exploit the protocol’s open trust model to intercept traffic, steal data, and take down services — and because DNS sits beneath every internet communication, a successful attack can affect everything at once.

    • DNS cache poisoning corrupts resolver caches with false records, silently redirecting users to attacker-controlled resources without touching authoritative DNS servers.

    • DNS tunneling hides non-DNS data inside DNS query and response traffic, giving attackers a covert channel to exfiltrate data or command botnets through firewalls that pass DNS freely.

    • DNS floods are DDoS attacks against DNS servers; DNS hijacking compromises authoritative DNS directly — both can take down services for everyone using the affected infrastructure.

    • Effective DNS security requires multiple layers: DNSSEC for record validation, rate limiting for flood protection, monitoring for anomaly detection, and regular security audits of DNS configurations.

    DNS is truly the unsung hero of the internet: Without it, we would be lost in a numeric soup of IP addresses. And when something goes wrong in the network, what do we blame first? That’s right: DNS. 

    So, if DNS is so important, why does no one ever discuss securing it? 

    DNS attacks are malicious campaigns directed at DNS weaknesses with the intent of capturing data or causing disruption to internal and external resources. Some important categories of DNS attacks include DNS poisoning, DNS tunneling, DNS floods, and DNS hijacking.

    This article will examine some of the more common ways that your DNS system may be in danger, how to lock it down, and how to identify and mitigate issues while securing DNS from attack.

    Summary of DNS attacks

    The following is a summary of the most important DNS attacks.

    DNS cache poisoningDNS cache poisoning occurs when a threat actor successfully corrupts the records that are kept in cache on a DNS server.
    DNS tunnelingDNS tunneling is the action of moving the data from a  corrupted machine out of the network by hiding data in DNS traffic.
    DNS floodIn a DNS flood, the attacker uses infected hosts or bots to take down DNS servers.
    DNS hijackingDNS hijacking occurs when an authoritative server is compromised and the threat actors gain access to change public A records.

    The impact of a DNS attack

    A DNS attack will impact the entire company structure, typically affecting most users and resources, if not all. The image below shows the extent of the impact reported by 1,080 companies surveyed for the IDC 2022 Global DNS Threat Report. DNS attacks can lead to private company data being exposed as well as information relating to customers, employees, and third-party vendors. A DNS attack can literally destroy a business from the inside out.

    Types of DNS attacks

    DNS attacks come in several forms, usually as a combination attack where DNS is affected alongside other services. Here are some common attacks and significant examples.

    DNS cache poisoning

    DNS cache poisoning occurs when a threat actor successfully corrupts the records that are kept in cache on a DNS Server. This can be done through various methods, including man-in-the-middle (MITM) attacks, spoofing IP addresses to look like another DNS server, and direct manipulation of records inside a DNS server. The diagram below shows a framework for such an attack.

    This is an example of a possible internal DNS attack. First, the threat actor (TA) will initiate a man-in-the-middle attack (MITM), which involves the TA placing a device they own or control between two other devices in a network that are having a conversation. Next, the TA will attempt to poison the ARP cache of any devices looking for the MAC address that belongs to the DNS / DHCP / default gateway router or server. The TA’s device responds to the ARP requests with its MAC address, impersonating the router/server, and starts serving DHCP requests. Inside the DHCP requests is the IP of the TA’s DNS server. This server then begins handing out falsified DNS records. 

    DNS tunneling

    In the example above, the attacker has managed to poison DNS, but how can this be exploited?

    The attacker will start with a web server, somewhere out on the Internet, that they own. Traffic will be redirected from the intended target IP to their web server IP via the poisoned DNS server, and malware will be installed on the host. Once the malware is installed, data can be extracted from the corrupted host. This moving of data from the corrupted machine out of the network by hiding data in DNS traffic is called DNS tunneling.One potential issue with tunneling is that most corporate and small business environments normally have a firewall. Luckily for our attacker, though, none of these firewalls will typically inspect DNS queries. DNS query inspection can reduce processing performance because every device makes many queries rapidly. (You can read more on the effects of deep packet inspection here). Armed with this knowledge, our attacker starts to hide the data payload inside the DNS query! The queries will move through the firewall to the attacker’s web server and deliver the stolen data. Below is a simplified diagram of how this would work.

    In 2017, Unit42 identified a string of DNS tunneling attacks from the threat group OilRig, most of which targeted financial institutions and government installations in the Middle East. These particular attacks began with a phishing scam designed to infect a host on the target network. An Excel document containing an “incompatible worksheet” was sent through email to the target, who was asked to enable content, and then a macro was run in the background. This macro would concatenate the worksheet to create a .HTA file that would be run in the background with mshta.exe (which executes HTML files), installing a backdoor trojan. 

    When the trojan captured data, it would respond to DNS queries created with random values from various subdomains (to avoid cached responses) and create responses with start/stop delimiters represented by specific IP addresses. This would completely disguise the payload in a way that no firewall would detect it. Other variations of the attack showed DNS queries being used to transmit the Mimikatz tool (password extraction and encryption software) in pieces of data meant to be reassembled by the trojan on the host; this is a large file and required too many DNS queries to transmit the data, which made it prone to detection.

    DNS flood

    This next attack is effectively a distributed denial of service (DDoS) attack using DNS queries. A DDoS attack aims to take down a resource by literally flooding it with packets; in a DNS flood, the attacker uses infected hosts or bots to take down DNS servers. For more details, see our in-depth article on DNS floods.

    There are many different types of DNS flood attacks, but we will focus on three in our discussion: a DNS query flood, a DNS reflective attack, and DNS water torture. Here is a simple diagram of the overall concept:

    DNS query flood

    In a DNS query flood, the threat actor will use several bots to send tons of DNS queries with spoofed source IP addresses.

    DNS reflective attack

    A DNS reflective attack is much more aggressive and will be more difficult to trace than a query flood. In this variation, a target IP address is designated and the requests are sent to several different DNS servers to avoid flooding any one DNS server. 

    DNS water torture attack

    DNS water torture attacks aim to take down authoritative DNS servers. Many bots make thousands of very small subdomain queries, like a thousand tiny drops (hence the name “slow drip” or “water torture”).

    DNS hijacking

    DNS hijacking occurs when an authoritative server is compromised and the threat actors gain access to change public A records. As a result, any endpoint or DNS resolver trying to reach a website would be redirected to a poisoned A record of the threat actor’s choosing. The example below discusses how Amazon’s DNS servers were hijacked using falsified BGP advertisements (more on the attack here).

    In 2018, threat actors launched a DNS hijacking attack against myetherwallet.com. Threat actors began advertising BGP routes for 205.251.199.0/23, which belongs to the authoritative DNS servers for Route 53, the AWS DNS service. Several DNS servers, including those of Cloudflare, accepted these routes. The TAs then started to redirect www.myetherwallet.com to a malicious website via the public A record for this top-level domain. On closer inspection, the advertised TLS certificate was self-signed, but if users chose to continue to the website, the TA could capture all of the information sent. This attack resulted in about $160,000 worth of Ethereum cryptocurrency being stolen over two hours.

    Identifying an attack

    In most instances, these attacks can go undetected for a significant amount of time because they are just very deceptive. When looking for signs of a DNS attack, it is important to pay close attention to the reports coming in from your end users and various organizational departments. If there is an influx of issues with your primary intranet site or an external web site indicating that the site “looks weird” or is completely down, it is time to take these reports very seriously. 

    Another good indication of these attacks would be reports of duplicate IP addresses on the network, which could be a rogue DHCP server handling requests. Any uptick in bandwidth consumption from specific machines or the DNS server itself is a good marker of an attack.

    Consider the following example scenario. Suppose that Dave is the website administrator for DavesCompany.com and starts receiving multiple reports that the website is running very slow and some claiming that it is down entirely. Dave begins investigating by testing the website from his local browser and receives the output shown below:

    Dave then uses the ping utility from his local workstation to test connectivity to the web server, as shown in the image below. Judging by the high latency of the ping requests, Dave becomes suspicious of a possible DDoS attack.

    Now Dave is on high alert. He immediately looks over the logs in the firewall associated with the authoritative server for davescompany.com. The results show high numbers of DNS queries from a specific IP subnet. These signs suggest that the DNS server holding records for davescompany.com is experiencing a DNS flood attack. Dave now needs to deal with this issue, as discussed in the next section.

    Mitigating and preventing DNS attacks

    DNS attacks range in severity and should be dealt with using measures appropriate to the specific attack. Here are some individual attack mitigation and prevention strategies for the various attack types described above.

    DNS cache poisoning

    The best course of action for mitigation here is to identify the source of the attack. In some instances, this will be a node on your internal network, so you will need to find the rogue device. Use network scanners to find devices that have makes, models, or MAC addresses that don’t fit with your standard deployments. Also check for machines on your network that are disconnected in your control software and devices that are offline but shouldn’t be.

    Once the rogue device is identified and eliminated from the network, you will want to flush the DNS on all of your network devices. In Windows, this can be done with the command ipconfig /flushdns, but a good, old-fashioned reboot is often the best approach. 

    DNSSEC is an excellent way to further prevent DNS cache poisoning, since DNS lacks any form of authentication by default (RFC 4033 is the standard for DNS security). DNSSEC will use digital signatures and public key cryptography to validate DNS data. If the data being transmitted is not encrypted with the private key, the public key will not be able to decipher the information and will discard the contents, preventing the device from being redirected by poisoned records.

    DNS tunneling

    This is a much more severe type of DNS attack. It will have some sort of malware involved, and some pretty deep log analysis will be required. 

    When filtering your logs, you will want to look for any DNS queries that have complex domain names or anything that looks suspicious; the odds are that there will be a lot of requests and replies to/from these domains. Compare the recent volume of DNS requests with historical DNS requests in a given day, and there will be much more when the attack was initiated and going forward.

    As always, run malware scanning tools on all network devices, starting with the machines responsible for the most DNS requests. Be sure to check mail logs and look for increases in spam from specific domains associated with the requests you are seeing, since this was likely initiated by a phishing scam in the first place.

    DNS flood

    DNS floods will be the easiest to mitigate, and the resources recover much more quickly compared to the other attacks. Blacklisting the IPs that are flooding your server is an absolute must if you intend to stop the attack, and blacklisting entire subnets may be necessary. Next-generation and cloud firewalls should offer filtering options as well as intrusion detection and prevention measures. 

    Rate limits can be set to restrict the number of queries that can be transmitted per second, preventing the server from being depleted of resources. Most third-party DNS and security providers will offer automatic detect-and-defeat functions for DDoS attacks. DNS servers should always have redundancy: Having only one DNS server configured within any autonomous system is a big mistake.

    DNS hijacking

    DNS hijacking can be very difficult to detect without third-party monitoring systems. The BGP protocol is still so widely adopted and so inherently insecure that it is very difficult to prevent another entity from advertising your routes as their own. 

    Resource Public Key Infrastructure (RPKI) is an example of a safeguard available for confirming the identity of BGP advertised routes.

    BGPSEC (RFC 8205) is another significant addition to help secure BGP routes.  While standard BGP will append a neighbor’s AS number to the front of the AS_PATH parameter, secure BGP will also add a cryptographic signature over the top of the AS_PATH.

    The Internet Society (ISOC) has a standardization initiative called MANRS that provides required fixes to common security issues within routing protocols.  Participation in and adoption of these standards will position a network to be much more secure and is a highly recommended best practice.

    It is very important to keep any edge routing equipment firmware up to date with the latest patches. Something as simple as using a VPN solution will prevent the hijacking of local DNS settings and redirection of end-user devices. Training staff and end-users is a big asset in preventing this kind of attack.

    Even if DNS is hijacked, the resulting websites will be very poorly disguised. Anyone with basic training should be able to recognize the signs and leave any false, redirected sites immediately.

    DNS security best practices

    As a recap, here are some recommendations for best practices for preventing DNS-based attacks:

    • Enable DNSSEC on all DNS servers (note that special considerations apply to IPv6).
    • Use rate limiting for DNS queries.
    • Implement firewalls and keep firewall definitions up to date.
    • Create and/or utilize redundant DNS servers.
    • Utilize third-party software to secure public DNS servers.
    • Implement RPKI infrastructure to better secure public routes advertised within your AS.

    Conclusion

    DNS is an absolute requirement for today’s internet; unfortunately, it was never designed with security in mind, which makes it a difficult attack surface to secure. DNS can be manipulated by cache poisoning, facilitating malware injection into your hosts through tunneling. It can completely take down your website in a flood, or worse, your public DNS records may be hijacked. 

    Pay close attention to the recommended best practices and maintain a diligent posture when it comes to monitoring and logs. By utilizing some of the extensive third-party options available and implementing proper safeguards to maintain DNS data, you can take one potential catastrophe off your already stacked IT plate.

    Stop DNS threats before they stop your services

    LogicMonitor’s network monitoring gives you real-time alerts on DNS anomalies, unauthorized record changes, and traffic spikes — so you can respond before an attack causes an outage.

    See LogicMonitor in action

    FAQs

    What are the most common types of DNS attacks?

    The four most significant DNS attack categories are: DNS cache poisoning (corrupting resolver caches with false records), DNS tunneling (hiding malicious data inside DNS traffic), DNS flood attacks (DDoS campaigns against DNS servers), and DNS hijacking (compromising authoritative DNS to redirect traffic at the source). Each exploits a different aspect of the DNS protocol.

    How does DNS cache poisoning work?

    In a DNS cache poisoning attack, the attacker attempts to inject fraudulent DNS records into a resolver’s cache. When successful, legitimate users querying that resolver are redirected to attacker-controlled IP addresses — often a phishing site or malware delivery server — without any change to authoritative DNS and without any visible indication that something is wrong.

    What is DNS tunneling and why is it hard to detect?

    DNS tunneling encodes non-DNS data (commands, exfiltrated data) inside DNS query and response fields. Because DNS traffic is rarely blocked by firewalls and is often not logged in detail, it provides attackers with a covert channel that can bypass traditional security controls. Effective detection requires traffic analysis tools that identify anomalous DNS query patterns such as unusually long domain names or high query rates to a single domain.

    How can DNSSEC help protect against DNS attacks?

    DNSSEC adds cryptographic signatures to DNS records, allowing resolvers to verify that responses are authentic and haven’t been tampered with in transit. This directly prevents cache poisoning and man-in-the-middle attacks on DNS responses. However, DNSSEC doesn’t protect against all attack types — DNS floods and tunneling require separate mitigation approaches.

    By Denton Chikura

    Technical Writer

    Denton Chikura is a technical writer and longtime observability advocate focused on helping site reliability engineers and engineering teams discover the tools and capabilities that strengthen internet resilience. He works at the intersection of monitoring, performance, and infrastructure to make complex systems more understandable and usable, bridging the gap between deep technical detail and real‑world operations. His goal is to help teams build faster, detect issues earlier, and recover smarter, ultimately making the internet a better, more reliable place for everyone.

    Disclaimer: The views expressed on this blog are those of the author and do not necessarily reflect the views of LogicMonitor or its affiliates.

    © LogicMonitor 2026 | All rights reserved. | All trademarks, trade names, service marks, and logos referenced herein belong to their respective companies.

    Product

    Platform

    Infrastructure

    Cloud & Multi-Cloud

    Log Management

    Edwin AI

    Enterprise

    Demo

    Pricing

    WebPageTest Pricing

    RUM Monitoring

    IPM Monitoring

    Synthetic Monitoring

    How We Compare

    Datadog

    Dynatrace

    Virtana

    Solarwinds

    PRTG

    ManageEngine

    ScienceLogic

    SiteScope

    BigPanda

    About

    Careers

    Our Partners

    Leadership

    Newsroom

    Security

    AI Governance

    Sustainability

    Legal

    Documentation

    Docs Hub

    Release Notes

    Security

    Support Center

    Resources

    Autonomous IT in 2026

    Resource Library

    LM Academy

    Blog

    Case Studies

    Customer Education

    Connect

    Contact & Locations

    Submit a Ticket

    Events

    LM Community

    Careers


    Product

    Platform

    Infrastructure

    Cloud & Multi-Cloud

    Log Management

    Edwin AI

    Enterprise

    Demo

    Pricing

    WebPageTest Pricing

    RUM Monitoring

    IPM Monitoring

    Synthetic Monitoring


    How We Compare

    Datadog

    Dynatrace

    Virtana

    Zenoss

    Solarwinds

    PRTG

    ManageEngine

    ScienceLogic

    SiteScope

    BigPanda


    About

    Careers

    Our Partners

    Leadership

    Newsroom

    Security

    AI Governance

    Sustainability

    Legal


    Documentation

    Docs Hub

    Release Notes

    Security

    Support Center


    Resources

    Autonomous IT in 2026

    Resource Library

    LM Academy

    Blog

    Case Studies

    Customer Education


    Connect

    Contact & Locations

    Submit a Ticket

    Events

    LM Community

    Careers


    Privacy Policy

    Terms of Use

    Preference Center

    Do Not Sell My Information

    © 2026 LogicMonitor