What goes wrong.
CACHE POISONING
Injecting false data into a resolver's cache, directing users elsewhere.
WHAT MAKES IT HARDER
Randomised source ports and query identifiers, and validation.
DOMAIN HIJACKING
Gaining control of a domain at the registrar and changing its nameservers.
WHAT PREVENTS IT
Registrar account security, two-factor authentication, and registry lock.
WHAT REGISTRY LOCK PROVIDES
Changes requiring manual verification, preventing automated or compromised changes.
AMPLIFICATION ATTACKS
Small queries producing large responses, sent with a forged source address.
WHAT PREVENTS PARTICIPATION
Not operating an open resolver, and rate limiting.
SUBDOMAIN TAKEOVER
A record pointing at a service no longer claimed, which someone else then claims.
WHAT CAUSES IT
Records left behind after a service is decommissioned.
WHAT PREVENTS IT
Removing records when removing services, and auditing for dangling entries.
TYPOSQUATTING AND LOOKALIKE DOMAINS
Registered to deceive, particularly for mail.
WHAT TO DO
Monitor for similar registrations to your own.
WHAT TO AUDIT REGULARLY
Every record in every zone, and what it still points to.