Security Articles
Articles on DNS security including DNSSEC, email authentication, and threat protection.
3 min read
Typo-Like Nameservers: Investigating 145,061 Historical Delegations
A historical pipeline flagged 145,061 delegations to a typo-like nameserver domain. Similar spelling alone does not establish malicious control or takeover.
10 min read
What Happens When One DNS Provider Goes Down: The Hidden Fragility of TLD Ecosystems
Historical DNS provider concentration figures illustrate shared failure risk. Read the reported counts alongside unresolved denominator and corpus limits before using them as current market shares.
3 min read
How Expired Name Servers Become Domain Hijacking Vectors
Historical nameserver-delegation candidates illustrate why owners should verify authority, provider status and domain control. An expiry-looking hostname does not prove takeover risk.
7 min read
Why DNSSEC Is Still Failing: Lessons from 240 Million Domains
Historical zone snapshots reported low parent-DS presence. Examine the measurement limits, provider incentives, and operational reasons DNSSEC deployment can remain incomplete.
20 min read
Complete Guide to DNS Attacks and DNS Security (Prevention, Testing & Mitigation)
A comprehensive guide to DNS attack types including cache poisoning, amplification, tunneling, zone walking, and hijacking. Learn how attackers exploit DNS, how to test your own domains, and how to harden your infrastructure.
6 min read
Phantom Domain Attack: How Unresponsive Domains Exhaust DNS Resolvers
Phantom domain attacks overwhelm DNS resolvers by forcing them to wait for responses from domains that never answer. Learn how this resource exhaustion attack works and how to defend your resolver infrastructure.
8 min read
DNSSEC Downgrade Attack: How Attackers Strip Cryptographic Protection from DNS
DNSSEC downgrade attempts exploit validation gaps or permissive policies. Learn why a valid signed chain should reject stripped signatures, and how to test secure, insecure, and bogus results.
6 min read
Fast Flux DNS: How Botnets Hide Behind Rapidly Rotating IP Addresses
Fast flux DNS rapidly rotates the IP addresses behind a domain to hide malicious infrastructure from takedowns. Learn how single and double flux networks work, how to detect them, and how threat intelligence teams track them.
7 min read
DNS Rebinding Attack: How Browsers Are Tricked Into Bypassing Same-Origin Policy
DNS rebinding manipulates DNS responses to trick a browser into treating an attacker's server and an internal network resource as the same origin. Learn how the attack works, why it bypasses firewalls, and how to defend against it.
8 min read
DNS Over HTTPS Abuse: How Encrypted DNS Creates Security Blind Spots
DNS over HTTPS encrypts DNS queries inside HTTPS traffic, providing privacy but also enabling attackers to bypass DNS monitoring, content filters, and security controls. Learn how DoH is abused and how to maintain visibility.
6 min read
DNS Tunneling Attack: How Data Is Smuggled Through Port 53
DNS tunneling hides data inside DNS queries to bypass firewalls and exfiltrate information through port 53. Learn how encoded subdomain queries work, how to detect tunneling, and how to lock down your DNS infrastructure.
6 min read
NXDOMAIN Attack: How Nonexistent Domain Floods Exhaust DNS Resolvers
NXDOMAIN attacks flood DNS resolvers with queries for domains that do not exist, exhausting resolver resources and degrading performance for legitimate users. Learn how the attack differs from water torture and how to defend your resolvers.
7 min read
DNS Water Torture Attack: How Random Subdomain Floods Overwhelm Nameservers
Random subdomain floods can defeat ordinary per-name caching and overload authoritative DNS. Learn where NXDOMAIN cuts and validated denial caching help, and how to plan mitigation.
6 min read
DNS Amplification Attack Explained: How Open Resolvers Enable Massive DDoS
DNS amplification attacks exploit open resolvers to generate massive DDoS floods with up to 70x traffic amplification. Learn how reflection works, the Spamhaus case study, and how to prevent your servers from being weaponized.
7 min read
Subdomain Takeover: How Dangling DNS Records Let Attackers Hijack Your Domain
A subdomain takeover happens when a CNAME points to a decommissioned cloud service that an attacker can reclaim. Learn how to find dangling DNS records, which providers are vulnerable, and how to prevent takeovers.
9 min read
DNS Hijacking Explained: How Attackers Take Control of Your Domain's Resolution
DNS hijacking redirects your domain's traffic by compromising registrar accounts, nameservers, or network infrastructure. Learn the four types of hijacking, real-world incidents like the Sea Turtle campaign, and how to protect your domains.
7 min read
What Is DNS Cache Poisoning? How It Works and How to Prevent It
DNS cache poisoning injects forged records into a resolver's cache, silently redirecting users to malicious servers. Learn how the Kaminsky attack works, how to test your resolver, and how DNSSEC prevents it.
10 min read
DNS Zone Walking for Subdomain Enumeration: How NSEC Exposes Your Subdomains
Ordinary NSEC chains can expose names within a DNS zone. Learn how subdomain walking differs from NSEC3 dictionary recovery and minimally covering denial responses.
11 min read
DNS Zone Walking at the TLD Level: NSEC, NSEC3, and Coverage Limits
Compare cleartext NSEC chains, NSEC3 hash recovery, and opt-out at the TLD level. Learn why represented delegations, registered domains, and parent-DS counts are different measures.
5 min read
DNS Zone Transfer Attack (AXFR): How a Single Query Exposes Your Entire Domain
An unrestricted DNS zone transfer hands an attacker your complete zone file, every subdomain, IP address, and service record. Learn how AXFR works, how to test your own nameservers, and how to lock down zone transfers.
7 min read
What Is an Open DNS Resolver? Why It's Dangerous and How to Fix It
An open DNS resolver accepts recursive queries from anyone on the internet, making it a weapon for DDoS amplification attacks. Learn how to check if your server is an open resolver and how to lock it down.
14 min read
How to Identify and Manage Web Crawlers: A Sysadmin's Guide to robots.txt, AI Bots, and SEO Crawlers
Before you file an abuse report against that IP hammering your server, check the User-Agent. This guide covers how to identify web crawlers, manage them with robots.txt and server-level controls, and decide when to block, allow, or report.
8 min read
How to Report Usenet Abuse: Spam, Piracy, and Illegal Content on Newsgroup Servers
Usenet remains active and so does its abuse. This guide covers how to report spam, copyright infringement, and illegal content on newsgroup servers, including how to trace posts to source IPs and file complaints with Usenet providers.
9 min read
How to Report Network Security Incidents to a CERT Team: Templates for Vulnerability Exploitation and Intrusions
CERT teams coordinate responses to security incidents across organizations and borders. This guide explains when to contact a CERT, how to write incident reports they can act on, and provides templates for common scenarios like vulnerability exploitation and network intrusions.
12 min read
How to Contact Law Enforcement About Cybercrime: Filing Reports With FBI IC3, Europol, and National CERTs
Sometimes ISP abuse reports aren't enough. You need law enforcement involved. This guide covers when to escalate to authorities, how to file reports with FBI IC3, Europol, and national CERTs, and what evidence to prepare for a criminal investigation.
7 min read
How to Report Child Exploitation Material (CSAM) Online: Emergency Contacts and Reporting Steps
Report suspected online child sexual exploitation through official channels. Do not download, screenshot or investigate the material. Provider duties are a separate workflow.
14 min read
DMCA Takedown Notice Template: How to Report Copyright Infringement to a Hosting Provider
When someone hosts your copyrighted content on their server, a properly formatted DMCA takedown notice is the fastest legal tool to get it removed. This guide includes a ready-to-use template, explains the legal requirements, and walks through finding the right abuse contact.
11 min read
How to Report Phishing Emails and Websites Hosted on an IP Address
Phishing sites can steal credentials in minutes, so speed matters when reporting them. This guide covers how to trace phishing emails and websites to their hosting IP, file takedown requests with hosting providers, and report to anti-phishing organizations.
12 min read
How to Report Spam From an IP Address: Abuse Reports for Unsolicited Email
Spam wastes bandwidth, clogs inboxes, and often carries malware. This guide shows you how to trace spam back to its source IP, extract the evidence from email headers, and file abuse reports that get spammers shut down.
9 min read
How to Report a Hacked Server: Filing Abuse Reports After a Compromise
A compromised server is often used to launch attacks on others. After containing the breach, reporting the compromise to your hosting provider and the attacker's ISP helps shut down the attack chain and protects other potential victims.
10 min read
How to Report Malware and Botnet Command-and-Control Traffic From an IP Address
When you detect command-and-control traffic reaching out to a malicious IP, reporting that C2 server can disrupt the entire botnet. This guide covers how to identify C2 indicators, collect network evidence, and file reports that get C2 infrastructure taken down.
9 min read
How to Report Port Scanning and Network Reconnaissance to an ISP
Port scanning is often the first step in a targeted attack. This guide explains how to detect network reconnaissance in your firewall logs, gather evidence, and report the scanning IP to its ISP before an actual attack follows.
10 min read
How to Report Brute Force SSH and RDP Attacks: Log Evidence and Abuse Report Templates
Brute force attacks against SSH and RDP are relentless and automated. This guide shows you how to extract the evidence from your auth logs, identify the attacking IP's abuse contact, and file reports that get malicious hosts shut down.
11 min read
How to Report a DDoS Attack to Your ISP: Evidence, Templates, and Escalation Steps
When a DDoS attack hits your infrastructure, the clock is ticking. This guide walks you through collecting the right evidence, finding your attacker's ISP abuse contact, and filing a report that actually gets the attack stopped.
27 min read
How to Report IP Address Abuse: The Complete Guide to Filing Reports That Get Results
Most abuse reports get ignored because they lack evidence or go to the wrong contact. This complete guide covers how to identify the right abuse contact, write reports that ISPs actually act on, and escalate when they don't respond.
13 min read
What Is DNSSEC and Why Should You Enable It?
DNSSEC protects your domain from cache poisoning and DNS spoofing by adding cryptographic verification to DNS responses. Learn how it works, why it matters, and how to enable it.
12 min read
SPF, DKIM, and DMARC: How DNS Protects Your Email From Spoofing
Learn how SPF, DKIM, and DMARC DNS records work together to authenticate your email, prevent spoofing, and protect your domain reputation. Includes example records and setup guidance.
10 min read
Dangling CNAMEs and Subdomain Takeover Risk Across the Global DNS
A historical analysis of 201 million CNAME records found 3.27 million matches to selected cloud-provider patterns. What those matches show, and why they do not establish takeover vulnerability.
10 min read
IPv6 in Historical DNS Data: AAAA Records from 2017 to 2020
Seven historical FDNS snapshots reported growth from 23.5 million to 219.7 million AAAA records. Changing coverage prevents treating that 9.35x corpus growth as an Internet adoption rate.
12 min read
SPF Record Audits: Includes, Lookup Limits and Policy Outcomes
Historical SPF observations and practical checks for permissive policies, lookup limits, redirect behavior and TXT formatting, with unresolved dataset limits stated explicitly.
11 min read
Email Authentication by the Numbers: Historical SPF and DMARC TXT Snapshots
Two historical TXT snapshots reported different SPF and DMARC record populations. Read the observed policy shares with scan-coverage, cohort, and provenance limits.
3 min read
IoT Port Exposure: Historical MQTT and Telnet Scan Observations
Reported 2019 TCP responses on MQTT- and Telnet-associated ports, with limits on device counts, protocol identity and authentication claims.
4 min read
The Shrinking Perimeter: Common Service Exposure Across IPv4
Historical 2019 TCP SYN observations across 16 conventional service ports, including 24.3 million port-22 responses. Open ports do not establish application identity or vulnerability.