The Domain Name System, or DNS, translates domain names into network addresses and supports many everyday Internet services.
For a business, DNS is involved in websites, email, cloud services, remote access, authentication systems, and other applications. Because DNS sits at the center of so many services, unusual DNS activity can provide useful security information.
The foundation
DNS is more than a phone book
DNS requests can provide useful context about what devices are attempting to reach.
A DNS request may reveal which domain a device is attempting to contact. On its own, a single request may not be concerning. Over time, however, DNS activity can help establish a baseline of normal behavior for users, devices, and applications.
-
01
DNS visibility
Requests can show where devices are going
Security monitoring can examine DNS requests for unusual patterns, including unexpected destinations, repeated lookups, and domains that are rarely used elsewhere in the business.
Monitoring priorityEstablish which DNS servers business devices use and retain enough DNS information to investigate unusual requests.
Threat detection
Malware often uses DNS
DNS activity can provide an additional source of evidence when a device is communicating with malicious infrastructure.
Malware may communicate with external infrastructure using domain names. A compromised computer might repeatedly request domains associated with command-and-control infrastructure, malware distribution, phishing, tracking, or suspicious dynamic DNS services.
-
01
Potential indicators
Look for changes in device behavior
- Repeated requests to rarely seen domains
- Connections to newly registered infrastructure
- Requests to suspicious dynamic DNS services
- Large increases in DNS volume
- Requests occurring at unusual times
Investigation priorityCompare the device's current DNS behavior with its normal activity and review the endpoint for unexpected processes.
Compromised devices
DNS can reveal changes that users cannot see
A compromised workstation may look normal to the employee using it.
Imagine that an employee's workstation suddenly begins requesting hundreds of unusual domains. The user may not notice anything different, but DNS monitoring could identify the change in behavior and allow the security team to investigate the device.
Behavioral change is an important signal
DNS monitoring is especially useful when it identifies a meaningful change from a device's established pattern of activity.
Email protection
DNS security also matters for email
Several DNS records are directly relevant to email delivery and domain impersonation.
Incorrect email DNS configuration can affect mail delivery and increase the risk of attackers impersonating the business domain. Important records include SPF, DKIM-related configuration, DMARC, and MX records.
-
01
Email DNS records
Configuration should be documented and reviewed
- SPF: identifies permitted sending systems
- DKIM: supports message signing and verification
- DMARC: defines how authentication failures are handled
- MX: identifies mail delivery servers
Business priorityDocument expected email DNS records and investigate unexpected changes or authentication failures.
Change monitoring
DNS changes can affect business operations
An unauthorized or accidental DNS modification can redirect websites, email, applications, or other services.
Important records include A, AAAA, CNAME, MX, TXT, and NS records. Changes should be documented, approved, and monitored so that unexpected modifications can be investigated quickly.
-
01
Records to monitor
Unexpected changes may have operational or security impact
- A records for websites and applications
- AAAA records for IPv6 services
- CNAME records for aliases and hosted services
- MX records for email delivery
- TXT records for verification and email security
- NS records for authoritative DNS delegation
Change-management priorityMaintain a record of approved DNS changes and alert on modifications that do not match the expected process.
Internal visibility
Internal DNS is also important
Businesses should not limit DNS monitoring to publicly visible domains.
Internal DNS activity can provide information about which systems are communicating, which domains are being requested, and which devices are generating unusual activity.
-
01
Internal activity
Monitor the behavior of devices inside the network
- Which systems are communicating
- Which domains are requested
- Which devices generate unusual requests
- Which hosts repeatedly fail DNS resolution
- Whether a device's request volume changes suddenly
Layered detection
DNS monitoring provides another security layer
DNS monitoring should complement—not replace—other security controls.
DNS monitoring should not replace firewalls, endpoint protection, or intrusion detection. Instead, it adds another source of evidence that can make a security investigation more complete.
-
01
Example investigation
Multiple signals can explain what happened
- Firewall: connection observed
- DNS: suspicious domain requested
- Endpoint: unexpected process detected
- IDS: suspicious network behavior identified
When these events are correlated, the organization can develop a much clearer picture of what occurred.
The takeaway
Improve visibility into your network
DNS monitoring can help businesses identify suspicious domains, compromised devices, unsafe configuration changes, and unusual internal activity.
It is most effective as part of a broader monitoring strategy that combines DNS, firewall, endpoint, authentication, and intrusion-detection information.
Centralize your security visibility
Monitor the activity your business depends on
Managed security monitoring can combine DNS, firewall, authentication, and intrusion-detection information into a centralized monitoring environment.
Request a Small Business Security Assessment