Small Business Security

Why Small Businesses Need DNS Monitoring

DNS supports websites, email, cloud services, remote access, and authentication systems. Monitoring DNS activity can reveal unusual behavior that other security tools may miss.

The Domain Name System, or DNS, translates domain names into network addresses and supports many everyday Internet services.

For a business, DNS is involved in websites, email, cloud services, remote access, authentication systems, and other applications. Because DNS sits at the center of so many services, unusual DNS activity can provide useful security information.

DNS connects a workstation to business services A workstation sends a DNS request to resolve a domain name before connecting to a business website or cloud service. DNS connects users, devices, and services Workstation DNS request example.com Resolved network address
DNS translates domain names into network addresses so devices can connect to websites, applications, and cloud services.

The foundation

DNS is more than a phone book

DNS requests can provide useful context about what devices are attempting to reach.

A DNS request may reveal which domain a device is attempting to contact. On its own, a single request may not be concerning. Over time, however, DNS activity can help establish a baseline of normal behavior for users, devices, and applications.

  • 01

    DNS visibility

    Requests can show where devices are going

    Security monitoring can examine DNS requests for unusual patterns, including unexpected destinations, repeated lookups, and domains that are rarely used elsewhere in the business.

    Monitoring priority

    Establish which DNS servers business devices use and retain enough DNS information to investigate unusual requests.

Threat detection

Malware often uses DNS

DNS activity can provide an additional source of evidence when a device is communicating with malicious infrastructure.

Malware may communicate with external infrastructure using domain names. A compromised computer might repeatedly request domains associated with command-and-control infrastructure, malware distribution, phishing, tracking, or suspicious dynamic DNS services.

DNS monitoring identifies suspicious domain requests A workstation sends repeated DNS requests to suspicious domains, which are detected by a centralized monitoring system. DNS activity monitor Employee workstation Unusual DNS pattern Repeated suspicious requests Requested domains unknown-domain.example suspicious-host.example dynamic-dns.example
A sudden increase in unusual domain requests can justify an investigation into the device and its running processes.
  • 01

    Potential indicators

    Look for changes in device behavior

    • Repeated requests to rarely seen domains
    • Connections to newly registered infrastructure
    • Requests to suspicious dynamic DNS services
    • Large increases in DNS volume
    • Requests occurring at unusual times
    Investigation priority

    Compare the device's current DNS behavior with its normal activity and review the endpoint for unexpected processes.

Compromised devices

DNS can reveal changes that users cannot see

A compromised workstation may look normal to the employee using it.

Imagine that an employee's workstation suddenly begins requesting hundreds of unusual domains. The user may not notice anything different, but DNS monitoring could identify the change in behavior and allow the security team to investigate the device.

Behavioral change is an important signal

DNS monitoring is especially useful when it identifies a meaningful change from a device's established pattern of activity.

Email protection

DNS security also matters for email

Several DNS records are directly relevant to email delivery and domain impersonation.

Incorrect email DNS configuration can affect mail delivery and increase the risk of attackers impersonating the business domain. Important records include SPF, DKIM-related configuration, DMARC, and MX records.

  • 01

    Email DNS records

    Configuration should be documented and reviewed

    • SPF: identifies permitted sending systems
    • DKIM: supports message signing and verification
    • DMARC: defines how authentication failures are handled
    • MX: identifies mail delivery servers
    Business priority

    Document expected email DNS records and investigate unexpected changes or authentication failures.

Change monitoring

DNS changes can affect business operations

An unauthorized or accidental DNS modification can redirect websites, email, applications, or other services.

Important records include A, AAAA, CNAME, MX, TXT, and NS records. Changes should be documented, approved, and monitored so that unexpected modifications can be investigated quickly.

  • 01

    Records to monitor

    Unexpected changes may have operational or security impact

    • A records for websites and applications
    • AAAA records for IPv6 services
    • CNAME records for aliases and hosted services
    • MX records for email delivery
    • TXT records for verification and email security
    • NS records for authoritative DNS delegation
    Change-management priority

    Maintain a record of approved DNS changes and alert on modifications that do not match the expected process.

Internal visibility

Internal DNS is also important

Businesses should not limit DNS monitoring to publicly visible domains.

Internal DNS activity can provide information about which systems are communicating, which domains are being requested, and which devices are generating unusual activity.

  • 01

    Internal activity

    Monitor the behavior of devices inside the network

    • Which systems are communicating
    • Which domains are requested
    • Which devices generate unusual requests
    • Which hosts repeatedly fail DNS resolution
    • Whether a device's request volume changes suddenly

Layered detection

DNS monitoring provides another security layer

DNS monitoring should complement—not replace—other security controls.

DNS monitoring should not replace firewalls, endpoint protection, or intrusion detection. Instead, it adds another source of evidence that can make a security investigation more complete.

Security telemetry from multiple sources is correlated Firewall, DNS, endpoint, and intrusion detection events are sent to a central monitoring environment to create a clearer picture of suspicious activity. Correlating security telemetry Firewall DNS Endpoint Intrusion detection Central monitoring Correlated security events Clearer picture Actionable investigation
Correlating DNS with firewall, endpoint, and intrusion-detection events can provide more context than any one source alone.
  • 01

    Example investigation

    Multiple signals can explain what happened

    • Firewall: connection observed
    • DNS: suspicious domain requested
    • Endpoint: unexpected process detected
    • IDS: suspicious network behavior identified

    When these events are correlated, the organization can develop a much clearer picture of what occurred.

The takeaway

Improve visibility into your network

DNS monitoring can help businesses identify suspicious domains, compromised devices, unsafe configuration changes, and unusual internal activity.

It is most effective as part of a broader monitoring strategy that combines DNS, firewall, endpoint, authentication, and intrusion-detection information.

Centralize your security visibility

Monitor the activity your business depends on

Managed security monitoring can combine DNS, firewall, authentication, and intrusion-detection information into a centralized monitoring environment.

Request a Small Business Security Assessment