DNS Security
DNS Best Practices
Practical steps to secure your DNS infrastructure.
Choosing DNS Protection
Critical Requirements:
100% Availability SLA:
- DNS cannot afford downtime
- Look for providers with strict SLAs
- Understand SLA measurement methodology
Always-On Protection:
- No manual activation delays
- Continuous traffic scrubbing
- Instant mitigation response
Global Anycast Network:
- Distributed presence across continents
- Multiple scrubbing centers
- Geographic load distribution
Massive Capacity:
- Tbps-level mitigation capability
- Proven track record with large attacks
- Scalable infrastructure
DNSSEC Support:
- Full DNSSEC compatibility
- Automated key management options
- Validation support
Configuration Best Practices
Authoritative Servers:
Multiple Nameservers:
- Minimum 3-4 nameservers per zone
- Different /24 networks (IP diversity)
- Different geographic locations
- Different autonomous systems (ASN diversity)
TTL Configuration:
- Longer TTLs for stable records (3600-86400 seconds)
- Shorter TTLs during migrations (300-600 seconds)
- Balance caching benefit vs. change flexibility
Record Management:
- Regular audit of DNS records
- Remove unused records promptly
- Document all changes
- Version control for zone files
Resolver Configuration:
For Organizations Running Resolvers:
Disable Recursion:
- On authoritative servers (should only answer for own zones)
- Prevents resolver abuse
Rate Limiting:
- Limit queries per source
- Limit responses per destination (RRL)
Forwarding:
- Consider forwarding to protected resolver service
- Don't expose internal resolvers directly to internet
Access Control Best Practices
DNS Management:
Strong Authentication:
- Multi-factor authentication (MFA) mandatory
- Unique accounts per administrator (no shared credentials)
- Regular password rotation
- Privilege separation (read-only vs. edit access)
IP Whitelisting:
- Restrict DNS management to known IPs
- VPN requirement for remote access
- Emergency access procedures documented
Change Management:
- All changes logged with timestamp and user
- Change approval process for critical zones
- Automated testing before production deployment
- Rollback procedures documented
Zone Transfer Security:
AXFR/IXFR Restrictions:
- Allow only from authorized secondary servers
- IP-based access control
- TSIG (Transaction Signatures) for authentication
- Monitor for unauthorized transfer attempts
Monitoring and Alerting
What to Monitor Daily:
Query Metrics:
- Total query volume
- Queries per zone
- NXDOMAIN rate
- Query type distribution
Performance Metrics:
- Average response time
- 95th percentile response time
- Server CPU/memory utilization
- Network bandwidth usage
Security Metrics:
- Failed authentication attempts
- Zone transfer requests
- Unusual query patterns
- Source IP distribution
Alert Configuration:
- Query volume >5x baseline
- NXDOMAIN rate >20% of queries
- Response time >100ms
- Single IP >1000 queries/minute
- Any zone transfer attempts (if disabled)
Redundancy and Backup
DNS Provider Redundancy:
Primary + Secondary Providers:
- Different DNS hosting providers
- Automatic synchronization between providers
- Independent infrastructure
- Geographic diversity
Benefits:
- Provider-level redundancy
- DDoS attack isolation
- Maintenance window flexibility
- Protection against provider outages
Zone File Backups:
- Daily automated backups
- Store backups off-site
- Version history (30+ days)
- Test restoration procedures quarterly
Regular Security Activities
Weekly:
- Review query volume trends
- Check for unusual traffic patterns
- Verify DNS resolution from multiple locations
Monthly:
- Audit DNS records for accuracy
- Review and update rate limiting thresholds
- Check for subdomain takeover vulnerabilities
- Review access logs
Quarterly:
- Test failover to secondary DNS providers
- Conduct tabletop DNS incident response exercise
- Review and update DNS security policies
- Audit user access permissions
Annually:
- Full DNS security assessment
- DNSSEC key rollover (if applicable)
- Vendor/provider performance review
- Disaster recovery drill
DNS Security Checklist
✅ Protection: Always-on DDoS protection with Anycast
✅ DNSSEC: Enabled and validated
✅ Redundancy: Multiple authoritative servers, different networks
✅ Monitoring: Continuous monitoring with automated alerts
✅ Access Control: MFA, IP whitelisting, audit logging
✅ Rate Limiting: Query and response rate limits configured
✅ Zone Transfers: Restricted to authorized servers only
✅ Backups: Daily automated zone file backups
✅ Testing: Quarterly failover and DR drills
✅ Documentation: Incident response playbook maintained
Common DNS Security Mistakes to Avoid
❌ Using free/basic DNS hosting without DDoS protection
❌ Relying on single DNS provider (no redundancy)
❌ Allowing unrestricted zone transfers
❌ No monitoring or alerting configured
❌ Weak authentication on DNS management
❌ Leaving unused DNS records (subdomain takeover risk)
❌ No testing of failover procedures
❌ Ignoring DNS in disaster recovery planning
Key Takeaway: DNS security is not "set and forget." It requires ongoing monitoring, regular testing, and continuous improvement to protect this critical infrastructure.
Ready to Safeguard Your Web Assets?

