Skip to content

Archive

DNS

48 articles
Tech 16 Sep 2026 5 min read

DNS Negative Caching Temporarily Stores Name Errors

A DNS cache does not store only successful answers. Recursive resolvers can also retain authoritative responses that say a requested name or record does not exist. This behavior is called negative caching. Negative caching reduces repeated work. If many clients ask for the same absent name, a resolver can answer from its cache instead of sending the same query through the DNS hierarchy each time. The trade-off is temporal. If an administrator adds the missing record while a negative answer is still cached, some clients can continue receiving the cached error until its negative cache lifetime expires.

Software Engineering 16 Sep 2026 6 min read

DNS Negative Caching Can Outlive Record Creation

A recursive DNS resolver can continue returning an earlier absence result after the authoritative zone has gained the requested name. The new record and the cached negative answer are not contradictory: they exist at different points in the resolution path, and the cache remains valid until its negative TTL expires or local policy removes it sooner. This behavior gives DNS absence its own cache lifetime. Publishing a record changes authoritative state, but it does not synchronously invalidate negative entries already stored by recursive resolvers.

Cybersecurity 15 Sep 2026 7 min read

NSEC3 Trades DNSSEC Name Exposure for Operational Cost

NSEC3 Trades DNSSEC Name Exposure for Operational Cost A signed DNS zone has to authenticate absence as well as presence. When a resolver asks for a name that does not exist, a DNSSEC-validating resolver needs cryptographic evidence that the negative answer was not forged by an intermediary. The original NSEC mechanism supplies that evidence by linking existing names in canonical order. That design has a side effect: the links expose names. Following NSEC records can reveal much of a zone even when ordinary DNS queries do not provide an enumeration interface.

Cybersecurity 15 Sep 2026 8 min read

DNSSEC Validation Makes DNS Tampering Detectable at the Resolver

DNSSEC Validation Makes DNS Tampering Detectable at the Resolver A recursive resolver can receive a syntactically valid DNS answer from the network and still have no cryptographic evidence that the answer came from the zone responsible for the name. Transaction identifiers, source-port randomization, and transport controls make blind forgery harder, but they do not turn ordinary DNS records into authenticated data. DNS Security Extensions add that missing property for signed portions of the namespace. Resource-record sets carry signatures, zones publish signing keys, and parent zones can bind child keys into a chain rooted in a configured trust anchor. A validating resolver can then classify data according to cryptographic evidence instead of accepting an answer solely because it arrived through the expected DNS exchange.

Cybersecurity 15 Sep 2026 7 min read

DNSSEC Makes DNS Data Verifiable Across Resolver Boundaries

DNSSEC Makes DNS Data Verifiable Across Resolver Boundaries A recursive resolver can receive a DNS response from the expected network address and still lack cryptographic proof that the record came from the zone owner. Traditional DNS uses transaction matching, delegation structure, and transport behavior to associate replies with queries. Those controls can reject many stray packets, but they do not make returned resource-record data cryptographically verifiable. DNS Security Extensions, commonly called DNSSEC, add signatures and a chain of authenticated delegation to that model. A validating resolver can test whether signed data corresponds to a key authorized through the DNS hierarchy. The result is narrower than encrypted DNS: DNSSEC authenticates DNS data, not the confidentiality of the query path.

Tech 15 Sep 2026 6 min read

DNS TTL Controls Cache Reuse

DNS TTL Controls Cache Reuse DNS resolvers avoid repeating the full lookup process for every request by caching resource records. Each cached record set carries a time to live, or TTL, that limits how long the resolver can normally reuse that data before consulting its source again. A longer TTL can reduce query traffic and make repeated lookups faster. A shorter TTL narrows the period in which cached data can remain in use after an authoritative record changes. The value therefore connects DNS performance with the timing of operational changes.

Cybersecurity 15 Sep 2026 6 min read

DNS Rebinding Turns Hostname Trust Into Network Reach

DNS Rebinding Turns Hostname Trust Into Network Reach A browser tab can keep the same scheme, hostname, and port while the IP address behind that hostname changes. That ordinary property of DNS becomes dangerous when software assumes the address reached by a browser is fixed for the lifetime of an origin. DNS rebinding attacks exploit the gap between two identities. Browser security policy is largely expressed in terms of origins, where a hostname is part of the identity. Network services often reason in terms of addresses and interfaces: loopback, a private subnet, a management VLAN, or another location considered unreachable from the public internet. Rebinding can preserve the browser-visible hostname while steering later connections toward a different network address.

Cybersecurity 15 Sep 2026 5 min read

DNS Rebinding Turns Browser Origin Trust Into a Network Pivot

DNS Rebinding Turns Browser Origin Trust Into a Network Pivot A browser can keep treating a page as belonging to the same web origin even after the hostname behind that origin starts resolving to a different IP address. That separation between origin identity and network destination creates the opening for DNS rebinding. The attacker does not need to convince a local service to initiate an outbound connection. Instead, a page already running in the browser issues requests under an attacker-controlled hostname. If subsequent DNS resolution maps that hostname to a loopback, private, or otherwise locally reachable address, the browser can become a bridge between remote content and a service exposed only to the victim’s network.

Tech 15 Sep 2026 4 min read

DNS Negative Caching Reuses Name Errors

DNS caches are not limited to successful address lookups. A recursive resolver can also retain an authoritative answer that says a requested name does not exist or that a particular record type has no data. This behavior is called negative caching. It prevents repeated requests for the same missing data from reaching authoritative DNS servers on every lookup. Negative answers cover different cases A DNS response can report that an entire domain name does not exist. The NXDOMAIN response code represents this case.

Tech 15 Sep 2026 7 min read

DNS Negative Caching Keeps Failed Lookups Temporary

A DNS lookup does not always return an address or another requested record. An authoritative server can report that a domain name does not exist, or it can report that the name exists but has no record of the requested type. Recursive resolvers can keep these negative answers in cache for a limited period. That behavior reduces repeated traffic for the same failed lookup and prevents authoritative servers from receiving identical questions on every client attempt.

Cybersecurity 15 Sep 2026 7 min read

CAA Records Constrain Public Certificate Issuance at the DNS Boundary

CAA Records Constrain Public Certificate Issuance at the DNS Boundary A public certificate can pass every browser check after issuance even if the domain operator never intended to use the certificate authority that created it. The Web PKI has several controls for detecting or responding to bad issuance, but DNS Certification Authority Authorization (CAA) acts earlier: it gives a domain holder a way to state which issuers are permitted to create certificates for a name.

Tech 14 Sep 2026 6 min read

Encrypted DNS Hides Name Queries From Local Networks

Opening a website usually starts with a name lookup. A device needs an IP address for a domain, so it sends a DNS query to a resolver. Traditional DNS commonly sends those queries without transport encryption, which allows networks along the local path to observe or alter them. Encrypted DNS changes that transport. DNS over HTTPS, often called DoH, carries DNS messages inside HTTPS. DNS over TLS, or DoT, carries them through a dedicated TLS connection. Both approaches protect queries between the client and the selected resolver from straightforward inspection on that path.

Cybersecurity 14 Sep 2026 8 min read

DNSSEC Makes DNS Answers Verifiable, Not Confidential

A resolver receives an address for a production hostname and has to decide whether the answer is merely syntactically valid or cryptographically tied to the zone that published it. Ordinary DNS provides no native proof that the data survived the path from an authoritative source without unauthorized alteration. DNSSEC changes that property, but only within a carefully defined boundary. That boundary matters in operations. DNSSEC does not encrypt a query, conceal a domain name, authenticate an application server, or guarantee that an authoritative service stays reachable. It signs DNS data so a validating resolver can detect forged or modified records when a chain of trust exists. Treating it as a broad DNS security layer obscures both its value and its failure modes.

Tech 14 Sep 2026 5 min read

DNS TTL Controls How Long Resolvers Reuse Records

DNS answers are often reused instead of being requested from authoritative servers for every connection. A resolver can keep a record in its cache for a limited period, then answer later queries from that cached copy. The record’s time to live, commonly written as TTL, sets that cache lifetime in seconds. A value of 300 permits caching for up to five minutes, while 3600 permits up to one hour. Once the remaining lifetime reaches zero, the cached record is no longer considered fresh and the resolver normally needs a new answer before serving it again.

Tech 14 Sep 2026 6 min read

DNS over HTTPS Encrypts Resolver Queries

Opening a website usually starts before the browser sends an HTTP request. The device first needs an IP address for the hostname, and DNS commonly provides that mapping. Traditional DNS traffic can expose those queries to systems along the network path because classic resolver exchanges are not encrypted by default. DNS over HTTPS, usually shortened to DoH, changes the transport. It sends DNS messages through HTTPS, so the request and response receive the confidentiality and integrity protection of the HTTPS connection between the client and the selected resolver.

Cybersecurity 14 Sep 2026 7 min read

CAA Records Narrow Certificate Issuance Authority

CAA Records Narrow Certificate Issuance Authority A public certificate authority can validate control of a domain correctly and still be the wrong authority for that domain’s operating policy. DNS Certification Authority Authorization, or CAA, addresses that gap by giving a domain operator a published way to constrain which certificate authorities are permitted to issue certificates for its names. Domain-control validation establishes that an applicant can satisfy a validation method. CAA expresses a separate authorization decision: among the public certificate authorities capable of performing validation, which ones may proceed with issuance for this domain?

Cybersecurity 13 Sep 2026 6 min read

DNS Rebinding Crosses the Browser Network Boundary

A browser tab can begin its life talking to a public server and, moments later, send requests under the same hostname to a device on a private network. No browser exploit is required for that transition. DNS can supply the change. That property sits at the center of DNS rebinding. The attack is easy to reduce to a slogan about DNS answers changing, but the security consequence comes from a deeper mismatch. Browsers identify web origins primarily through scheme, host, and port. Network services often make trust decisions from the destination address, interface, or apparent local reachability. Rebinding creates a point where those two models no longer describe the same security boundary.

Tech 13 Sep 2026 7 min read

DNS Cache and Record TTL

A domain can point to a new server and still resolve to its previous address for some people. The change may already be present on the authoritative DNS server, yet a resolver that received the older record earlier can continue returning that cached answer until its permitted lifetime runs out. That lifetime is expressed through DNS time to live, usually shortened to TTL. It gives caching resolvers a limit for retaining record data. TTL makes repeated lookups less dependent on contacting authoritative servers, but it also means a DNS change is not necessarily visible to every resolver at the same moment.

Tech 13 Sep 2026 6 min read

DNS Cache and Delayed Address Changes

A website can move to a new server while one device still reaches the old address and another reaches the new one. The site itself may be healthy in both places. The difference can come from DNS caching: a resolver is reusing an answer it received earlier instead of asking the authoritative DNS service for the current record. This behavior is part of normal DNS operation. Caching reduces repeated queries and lets resolvers answer familiar names without starting a fresh lookup each time. It also means a DNS record change does not become visible to every client at the same instant.

Cybersecurity 13 Sep 2026 9 min read

Dangling DNS Records Preserve Authority After Services Disappear

A product team deletes an old hosted application, the cloud resource disappears, and the monthly bill stops. The public hostname often survives. Months later, preview.example.com still resolves through a CNAME to a provider-specific name associated with a resource that no longer exists. From the organisation’s perspective the application is gone. From DNS’s perspective, authority is still being delegated. That mismatch creates the conditions associated with subdomain takeover. The important detail is not simply that a DNS record points at a dead destination. Exploitation also depends on the external service allowing another party to claim the referenced name, tenant, site, bucket, project, or equivalent routing identifier. A dangling record is therefore evidence of stale control; whether it is directly exploitable depends on the provider’s ownership model.

Cybersecurity 12 Sep 2026 8 min read

DNS Rebinding Turns Name Validation Into Stale Evidence

A service receives a URL, resolves its hostname, confirms that the returned address is public, and approves the request. Moments later, the HTTP client resolves the same hostname again. This time the answer points at a loopback address, a private network, or another destination the service was supposed to keep out of reach. Both pieces of code can appear correct in isolation. The validator rejected forbidden addresses. The client connected to the hostname it was given. The failure sits between them: the security decision was made about one DNS result, while the network operation used another.

Cybersecurity 12 Sep 2026 6 min read

DNS Rebinding Turns Name Resolution Into a Browser Pivot

DNS Rebinding Turns Name Resolution Into a Browser Pivot A browser tab does not need direct knowledge of a private network to become a useful bridge into it. If an attacker controls a hostname and its DNS answers, the same hostname can first resolve to an attacker-controlled public server and later resolve to an address reachable only from the browser’s network. The page keeps using a familiar origin label while the destination behind that label changes.

Tech 12 Sep 2026 6 min read

DNS Cache and Stale Addresses

A website can move to a new server while one device still tries the old address. Another device on the same network may connect normally. That mismatch can come from DNS caching: a resolver has kept an earlier answer and is still allowed to reuse it. DNS caching is not a single cache in one fixed place. Browsers, operating systems, local network software, and recursive DNS resolvers can all retain DNS information. The result is fewer repeated lookups, but it also means a changed record does not necessarily appear everywhere at the same instant.

Tech 02 Sep 2026 7 min read

What DNS Does and Why It Can Affect Browsing

When you enter a website address into a browser, your device usually needs to discover which network address belongs to that name before it can connect. The system that performs this translation is the Domain Name System, or DNS. DNS normally works quietly in the background. Because it is involved near the beginning of many internet connections, however, a DNS problem can make a healthy connection feel broken. A website may fail to open even though Wi-Fi is connected and other network services still work.