Glossary

DNS NXDOMAIN attack

DNS NXDomain Attack

A DNS NXDOMAIN attack, sometimes referred to as a phantom domain attack or DNS water torture attack, is a denial-of-service technique that overwhelms DNS infrastructure with requests for domains or hostnames that do not exist. By forcing DNS servers to repeatedly process and respond to invalid queries, attackers can consume network, memory, processor, and DNS resources, degrading performance and disrupting legitimate DNS resolution.

{{anchor:What is NXDOMAIN}}

What is NXDOMAIN?

NXDOMAIN stands for non-existent domain, a standard DNS response indicating that a requested domain or hostname does not exist.

NXDOMAIN responses are a normal part of DNS operations and commonly occur due to:

Attackers exploit this normal DNS behavior by generating massive volumes of invalid DNS queries, turning a legitimate protocol response into an attack vector.

{{anchor:How it works}}

How DNS NXDOMAIN attacks work

In an NXDOMAIN attack, malicious actors generate large numbers of requests for random or non-existent domains and subdomains.

This activity forces:

Because many of the requested domains do not exist, DNS servers cannot rely on cached responses and must continually process new requests, increasing the effectiveness of the attack.

A common variation involves generating random subdomains against a legitimate domain, creating a continuous stream of unique DNS queries that overwhelm authoritative DNS servers.

{{anchor:Why it matters}}

Why DNS NXDOMAIN attacks matter

NXDOMAIN attacks can create significant operational and business impacts, including:

Organizations that depend on internet-facing applications, APIs, and digital services are particularly vulnerable to DNS availability issues caused by these attacks.

{{anchor:Reducing risk}}

Reducing NXDOMAIN risk

Organizations can strengthen resilience against NXDOMAIN attacks by:

A proactive DNS strategy helps organizations maintain service availability even during periods of elevated malicious traffic.

{{anchor:How DigiCert helps}}

How DigiCert can help

DigiCert UltraDNS is an enterprise-grade authoritative DNS platform designed to help organizations maintain availability and performance under demanding conditions. Built on a globally distributed Anycast network, UltraDNS provides fault tolerance, intelligent traffic distribution, and resilience against DNS-focused attacks that target authoritative infrastructure.

By providing a secure and highly resilient DNS foundation, DigiCert UltraDNS helps organizations reduce the risk of DNS-related outages, strengthen operational resilience, and deliver trusted digital experiences even in the face of evolving DNS threats.