Glossary
DNS on-path attack
A DNS on-path attack occurs when an attacker intercepts communications between a user and a DNS service, allowing them to observe, modify, or redirect DNS traffic. By manipulating DNS responses, attackers can send users to fraudulent websites, capture credentials, intercept sensitive information, or disrupt access to trusted services.
Because DNS is responsible for directing users to online resources, compromising DNS communications can undermine the trust and security of virtually any internet-connected application.
{{anchor:How it works}}
How DNS on-path attacks work
Most DNS traffic has historically relied on unencrypted protocols, making it possible for attackers who gain access to a network path to intercept DNS requests and responses.
An attacker may:
- Intercept DNS traffic between users and DNS servers
- Modify DNS responses before they reach the user
- Redirect users to malicious or fraudulent websites
- Capture credentials, payment information, or sensitive data
- Impersonate trusted applications or services
These attacks can occur on public networks, compromised infrastructure, or any environment where attackers can position themselves within the DNS communication path.
{{anchor:Why it matters}}
Why DNS on-path attacks matter
Successful DNS manipulation can have significant consequences for organizations and users, including:
- Credential theft and account compromise
- Data breaches and unauthorized access
- Financial fraud and payment theft
- Service disruption and downtime
- Loss of customer trust
- Regulatory and compliance exposure
Both remote users and users inside corporate environments can be affected if DNS communications are intercepted or altered.
{{anchor:Reducing risk}}
Reducing DNS on-path attack risk
Organizations can strengthen defenses against DNS on-path attacks by:
- Implementing DNSSEC to validate DNS responses
- Using encrypted DNS technologies such as DNS over HTTPS (DoH) and DNS over TLS (DoT)
- Leveraging protective DNS services
- Monitoring DNS traffic for suspicious activity
- Maintaining strong endpoint security controls
- Conducting regular security assessments and vulnerability reviews
- Securing DNS infrastructure and administrative access
A layered approach to DNS security helps ensure users receive authentic DNS responses and reduces the risk of traffic manipulation.
{{anchor:How DigiCert helps}}
How DigiCert can help
DigiCert UltraDNS provides enterprise-grade authoritative DNS services designed to help organizations maintain the integrity, availability, and security of their DNS infrastructure. UltraDNS supports DNSSEC, helping organizations verify the authenticity of DNS responses and reduce the risk of DNS manipulation and tampering. DNSSEC protection helps ensure users receive trusted DNS data from authoritative sources rather than altered responses introduced by attackers.