Glossary

DNS poisoning

DNS poisoning

DNS poisoning is a cyberattack that manipulates DNS data to redirect users from legitimate websites to malicious destinations. By introducing fraudulent DNS information into the DNS resolution process, attackers can cause users to unknowingly connect to attacker-controlled websites, enabling phishing, malware delivery, credential theft, and other malicious activities.

Because DNS serves as the foundation for internet navigation, compromised DNS responses can undermine trust in online services and expose organizations and users to significant security risks.

{{anchor:How it works}}

How DNS poisoning works

DNS poisoning occurs when attackers successfully inject false DNS information into the DNS resolution process. As a result, DNS resolvers or devices return incorrect IP addresses for legitimate domains.

Common DNS poisoning techniques include:

Once poisoned DNS information is accepted, users may be redirected to fraudulent websites that appear legitimate but are controlled by attackers.

{{anchor:Cache poisoning vs DNS poisoning}}

DNS poisoning vs. cache poisoning

While the terms are often used interchangeably, DNS cache poisoning is a specific type of DNS poisoning.

Both techniques seek to redirect traffic away from legitimate destinations and toward attacker-controlled infrastructure.

{{anchor: Why it matters}}

Why DNS poisoning matters

Successful DNS poisoning attacks can result in:

Because users often have no visible indication that DNS responses have been manipulated, these attacks can remain highly effective and difficult to detect.

{{anchor: Reducing risk}}

Reducing DNS poisoning risk

Organizations can strengthen defenses against DNS poisoning by:

{{anchor: How DigiCert helps}}

How DigiCert helps

DigiCert UltraDNS provides enterprise-grade authoritative DNS services designed to help organizations maintain secure, trusted, and highly available DNS infrastructure. UltraDNS supports DNSSEC, which helps protect against DNS poisoning by cryptographically validating DNS responses and ensuring users receive authentic DNS information from authoritative sources rather than manipulated or forged responses.