Glossary
DNS poisoning
DNS poisoning is a cyberattack that manipulates DNS data to redirect users from legitimate websites to malicious destinations. By introducing fraudulent DNS information into the DNS resolution process, attackers can cause users to unknowingly connect to attacker-controlled websites, enabling phishing, malware delivery, credential theft, and other malicious activities.
Because DNS serves as the foundation for internet navigation, compromised DNS responses can undermine trust in online services and expose organizations and users to significant security risks.
{{anchor:How it works}}
How DNS poisoning works
DNS poisoning occurs when attackers successfully inject false DNS information into the DNS resolution process. As a result, DNS resolvers or devices return incorrect IP addresses for legitimate domains.
Common DNS poisoning techniques include:
- DNS cache poisoning – Inserting fraudulent records into a DNS resolver’s cache
- DNS spoofing – Sending forged DNS responses to redirect users
- Compromised DNS infrastructure – Manipulating DNS servers or configurations
- Malicious DNS services – Directing users to rogue DNS resolvers
- Host file manipulation – Altering local systems to resolve domains incorrectly
Once poisoned DNS information is accepted, users may be redirected to fraudulent websites that appear legitimate but are controlled by attackers.
{{anchor:Cache poisoning vs DNS poisoning}}
DNS poisoning vs. cache poisoning
While the terms are often used interchangeably, DNS cache poisoning is a specific type of DNS poisoning.
- DNS poisoning refers to the broader category of attacks that manipulate DNS resolution.
- DNS cache poisoning specifically targets cached DNS records stored by resolvers or devices.
Both techniques seek to redirect traffic away from legitimate destinations and toward attacker-controlled infrastructure.
{{anchor: Why it matters}}
Why DNS poisoning matters
Successful DNS poisoning attacks can result in:
- Credential theft and account compromise
- Phishing attacks and social engineering campaigns
- Malware infections
- Financial fraud
- Data breaches
- Loss of customer trust
- Operational disruption and reputational damage
Because users often have no visible indication that DNS responses have been manipulated, these attacks can remain highly effective and difficult to detect.
{{anchor: Reducing risk}}
Reducing DNS poisoning risk
Organizations can strengthen defenses against DNS poisoning by:
- Implementing DNSSEC to validate DNS responses
- Using trusted DNS providers
- Monitoring DNS activity for anomalies
- Securing DNS infrastructure and administrative access
- Applying software updates and security patches
- Limiting exposure to rogue DNS services
- Conducting regular DNS security reviews
{{anchor: How DigiCert helps}}
How DigiCert helps
DigiCert UltraDNS provides enterprise-grade authoritative DNS services designed to help organizations maintain secure, trusted, and highly available DNS infrastructure. UltraDNS supports DNSSEC, which helps protect against DNS poisoning by cryptographically validating DNS responses and ensuring users receive authentic DNS information from authoritative sources rather than manipulated or forged responses.