Glossary
Multicast DNS (mDNS) amplification DDoS
A multicast DNS (mDNS) amplification DDoS attack is a denial-of-service technique that exploits vulnerable or misconfigured devices running the mDNS protocol to generate amplified traffic toward a target. By sending small requests that trigger significantly larger responses, attackers can overwhelm networks, applications, or infrastructure with malicious traffic while using relatively few resources themselves.
Because mDNS is commonly enabled on printers, IoT devices, servers, and other network-connected systems, improperly configured devices can be exploited without their owners’ knowledge.
{{anchor:How it works}}
How mDNS amplification attacks work
mDNS was designed to simplify device discovery on local networks by allowing systems to automatically find and communicate with one another without a dedicated DNS server.
Attackers exploit this protocol by:
- Identifying devices that respond to external mDNS requests
- Sending spoofed mDNS queries that appear to originate from a victim
- Triggering large responses from vulnerable devices
- Amplifying traffic volumes directed at the target
- Using many devices simultaneously to increase attack scale
Because the response can be substantially larger than the original request, attackers can generate significant traffic amplification and disrupt targeted services.
{{anchor:Why it matters}}
Why mDNS amplification matters
mDNS amplification attacks can create serious operational and business impacts, including:
- Network congestion and service outages
- Application downtime and degraded performance
- Lost revenue and productivity
- Increased operational and remediation costs
- Damage to customer trust and brand reputation
- Potential legal and compliance exposure
Organizations may also unknowingly participate in attacks if vulnerable devices within their environments are abused as amplification sources.
{{anchor:Prevention}}
Reducing mDNS amplification risk
Organizations can reduce exposure by implementing security best practices such as:
- Blocking unnecessary UDP traffic on port 5353
- Disabling mDNS services where not required
- Keeping device firmware and software up to date
- Segmenting networks to limit service exposure
- Monitoring for abnormal mDNS activity
- Auditing network-connected devices regularly
- Implementing ingress filtering and source validation controls
A proactive approach to device and network security can significantly reduce the risk of mDNS-based amplification attacks.
{{anchor:How DigiCert helps}}
How DigiCert can help
DigiCert UltraDNS provides a resilient, enterprise-grade DNS foundation designed to help organizations maintain availability and performance during periods of elevated traffic and attack activity. Built on a globally distributed Anycast architecture, UltraDNS delivers fault tolerance, intelligent traffic management, and enterprise-grade resilience to support business continuity and reduce downtime risk.