Don’t take your DNS service for granted

DNS failures can put your business in jeopardy

Cybercriminals are increasingly targeting the DNS as part of their attack methodology. A successful takeover of a DNS infrastructure provides the attacker unlimited opportunities to manipulate the domain content to further increase the chances of a successful attack against its target infrastructure.

Without proper monitoring, unauthorised changes to domain content and even complete DNS failures can go unnoticed for long periods of time with serious consequences.

The DNS is one of your most important assets. It’s time to stop neglecting it!

DNSmonitor is a subscription-based service that continuously monitors the Availability and Integrity of your domain and its DNS servers.

With focus areas such as Integrity, Availability, DNSSEC and Mail, DNSmonitor provides a flexible and versatile tool for monitoring your public DNS infrastructure.

Integrity

Monitor zone data correctness to ensure that every monitored record is routed to the intended target and scans the DNS configuration for obvious data leaks.

Availability

Monitor that the zones are available and can respond to queries on all public DNS servers.

DNSSEC

Monitor that signed records are validated correctly and that the DNSSEC settings are implemented according to established standards.

Mail/Spam

Monitor that mail routing is working as intended and that mail policing records are present and unaltered.

Why monitor DNS?

All IT systems and services need to be monitored. We all know that systems may go down and services can stop working for seemingly no reason at all, and that is before we take into account the threats of hackers having a go at your systems. Monitoring Internet-facing systems is important from both an availability and a security standpoint.

Critical Internet-facing systems such as the DNS, need monitoring of both its availability and, more important, its data integrity. This sounds obvious enough, but the majority of the DNS servers on the Internet lack adequately monitoring. This article describes why.

Why monitor DNS?

All IT systems and services need to be monitored. We all know that systems may go down and services can stop working for seemingly no reason at all, and that is before we take into account the threats of hackers having a go at your systems. Monitoring Internet-facing systems is important from both an availability and a security standpoint.

Critical Internet-facing systems such as the DNS, need monitoring of both its availability and, more important, its data integrity. This sounds obvious enough, but the majority of the DNS servers on the Internet lack adequately monitoring. This article describes why.

Cyber attacks targeting civilian infrastructure are increasing at an alarming rate. These attacks cause disruptions to a wide range of everyday services which in aggregate are becoming very costly.

The number DNS-based attacks have steadily increased over the past few years, and the threat actors are targeting a wider range of industries than they did a few years ago. This is one of the reasons why many organisations are starting to recognise the importance of including the DNS as part of their overall security strategy.

Digital interface displaying "DNS" surrounded by icons representing web and network functions, emphasizing DNS security, monitoring, and surveillance.

DNS Threats

When the DNS was designed in the early 80’s the focus was on building a reliable and functional application. Security didn’t become a real issue until the Internet became everyone’s property. It is safe to say that the DNS has played security catch-up since then.

Threats to the DNS can be divided into four distinct categories, each with its own unique characteristics and challenges.

All these categories but the last are very difficult to detect. In this article series we will delve deeper into each category and unravel what they’re all about.

A digital screen displaying a warning message that reads "System HACKED" within a yellow triangle, surrounded by lines of code and various data visualizations, highlighting themes of DNS security, DNS monitoring and cyber attack prevention.

Attack Impact

Frequent and costly DNS attacks have become a real threat to organisations across the globe. Attacks are occurring across all industries and affecting day-to-day operations.In 2023, the average cost of a DNS attack was USD 1.1m. With an average of 7.5 attacks per year, the financial effects rapidly becomes significant. Not only do these attacks cause finacial damage, they can also result in rputational damage, loss of customers, and compromise of intellectual property.

According to the 2023 IDC Global DNS Threat Report, 73% of the survey respondents experienced application downtime, both in the cloud and on-premises, as a result of DNS attacks. Loss of access to these often critical resources affects employees, customers and partners alike. Of the 1.000 survey respondents, 900 of them, or 90%, had experienced one or more DNS attacks during 2023.

Our summary of the report is available here.

A hand is reaching towards a digital interface displaying various icons related to technology, prominently featuring the term "DNS" in a bright, bold font. The background is a gradient of dark blue tones, and the interface includes hexagonal shapes with symbols representing servers, the internet, and cloud computing, emphasizing themes of DNS security, monitoring, and surveillance.

What is DNS?

The DNS play an extremely critical role on the Internet. The most well-known service it provides is to translate human-readable domain names (e.g. web addresses) into machine-readable IP addresses, so you and your computer can reach the desired website or Internet service.

DNS is also utilised for a number of perhaps less well-known but equally important services:

  • Mail routing, spam control and mitigation,
  • Certificate issuer control,
  • Enhancing web security,
  • and several other lesser known but equally important services.

In short, if the DNS service breaks down much of the Internet would stop working.

DNS Threats

When the DNS was designed in the early 80’s the focus was on building a reliable and functional application. Security didn’t become a real issue until the Internet became everyone’s property. It is safe to say that the DNS has played security catch-up since then.

Threats to the DNS can be divided into four distinct categories, each with its own unique characteristics and challenges.

All these categories but the last are very difficult to detect. In this article series we will delve deeper into each category and unravel what they’re all about.

Attack Impact

Frequent and costly DNS attacks have become a real threat to organisations across the globe. Attacks are occurring across all industries and affecting day-to-day operations. In 2023, the average cost of a DNS attack was USD 1.1m. With an average of 7.5 attacks per year, the financial effects rapidly becomes significant. Not only do these attacks cause financial damage, they can also result in reputational damage, loss of customers, and compromise of intellectual property.

According to the 2023 IDC Global DNS Threat Report, 73% of the survey respondents experienced application downtime, both in the cloud and on-premises, as a result of DNS attacks. Loss of access to these often critical resources affects employees, customers and partners alike. Of the 1.000 survey respondents, 900 of them, or 90%, had experienced one or more DNS attacks during 2023.

Our summary of the report is available here.

What is DNS?

The DNS play an extremely critical role on the Internet. The most well-known service it provides is to translate human-readable domain names (e.g. web addresses) into machine-readable IP addresses, so you and your computer can reach the desired website or Internet service.

DNS is also utilised for a number of perhaps less well-known but equally important services:

  • Mail routing, spam control and mitigation,
  • Certificate issuer control,
  • Enhancing web security,
  • and several other lesser known but equally important services.

In short, if the DNS service breaks down much of the Internet would stop working.

Plans & Packages

A plan is selected for each individual domain that is added to the monitoring dashboard. After the initial setup is completed, each individual plan can be modified with packages (the Basic plan), additional monitoring locations and Resource record checks to customise what is monitored on each individual domain.

Basic

The Basic plan is our entry-level monitor scheme that runs a fixed set of checks every 5 minutes and compile them into one Integrity and one Availability metric.

The Basic plan can be customised by adding monitoring packages and additional resource records to suit every requirement.

  • Availability package (optional)
  • Integrity package (optional)
  • Mail package (optional)
  • DNSSEC package (optional)

Premium

The Premium plan is suitable for monitoring the primary domains in a domain portfolio that require full attention.

The Premium plan can be customised by adding additional resource records to suit every requirement.

  • Availability package included
  • Integrity package included
  • Mail package included
  • DNSSEC package included

Sign up to DNSmonitor

We provide our subscribers with continuous monitoring of the integrity and availability of their domains and DNS servers.

Q&A

Q: Can I use DNSmonitor for free?

A: Yes. you can monitor up to three domains in free mode. Read more about Free mode and its limitations here.

Q: Do we need to do any configuration on our part like open ports in our firewall and/or install any additional software?

A: No. Our service utilises the standard DNS service ports, so no configuration changes is required.

Q: Can you monitor our internal DNS servers?

A: No. The DNSmonitor service can only be used on public DNS servers.

Q: Is there alternatives to use your Dashboard?

A: Yes. You can download monitoring data through our API.

DNS Articles

DNS’ importance for SEO performance – part 2

DNS’ importance for SEO performance – part 2

In the first blogpost in this series, the focus was on why the Domain Name System (DNS) is a critical but often overlooked component of technical SEO.

DNS is positioned as the infrastructure layer that supports website speed, availability, accessibility, and crawl efficiency, and as a key factor in how search engines evaluate reliability and user experience. Building on that foundation, this second part moves from configuration and theory to real-world impact.

This second blogpost examines how DNS performance affects SEO in practice, beginning with its role in loading speed and search performance. From the first DNS lookup to page rendering and crawl behaviour, DNS performance directly shapes how both users and search engines experience a website. Together, the two posts provide a complete view of DNS as a strategic asset for long-term SEO success.

read more
DNS’ importance for SEO performance – part 1

DNS’ importance for SEO performance – part 1

We will explore, in a two-part series blogposts, the relationship between DNS and SEO and how optimising DNS can support stronger search performance on your website. In this first post, we focus on the fundamentals: why DNS matters for SEO, briefly on how DNS works and what SEO is, and how DNS settings form a critical part of a website’s technical SEO foundation. Together, the two posts provide a complete view of DNS as a strategic asset for long-term SEO success.

read more
Securing email in DNS – part 1

Securing email in DNS – part 1

This is the first part of a planned article series in three parts about how the DNS is instrumental in elevating the security for the email service. In this series we will cover how to counter spam with SPF, DKIM and DMARC records and continue with securing email transfer with certificate-signed TLS transfers using MTA-STS, TLSA and DANE.

read more
DNS’ importance for SEO performance – part 2

DNS’ importance for SEO performance – part 2

In the first blogpost in this series, the focus was on why the Domain Name System (DNS) is a critical but often overlooked component of technical SEO.

DNS is positioned as the infrastructure layer that supports website speed, availability, accessibility, and crawl efficiency, and as a key factor in how search engines evaluate reliability and user experience. Building on that foundation, this second part moves from configuration and theory to real-world impact.

This second blogpost examines how DNS performance affects SEO in practice, beginning with its role in loading speed and search performance. From the first DNS lookup to page rendering and crawl behaviour, DNS performance directly shapes how both users and search engines experience a website. Together, the two posts provide a complete view of DNS as a strategic asset for long-term SEO success.

read more
DNS’ importance for SEO performance – part 1

DNS’ importance for SEO performance – part 1

We will explore, in a two-part series blogposts, the relationship between DNS and SEO and how optimising DNS can support stronger search performance on your website. In this first post, we focus on the fundamentals: why DNS matters for SEO, briefly on how DNS works and what SEO is, and how DNS settings form a critical part of a website’s technical SEO foundation. Together, the two posts provide a complete view of DNS as a strategic asset for long-term SEO success.

read more