DNS Security
DNS Security is the set of protective measures around the Domain Name System (DNS), which resolves domain names into IP addresses. It covers both securing name resolution itself and using DNS queries as an early control point against malicious destinations.
Three approaches are distinguished. Protective DNS filters queries on the basis of reputation data and blocks the resolution of known malware, phishing or command-and-control domains before a connection is established. DNSSEC secures the authenticity of DNS responses through digital signatures and protects against manipulated entries. Encrypted methods such as DNS over HTTPS (DoH) and DNS over TLS (DoT) prevent queries from being read, but can bypass company DNS controls if they are not centrally managed.
In addition, DNS security detects abuse patterns such as DNS tunneling, in which data flows out hidden in DNS queries, or algorithmically generated domains through which malware contacts attackers. In security service edge architectures, DNS filtering is frequently part of the Secure Web Gateway (SWG). DNS security complements IT Security with a protective layer that takes effect even before a connection is established.