Glossary
DNS Spoofing
DNS is like the phone book of the internet - it translates website names to addresses. DNS spoofing poisons this phone book so when you ask for 'bank.com', you get sent to a fake site instead. You typed the right address but ended up in the wrong place.
What is DNS Spoofing?
An attack that corrupts DNS cache data to redirect users to malicious websites, even when they type the correct URL.
Why Should You Care?
DNS spoofing enables attackers to intercept traffic destined for legitimate services and redirect users to credential-harvesting sites or malware distribution platforms, bypassing URL validation since the victim's browser will trust the spoofed DNS response. Organizations are particularly vulnerable when users access internal services or critical web applications, as attackers can hijack email authentication records (MX records) to intercept password resets or business communications, and compromise cloud infrastructure traffic by poisoning DNS queries for service endpoints.
Is your business exposed?
Real-World Example
An attacker who can poison DNS responses on a local network can redirect a user who types the correct banking or webmail URL to an attacker-controlled lookalike site, because the DNS query resolves to the attacker's IP address. The victim sees the expected address bar yet lands on a fake login page that harvests their credentials—demonstrating how DNS spoofing defeats the user's ability to verify legitimacy through URL inspection alone. Protocols like DNSSEC and encrypted DNS exist specifically to mitigate this class of attack.
How to Protect Against DNS Spoofing
- 1.
Use DNS providers with DNSSEC support
- 2.
Implement DNS over HTTPS (DoH)
- 3.
Monitor for unusual DNS traffic
Related Terms
Is your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required