Skip to main content
Network & InfrastructureUpdated September 3, 2026

DNS (Domain Name System)

The Domain Name System translates human-readable domain names (like ismalicious.com) into IP addresses. DNS data is a rich source of threat intelligence — malicious domains, fast-flux networks, DNS tunneling, and typosquatting are all detectable via DNS analysis.

DNS is the directory that turns names into addresses. A client asks a resolver for a name; the resolver walks from the root servers to the top-level domain to the authoritative nameserver and returns a record: an A or AAAA record for an address, MX for mail, NS for delegation, TXT for everything else, CNAME for an alias.

Almost every attack touches DNS at least once, because malware, phishing pages and command servers are reached by name. That makes the protocol both an attack surface and a vantage point: attackers register look-alike names, rotate addresses under a name, tunnel data in TXT queries; defenders see all of it in resolver logs.

For threat intelligence, DNS is where the durable indicators live. Addresses change hourly; a registered name persists, carries a registration date, a registrar and a nameserver history, and can be blocked at the resolver before a single connection is made.

Example

A resolver log shows one workstation querying a 24-character random-looking hostname every 60 seconds. The name has no history, was registered yesterday, and resolves to a known C2 address. The query pattern alone identified the infection.

In isMalicious

Every domain report on isMalicious resolves the current records, shows the nameservers and registration data, and lists the addresses the name has resolved to over time, so the DNS facts an analyst needs are on one page.

Frequently Asked Questions

What is DNS (Domain Name System)?

The Domain Name System translates human-readable domain names (like ismalicious.com) into IP addresses. DNS data is a rich source of threat intelligence — malicious domains, fast-flux networks, DNS tunneling, and typosquatting are all detectable via DNS analysis.

How is DNS (Domain Name System) related to DNS History?

DNS (Domain Name System) and DNS History are both key concepts in threat intelligence. DNS history is a record of historical DNS resolution data for a domain — including all IP addresses it has ever resolved to, when changes occurred, and what nameservers have been used. It is used in threat investigations to trace infrastructure reuse and identify related malicious domains.

Related Terms

Put this intelligence to work

Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.

Check any indicator free
← Back to Glossary