What Is a DNS Amplification Attack?

A DNS amplification attack is a volumetric Distributed Denial of Service (DDoS) attack that exploits open DNS resolvers to flood a target network with a massive wave of unwanted traffic. Its defining trait is the mismatch it exploits: a tiny request can trigger a response dozens of times larger, letting an attacker with modest bandwidth generate an overwhelming flood.

Understand DNS threats. See Prophaze protect every query in real time.

How a DNS Amplification Attack Works

Spoofing the source.

The attacker sends small DNS lookup requests, often an “ANY” query, which asks for every record a DNS zone has to public, open DNS resolvers, forging the source IP address to match the victim’s address instead of their own.

Amplifying the response.

Because a small request can trigger a response 28 to 54 times larger (sometimes more), the resolver generates a disproportionately large reply to what it believes is a legitimate query.

Delivering the flood.

The resolver sends that oversized response to the forged address of the victim rather than back to the attacker, exhausting the victim’s bandwidth and potentially crashing the surrounding network infrastructure.

Key Characteristics

High amplification factor.

A small, cheap request multiplies into a heavy data flood, which is exactly what makes this attack economical for someone with limited resources of their own.

Built-in anonymity.

Because the source IP is spoofed, tracing the attack back to its actual origin is difficult; the resolver that sent the flood is an unwitting participant, not the attacker.

Exploits normal behavior, not a bug.

The attack relies on DNS resolvers doing exactly what they’re supposed to do, answering queries helpfully rather than any specific software vulnerability or breach.

Why Amplification and Reflection Get Mentioned Together Often

A DNS amplification DDoS attack typically combines two mechanisms: amplification describes the size problem, while reflection describes the direction of the traffic. This combination is sometimes called reflection amplification, because a spoofed DNS request causes an enlarged response to be reflected toward the victim.
Amplification describes the size problem of a small request producing a large response. It’s closely paired with DNS reflection, which describes the direction problem using a spoofed source address so that a large response goes to a victim instead of back to the sender. In practice, almost every real-world attack combines both: reflection gets the traffic pointed at the right target, and amplification makes sure that traffic is big enough to matter.
Sources often use the two terms interchangeably or as a single combined phrase (“DNS reflection/amplification attack”) for exactly this reason they’re two halves of the same mechanism rather than two separate attack types.

How to Prevent and Mitigate DNS Amplification Attacks

Disable open recursion.

Configure DNS servers so they don’t answer recursive queries from arbitrary, unauthorized clients on the internet and restrict recursive resolution to trusted internal networks only.

Response Rate Limiting (RRL).

Cap how many responses a DNS server will send to a single source within a given timeframe, slowing an attacker’s ability to generate a flood through any one resolver.

Ingress filtering at the ISP level.

Internet Service Providers can verify that outbound packets actually originate from the address range they claim, dropping forged-source packets before they ever leave the network; this is the single most effective structural fix, since it prevents the spoofing step the whole attack depends on.

Route through DDoS protection services.

An anti-DDoS service with enterprise-grade scrubbing and Anycast distribution can absorb and filter out volumetric traffic before it reaches the target’s own infrastructure.

Small Requests, Large Consequences

A DNS amplification attack doesn’t need a vulnerability to exploit, it needs an open resolver willing to do exactly what resolvers are built to do, and an attacker willing to lie about where the request came from. That combination is what makes the attack both cheap to run and genuinely difficult to stop once it’s underway, since legitimate DNS infrastructure is doing the actual flooding. The fix isn’t exotic: close open recursion, verify source addresses before they leave a network, and rate-limit responses three changes that, applied broadly across the internet’s DNS infrastructure, would make this entire attack class far less viable.

Frequently Asked Questions (FAQ)

1. What is an amplification attack, in general?
An amplification attack is any DDoS technique that exploits a protocol where a small request can trigger a disproportionately large response, then directs that oversized response at a victim using a spoofed source address. DNS is the most commonly abused protocol for this, but NTP and Memcached servers have been exploited the same way.
Yes. Launching a DDoS attack including a DNS amplification attack against a system you don’t own or have explicit authorization to test is illegal in most jurisdictions, typically prosecuted under computer fraud and abuse laws, regardless of the attacker’s stated motive.
Signs include a sudden, unexplained spike in inbound UDP traffic on port 53 from DNS resolvers you never queried, network bandwidth exhaustion with no corresponding increase in legitimate user activity, and from the resolver operator’s side a surge of outbound traffic responding to queries that were never actually requested by the destination.
Free, web-based tools from projects like the Open DNS Resolver Project and the Measurement Factory can scan a network range and identify open recursive resolvers that could be exploited. If your organization runs a DNS server, testing it against one of these tools and disabling open recursion if it’s found is a quick, high-value check.

Secure DNS. Block threats before they spread.

Prevent DNS attacks, block malicious domains, and protect critical traffic without disrupting your online services.

Recent Blog Posts

DNS Security Vendors India

Top 12 DNS Security Providers In India for 2026

Key Takeaways DNS security stops threats before a connection is made. NSA and CISA guidance

AI Security in Banking

AI Security in Banking: Protecting Customer Data, LLMs, and AI Applications

Key Takeaways AI security in banking is different from general AI security because model outputs

AI Security Guardrails

How Do AI Security Guardrails Protect RAG Pipelines?

Key Takeaways AI security guardrails are runtime controls between users, applications and LLMs. They work

Scroll to Top