What Is a DNS Flood Attack?

A DNS flood attack is a type of distributed denial-of-service (DDoS) attack that overwhelms a domain’s DNS servers with a massive volume of requests to crash the server or block legitimate users. Where DNS amplification relies on a small number of spoofed requests tricking open resolvers into generating oversized responses, a DNS flood is more direct: a botnet simply sends an overwhelming number of queries straight at the target, exhausting its resources through sheer volume rather than clever multiplication.

Understand DNS threats. See Prophaze protect every query in real time.

How a DNS Flood Works

Attackers use botnets networks of compromised computers or IoT devices to send millions of DNS queries simultaneously to a specific target’s servers. The resulting influx overloads the server’s CPU, memory, and bandwidth, making it slow to respond or entirely unresponsive to legitimate users trying to resolve that domain. Because the queries can look like real requests for real records, a flood is often difficult to distinguish from an unusually large spike in legitimate traffic which is part of what makes mitigation harder than simply blocking obviously malformed packets.

DNS Flooding as a Volumetric DDoS Attack

A DNS flooding DDoS attack is a type of volumetric DNS attack that overwhelms DNS infrastructure with an excessive volume of queries. One common form is a DNS query flood, where attackers send large numbers of DNS requests to exhaust server resources and reduce the capacity available for legitimate users. Unlike DNS amplification, which multiplies traffic through third-party resolvers, DNS flooding relies primarily on the sheer volume of requests reaching the target.

Common Types of DNS Floods

DNS query flood.

A high volume of legitimate-looking queries for real records on a domain, hard to separate from normal heavy traffic because each individual request looks valid.

NXDOMAIN attack (water torture).

Instead of real records, the attacker floods a server with queries for randomized, non-existent subdomains. Because these queries can’t be answered from cache, every single one forces the authoritative server to do fresh computational work, exhausting its resources even though the actual traffic volume may look modest.

DNS amplification/reflection.

A related but distinct technique covered in its own entries is small, spoofed queries sent to open resolvers, which then flood the victim with oversized responses rather than the attacker sending the flood directly.

Why Flood and Amplification Attacks Differ

Both are DDoS techniques that target DNS infrastructure, but the underlying mechanics and the right defenses differ meaningfully. A flood is a symmetric attack: the attacker (or their botnet) generates roughly as much traffic as the victim receives, exhausting the target’s server-side resources (CPU, memory) directly. Amplification is asymmetric: a small amount of attacker-generated traffic gets multiplied by exploiting a third party (an open resolver), so the victim receives far more traffic than the attacker ever actually sent. This distinction matters operationally, rate limiting and resolver hardening are the primary defenses against amplification, since they target the multiplication step, while flood defenses need to focus on absorbing and filtering raw volume at scale, since there’s no “multiplier” step to interrupt.

Key Mitigation Strategies

Rate limiting.

Restrict the number of DNS queries accepted from a single source IP within a given timeframe, prioritizing legitimate request patterns over bulk automated traffic.

Anycast DNS.

Distribute DNS traffic across multiple geographically diverse servers so a flood’s impact is spread thin rather than concentrated on a single point of failure.

Response caching.

Configure recursive resolvers to cache valid responses longer, reducing how often the authoritative server needs to process repeat queries though this needs to be paired with rate limiting, since caching alone does nothing against an NXDOMAIN flood that deliberately avoids ever hitting the cache.

Behavioral analysis.

Deploy DDoS protection tooling that uses heuristic pattern detection to spot and block malicious query patterns in real time, rather than relying solely on static thresholds.

Volume Is the Weapon, Regardless of How It's Generated

A DNS flood attack doesn’t need a clever trick to work, it just needs enough raw traffic to overwhelm whatever’s on the receiving end, whether that traffic comes directly from a botnet or gets multiplied through an exploited third-party resolver. Treating “flood” as a single category misses the operational distinction that actually matters: a direct, symmetric flood needs absorption and filtering at scale, while an amplification-based flood needs the multiplication step itself interrupted, closer to the source. Effective DNS DDoS defense generally needs both approaches layered together, since attackers switch between techniques based on whatever infrastructure happens to be available to abuse.

Frequently Asked Questions (FAQ)

1. What is a DNS flood attack, in simple terms?
It’s a DDoS attack that targets DNS servers directly with an overwhelming volume of query traffic, aiming to exhaust the server’s resources so it can no longer answer requests from real users effectively making every website and service that depends on that DNS infrastructure unreachable.
Amplification is a reflection-based technique: small, spoofed requests sent to open resolvers generate oversized responses aimed at a victim. Water torture (NXDOMAIN) is a direct flood technique: an attacker sends queries for random, non-existent subdomains straight at an authoritative server, forcing it to do expensive, uncacheable lookup work on every single request. Both are DNS-based DDoS methods, but amplification multiplies traffic through a third party, while water torture exhausts a server’s own computation directly.
Rate limiting caps how many queries a DNS server will process from any single source within a given window, which prevents one botnet node or one misbehaving client from monopolizing server resources. It doesn’t stop a flood distributed across thousands of different sources on its own, which is why it’s typically combined with Anycast distribution and behavioral filtering rather than used alone.
Open resolvers will answer DNS queries from anyone on the internet, not just trusted internal clients, which makes them a reusable tool for attackers running amplification and reflection attacks against third parties. An organization running an accidentally open resolver isn’t just risking its own security, it can become an unwitting participant in attacks against someone else entirely.

Secure DNS. Block threats before they spread.

Prevent DNS attacks, block malicious domains, and protect critical traffic without disrupting your online services.

Recent Blog Posts

DNS Security Vendors India

Top 12 DNS Security Providers In India for 2026

Key Takeaways DNS security stops threats before a connection is made. NSA and CISA guidance

AI Security in Banking

AI Security in Banking: Protecting Customer Data, LLMs, and AI Applications

Key Takeaways AI security in banking is different from general AI security because model outputs

AI Security Guardrails

How Do AI Security Guardrails Protect RAG Pipelines?

Key Takeaways AI security guardrails are runtime controls between users, applications and LLMs. They work

Scroll to Top