What Is a DNS Reflection Attack?

A DNS reflection attack is a type of distributed denial-of-service (DDoS) attack where an attacker uses spoofed IP addresses to trick open DNS resolvers into flooding a target with massive amounts of unwanted network traffic. The core trick is redirection: the resolver believes it’s replying to the party that asked the question, when in fact its answer is being “reflected” onto someone who never sent a request at all.

Understand DNS threats. See Prophaze protect every query in real time.

DNS Reflection DDoS and Source IP Spoofing

A DNS reflection DDoS attack depends on spoofed source IP DNS requests to redirect responses toward a victim. When those responses are also much larger than the original requests, the technique becomes a reflection amplification attack, combining source-address spoofing with traffic amplification to create a much larger DDoS flood than the attacker could generate directly.

How a DNS Reflection Attack Works

IP spoofing.

The attacker sends small DNS lookup requests to public, open DNS servers, but changes the source IP address in the packet to match the victim’s address rather than their own.

Reflection.

Because the DNS server has no way to verify that the claimed source address is genuine, it believes the request came from the victim and sends its reply directly there; the attacker never receives a response at all, and doesn’t need to.

Amplification.

Attackers typically request large zone files or specific query types (like ANY or TXT records) that generate responses far larger than the original request, multiplying the volume of traffic the victim receives on top of the redirection itself.

A Simple Analogy

Think of it like a prank call to a restaurant: the caller says “I’ll have one of everything, please call this number back and read me my whole order” but gives the restaurant someone else’s phone number. The restaurant, trying to be helpful, calls that other person back with a long, detailed order they never asked for. The restaurant did nothing wrong by its own rules; it just had no way to verify who was actually on the other end of the number it was given.

Why Reflection Is the Mechanism, and Amplification Is the Multiplier

It’s worth being precise about what reflection itself actually does, since it often gets blended with DNS amplification in casual use. Reflection is entirely about misdirecting a response using a forged source address so a reply goes somewhere the request never actually came from. On its own, reflection doesn’t require the response to be unusually large; a reflected attack using small, equally-sized responses is still possible, just far less effective.
Amplification is what makes reflection devastating rather than merely annoying, pairing the misdirection with a technique that inflates the response size by 28 to 54 times (or more) turns a modest number of spoofed requests into a flood large enough to take down serious infrastructure. Nearly every real-world DNS reflection attack also uses amplification, which is why the two are so often described as a single combined technique.

How to Prevent and Mitigate DNS Reflection Attacks

The Resolver Does Exactly What It's Told By the Wrong Person

A DNS reflection attack works because open resolvers have no built-in way to verify that a request’s claimed source is genuine, and attackers exploit that gap to make someone else’s infrastructure do their flooding for them. The fix isn’t about making DNS resolvers less helpful it’s about closing the specific trust gap that lets a forged address go unchecked: verifying source addresses before they leave a network, restricting who’s allowed to ask a resolver for recursive answers, and rate-limiting how much any single source can extract. Reflection and amplification are usually discussed together because defending against one largely means defending against both.

Frequently Asked Questions (FAQ)

1. What is a characteristic of a DNS amplification and reflection attack?
The defining characteristic is the combination of a spoofed source address (so the response is misdirected to a victim) and a disproportionately large response relative to the original request (so that misdirected traffic is heavy enough to cause real disruption). Neither element alone is as damaging as the two working together.
Reflection is about where a response goes, redirecting it to a spoofed address instead of the real sender. Amplification is about how big that response is inflating a small request into a much larger reply. Most real attacks use both, but they describe two separate mechanics within the same overall technique.
Reflection is generally categorized separately from hijacking. Hijacking involves gaining actual control over DNS infrastructure, a server, router, or registrar account to redirect traffic deliberately. Reflection doesn’t require controlling anything; it exploits the fact that open resolvers will answer any request they receive without verifying who actually sent it.
DNS poisoning (cache poisoning) injects false data into a resolver’s cache so it returns a fraudulent answer to future, unrelated queries; the goal is misleading users about where a domain actually points. DNS reflection is a DDoS technique with a different goal entirely: overwhelming a victim’s network with volume, using the resolver as an unwitting traffic amplifier rather than trying to deceive anyone about a domain’s real address.

Secure DNS. Block threats before they spread.

Prevent DNS attacks, block malicious domains, and protect critical traffic without disrupting your online services.

Recent Blog Posts

DNS Security Vendors India

Top 12 DNS Security Providers In India for 2026

Key Takeaways DNS security stops threats before a connection is made. NSA and CISA guidance

AI Security in Banking

AI Security in Banking: Protecting Customer Data, LLMs, and AI Applications

Key Takeaways AI security in banking is different from general AI security because model outputs

AI Security Guardrails

How Do AI Security Guardrails Protect RAG Pipelines?

Key Takeaways AI security guardrails are runtime controls between users, applications and LLMs. They work

Scroll to Top