A DNS reflection attack is a type of distributed denial-of-service (DDoS) attack where an attacker uses spoofed IP addresses to trick open DNS resolvers into flooding a target with massive amounts of unwanted network traffic. The core trick is redirection: the resolver believes it’s replying to the party that asked the question, when in fact its answer is being “reflected” onto someone who never sent a request at all.
DNS Reflection DDoS and Source IP Spoofing
A DNS reflection DDoS attack depends on spoofed source IP DNS requests to redirect responses toward a victim. When those responses are also much larger than the original requests, the technique becomes a reflection amplification attack, combining source-address spoofing with traffic amplification to create a much larger DDoS flood than the attacker could generate directly.
How a DNS Reflection Attack Works
IP spoofing.
The attacker sends small DNS lookup requests to public, open DNS servers, but changes the source IP address in the packet to match the victim’s address rather than their own.
Reflection.
Because the DNS server has no way to verify that the claimed source address is genuine, it believes the request came from the victim and sends its reply directly there; the attacker never receives a response at all, and doesn’t need to.
Amplification.
Attackers typically request large zone files or specific query types (like ANY or TXT records) that generate responses far larger than the original request, multiplying the volume of traffic the victim receives on top of the redirection itself.
A Simple Analogy
Think of it like a prank call to a restaurant: the caller says “I’ll have one of everything, please call this number back and read me my whole order” but gives the restaurant someone else’s phone number. The restaurant, trying to be helpful, calls that other person back with a long, detailed order they never asked for. The restaurant did nothing wrong by its own rules; it just had no way to verify who was actually on the other end of the number it was given.
Why Reflection Is the Mechanism, and Amplification Is the Multiplier
It’s worth being precise about what reflection itself actually does, since it often gets blended with DNS amplification in casual use. Reflection is entirely about misdirecting a response using a forged source address so a reply goes somewhere the request never actually came from. On its own, reflection doesn’t require the response to be unusually large; a reflected attack using small, equally-sized responses is still possible, just far less effective.
Amplification is what makes reflection devastating rather than merely annoying, pairing the misdirection with a technique that inflates the response size by 28 to 54 times (or more) turns a modest number of spoofed requests into a flood large enough to take down serious infrastructure. Nearly every real-world DNS reflection attack also uses amplification, which is why the two are so often described as a single combined technique.
How to Prevent and Mitigate DNS Reflection Attacks
- Secure DNS servers against open recursion. Configure resolvers to answer recursive queries only from trusted internal networks, not from arbitrary requesters anywhere on the internet.
- Ingress filtering. ISPs should verify that outbound packets' source addresses are actually reachable via the path they're transmitted on, and drop anything that looks forged that directly targets the spoofing step reflection depends on.
- Response Rate Limiting (RRL). Limit how many identical or near-identical responses a DNS server will send within a given window, capping how much an attacker can extract from any single resolver.
- Route traffic through DDoS protection and Anycast networks. Scrubbing services distributed across many data centers can absorb reflected floods before they overwhelm a single target's own infrastructure, part of a broader DDoS mitigation strategy rather than a standalone fix.
The Resolver Does Exactly What It's Told By the Wrong Person
A DNS reflection attack works because open resolvers have no built-in way to verify that a request’s claimed source is genuine, and attackers exploit that gap to make someone else’s infrastructure do their flooding for them. The fix isn’t about making DNS resolvers less helpful it’s about closing the specific trust gap that lets a forged address go unchecked: verifying source addresses before they leave a network, restricting who’s allowed to ask a resolver for recursive answers, and rate-limiting how much any single source can extract. Reflection and amplification are usually discussed together because defending against one largely means defending against both.
Frequently Asked Questions (FAQ)
1. What is a characteristic of a DNS amplification and reflection attack?
The defining characteristic is the combination of a spoofed source address (so the response is misdirected to a victim) and a disproportionately large response relative to the original request (so that misdirected traffic is heavy enough to cause real disruption). Neither element alone is as damaging as the two working together.
2. What's the difference between reflection and amplification?
Reflection is about where a response goes, redirecting it to a spoofed address instead of the real sender. Amplification is about how big that response is inflating a small request into a much larger reply. Most real attacks use both, but they describe two separate mechanics within the same overall technique.
3. What are the different types of DNS hijacking attacks, and is reflection one of them?
Reflection is generally categorized separately from hijacking. Hijacking involves gaining actual control over DNS infrastructure, a server, router, or registrar account to redirect traffic deliberately. Reflection doesn’t require controlling anything; it exploits the fact that open resolvers will answer any request they receive without verifying who actually sent it.
4. What's a DNS poisoning attack, and how is it different from reflection?
DNS poisoning (cache poisoning) injects false data into a resolver’s cache so it returns a fraudulent answer to future, unrelated queries; the goal is misleading users about where a domain actually points. DNS reflection is a DDoS technique with a different goal entirely: overwhelming a victim’s network with volume, using the resolver as an unwitting traffic amplifier rather than trying to deceive anyone about a domain’s real address.
Secure DNS. Block threats before they spread.
Prevent DNS attacks, block malicious domains, and protect critical traffic without disrupting your online services.