It can involve a registrar account, a zone or delegation, an authoritative name server, compromised resolver administration, a router, or an endpoint setting. The affected layer determines whether redirection reaches one device, one network, or users of a domain more broadly.
Compromise can enable interception, credential theft, malware delivery, email diversion, or denial of service while the intended destination remains intact.
Key points
Affected layersDetermine whether control changed at the registrar, registry, authoritative zone, hosting provider, resolver, network configuration, or endpoint; recovery authority and scope differ at each layer.
EvidenceReview registration and DNS audit history, record changes, administrator sessions, resolver configuration, certificate issuance, independent query results, and downstream identity or endpoint events.
ResponseSecure administrative accounts through known-good channels, coordinate with providers, restore verified records and settings, revoke exposed access, and assess traffic, email, credentials, and data that may have been redirected.
Important limitationAn unexpected DNS answer is not proof of hijacking. Content delivery, geographic routing, split or Dynamic DNS, caching, failover, local policy, and errors can produce legitimate differences; establish the expected authority and the unauthorized change.