# What is DNS Hijacking?

> Domain Name System (DNS) hijacking is unauthorized takeover or alteration of DNS administration, delegation, authoritative data, resolver selection, or network or device configuration so queries use attacker-chosen infrastructure or records.

- Canonical URL: https://yellowcube.eu/glossary/domain-name-system-hijacking/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It can involve a registrar account, a zone or delegation, an authoritative name server, compromised resolver administration, a router, or an endpoint setting. The affected layer determines whether redirection reaches one device, one network, or users of a domain more broadly.

Compromise can enable interception, credential theft, malware delivery, email diversion, or denial of service while the intended destination remains intact.

### Key points

- **Affected layers:** Determine whether control changed at the registrar, registry, authoritative zone, hosting provider, resolver, network configuration, or endpoint; recovery authority and scope differ at each layer.
- **Evidence:** Review registration and DNS audit history, record changes, administrator sessions, resolver configuration, certificate issuance, independent query results, and downstream identity or endpoint events.
- **Response:** Secure administrative accounts through known-good channels, coordinate with providers, restore verified records and settings, revoke exposed access, and assess traffic, email, credentials, and data that may have been redirected.
- **Important limitation:** An unexpected DNS answer is not proof of hijacking. Content delivery, geographic routing, split or Dynamic DNS, caching, failover, local policy, and errors can produce legitimate differences; establish the expected authority and the unauthorized change.

### Related terms

[Domain Name System (DNS)](<https://yellowcube.eu/glossary/domain-name-system/>) · [Domain Name System (DNS) security](<https://yellowcube.eu/glossary/domain-name-system-security/>) · [Domain Name System (DNS) cache poisoning](<https://yellowcube.eu/glossary/domain-name-system-cache-poisoning/>) · [Dynamic DNS (DDNS)](<https://yellowcube.eu/glossary/dynamic-dns/>) · [Pharming](<https://yellowcube.eu/glossary/pharming/>)

### Sources

[NIST SP 800-81 Rev. 3: Secure DNS Deployment Guide](https://csrc.nist.gov/pubs/sp/800/81/r3/final) · [CISA Advisory AA19-024A: DNS Infrastructure Hijacking Campaign](https://www.cisa.gov/news-events/cybersecurity-advisories/aa19-024a) · [ICANN SSAC SAC040: Measures to Protect Registration Services Against Misuse](https://www.icann.org/en/groups/ssac/documents/sac-040-en.pdf)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

