Unlike phishing, it need not persuade the user to follow a deceptive message or mistyped link; the user may enter the correct address and still be redirected.
Redirection can result from modified endpoint settings, compromised routers or resolvers, poisoned Domain Name System (DNS) caches, or unauthorized changes to domain registration or authoritative DNS data. The destination may imitate a sign-in or payment service to capture information or deliver malicious content.
Key points
Affected layerCompare results across trusted resolvers, networks, and devices; inspect endpoints, routers, resolvers, registrars, and authoritative DNS rather than assuming every redirect has the same cause.
Response and evidenceStop sensitive transactions, preserve DNS answers, timestamps, certificates, and destinations, and contact the relevant service, DNS operator, or registrar through trusted channels.
Defensive layersSecure registrar and DNS administration, network equipment, and endpoints; monitor DNS changes, validate DNS Security Extensions (DNSSEC) where supported, and use certificate validation and protective DNS.
Important limitationDNSSEC authenticates signed DNS data but cannot prevent endpoint, router, registrar, or authoritative-account compromise. Encrypted DNS protects the client-to-resolver transport; Hypertext Transfer Protocol Secure (HTTPS) certificate validation can reveal certificate/name mismatches, but neither establishes that a destination is legitimate or covers every redirection path.