You need to enable JavaScript to use the communication tool powered by OpenWidget

What Is DNS Amplification?

DNS Amplification — a reflection DDoS technique that sends small DNS queries with a victim's spoofed source address to elicit much larger responses toward the victim.

The attack exploits trust in DNS, caching behavior, or the size difference between queries and responses. Mitigation requires a combination of DNSSEC validation, restricted recursion, source-address filtering, rate controls, and resilient infrastructure.

New from NIC.UA: a powerful AI website builder

Popular Questions About DNS Amplification

  • What does DNS Amplification mean?

    DNS Amplification — a reflection DDoS technique that sends small DNS queries with a victim's spoofed source address to elicit much larger responses toward the victim.

  • How does the attack work?

    An attacker attempts to forge a DNS answer, place false data in a cache, or use DNS servers to amplify traffic toward a victim. The exact technique depends on the attack type.

  • How can the risk be reduced?

    Disable open recursion, keep DNS software updated, use DNSSEC validation where applicable, limit abusive queries and responses, deploy source-address filtering, and monitor anomalous traffic.

  • Helpful articles

    • Glossary

      • Latest news & promotions

          Loading…