Industry-Leading DNS Auditing
The DNS Institute enables domain owners and DNS professionals to monitor and check
conformance and vulnerabilities of their DNS infrastructure, through scheduled
protocol tests,
vulnerability tests, alerts, news, and statistics with complete reporting.
Our DNS
auditing solutions enable organizations
to proactively identify and remediate DNS misconfigurations
and vulnerabilities, measure and manage risk,
and ensure accuracy and compliance with no to little additional
software or infrastructure costs.
The DNS Institute is a training, consulting, and documentation service
covering the Domain Name System and its security.
Our offerings include: automated DNS monitoring, DNS server and
client configuration reviews, custom DNS development, DNS server
installations, DNS server conformance and regression testing, DNS
zone data auditing, DNS vulnerability testing, server penetration
testing, DNSSEC deployments, DNS performance evaluations,
DNS courseware,
DNS installation and management instruction, DNS documentation,
and more.
Contact us for a demo or free evaluation.
Recent Research
-
Hijacking registered domains (2024-08)
Looking for "Sitting Ducks" domains where their delegations
point to authoritative DNS hosting services that no longer serve
for the domain.
-
Finding out-of-sync TLD nameservers (2024-05)
Looking at nameservers for 1448 TLDs to find zones
that possibly are out-of-date by comparing SOAs and RRSIGs.
-
DNS over IPv6 for Czech Republic Domains (2024-02)
An analysis of Czech Republic government domains indicated that around 22% of the domains had an IPv6 mistake related to DNS and 7% completely failed for DNS over IPv6.
-
DNSSEC Research for Largest 100 Banks (2022-12)
Twenty-eight of the top 100 global banks had at least one DNS domain
with DNSSEC.
Only 9.4% of the domains owned by the largest banks were DNSSEC signed.
The banks with the most DNSSEC-signed domains were
State Bank of India (26),
Skandinaviska Enskilda Banken AB (22), and
Svenska Handelsbanken AB (15).
-
SPF Record Problems (2022-05)
DNS Institute identified SPF (Sender Policy Framework)
problems in around 4.2% of domains.
-
SPF and Dangling DNS Targets (2022-05)
DNS Institute found over 80 SPF records that had policies using
currently non-existent domains which may be available for purchase
or assignment from domain resellers, brokers, squatters, registrars,
or subdomain hosting providers.
-
Top Ten Most Frequent Test Failures (2022-04)
We have ran over a third of a million test runs resulting in over
fifty-one million individual test results.
Some of the tests fail so frequently they can be considered just
unimportant noise — or are they?
-
Analyzing OpenNIC (2022-01)
Quick audit of over a thousand delegated domain names found under
the alternative DNS root OpenNIC identified tens of thousands of
issues (58 unique) including two expired TLDs. Interestingly, we
learned that many of the domains also used delegations under standard
DNS.
-
Summary of Audit of Top Ten Domains for Top TLDs (2021-10)
Highlights of the interesting problems from analyzing
the top domains for 62 most popular TLDs.
-
ASN and Network Prefixes for TLD Nameservers (2021-10)
Counts of different ASNs and network prefixes for each IPv4 nameserver
(from root server delegations) for all TLDs.
-
Running ancient 1990 BIND 4 on modern Internet
DNS standards still mostly working after 30 years.
This week-long study used a 386BSD port of 1990
4.3BSD-Reno's BIND named 4.8.3 with modern DNS
for recursive and authoritative services.
-
Russia Government Domains Analysis (2021-07)
Identified over 20,000 DNS anomalies from research of 500 Russian
Federation domains including very poor IPv6 and DNSSEC support,
many nameservers without EDNS support,
and several open resolvers.
-
Summary of Analysis for Single Top Ranked Domain for Each TLD
The most popular domain for many TLDs had interesting DNS problems.
-
Popularity Rankings for TLDs
Popularity Rankings table for 1200+ TLDs. The 10 most popular TLDs
from the Tranco top sites list are com, net, ru, org, info, in,
ir, uk, au, and de.
-
DNS over IPv6 Research 2020-11 for Fortune 500 Companies
129 Fortune 500 companies didn't have working DNS over IPv6.
-
TLD Delegation and Nameserver Failures (2020-09)
An analysis of 1508 top-level domain names found many interesting
and even critical problems in at least 20 TLDs, including DNSSEC
failures.
-
DNS Nameserver Counts for Top Million Websites (2020-08)
The most popular NS nameserver domain name was
cloudflare.com.
-
DNS Mistakes (Part 2): Lots of Typos
More mistakes often caused by typos, copy-and-paste issues, or
misunderstandings for what is allowed in DNS.
Random Recent DNS Checks