Ignore DNS at your Peril

When organizations don’t leverage the power of DNS, they’re missing out on network security, visibility, etc. How can we convince executives they need DNS?

IT professional studying DNS architecture diagrams sketched on a whiteboard, planning network and cybersecurity strategy
Key Takeaways
  • Relying on default Microsoft DNS behavior within Active Directory leads many organizations to overlook a critical service whose failure can severely impact core operations such as call centers.
  • DNS is the foundational control plane for internal and external resource access, application-to-application communication, global load balancing, and is mandatory for Active Directory authentication to function.
  • Attackers have long exploited DNS for network reconnaissance and targeting, while many administrators treat DNS as a “set and forget” service, leaving visibility and security value untapped.
  • Properly configured DNS provides rich telemetry on where users and devices are connecting, enabling detection of compromised accounts or anomalous behavior patterns.
  • DNS firewalls and DNS-based security controls can block malicious domains at query time and correlate DNS with IP and DHCP data to identify who requested which IP and how it was used.
  • Integrated DNS, DHCP, and IP address management solutions add network-layer defenses with minimal end-user impact and favorable administrative overhead relative to their security benefit.

Learn more from Mathew Chase’s webinar on how busy IT executives can leverage DNS or read his thoughts on cybersecurity in our Cybersecurity Spotlight series.

It’s easy to ignore DNS.

Microsoft in particular has made it so. Microsoft DNS automatically deploys in the Active Directory environment, so you set up your servers and forget about it. And 90 percent of the time, it works.

But ‘90 percent of the time’ in a high-functioning IT organization is a horrible metric. When you actually do something important that is truly reliant upon DNS or DHCP, like run a call center, something that works 90 percent of the time is a huge problem.

DNS is the fundamental backplane of your network. It’s how everyone inside your organization accesses resources in and outside your network. All of your applications that have to talk to each other rely upon it. In complicated load balancing scenarios on a global network, DNS is crucial. And let’s not forget this important point: Active Directory doesn’t function without DNS. Period. All of your authentication systems for Microsoft components are built on underlying DNS records.

The people who have often best understood and paid attention to DNS are, unfortunately, primarily on the other side of the fence – hackers. In the early days, DNS was the quick way to conduct reconnaissance to map networks and identify hostnames and prime targets on a network. For many network administrators, DNS is just a means to an end: ‘I put in my DNS server and I’m done.’ That’s where their understanding of it frequently stops.

Ignoring DNS is something you do at your own peril.

When properly administered and configured, DNS yields very good information. It tells us what’s happening, where people are going and what they’re doing. In modern cybersecurity environments, we’re always concerned about a bad actor on our network. How do we determine when people are either compromised or acting in a way that is uncommon for them to act? DNS can provide valuable clues.

Every malicious web address starts with a DNS request. DNS firewalls are exceptionally good at disrupting these queries, whether through a threat feed or custom-built policies. DNS-based security also allows for visibility into the IP address space and DHCP, allowing network administrators to see who’s requesting IP addresses on the network and where they’re going with them.

Of course, any addition to the security stack begs the question of how it will be managed. Is the new solution going to take more people? How much more money is it going to cost me? And what’s my return on investment? Good solutions that can solve problems at a network level, and don’t require a lot of end user configuration, can really help improve your security posture. DNS, DHCP, and IP address management enterprise solutions provide that, along with all the reliability and redundancy required in stable operations. But from a security perspective, you gain network layer defenses with almost no impact to end users. The cost of administration to security benefit has always weighed in my favor.

Mathew Chase

Mathew most recently was vice president of IT for Inovalon, which provides cloud-based platforms and data analytics for the healthcare industry. He has deep experience with DNS and its implications for cybersecurity and other digital transformation initiatives. He got his start in IT in the mid-90’s at the Las Vegas Review-Journal, when he was pulled off his desktop publishing shift to help the newsroom become one of the first in the U.S. to produce their paper electronically. Career highlights include the IT operations manager for resident shows at Cirque du Soleil and the CIO for a U.S. government health insurance commission.


An avatar of the author

BlueCat provides core services and solutions that help our customers and their teams deliver change-ready networks. With BlueCat, organizations can build reliable, secure, and agile mission-critical networks that can support transformation initiatives such as cloud adoption and automation. BlueCat’s growing portfolio includes services and solutions for automated and unified DDI management, network security, multicloud management, and network observability and health.

Related content

Flock of geese flying in formation across a blue sky, framed by a pink graphic border, symbolizing coordinated network migrat

Automate your DDI modernization path by migrating with Micetro

Automate cross-platform DNS and DHCP migration with Micetro to reduce risk, eliminate manual effort, and modernize infrastructure faster.

Read more
Three armored figures walking toward a futuristic Las Vegas skyline with pyramids, glowing orb, and "Welcome to Fabulous Las

Your journey to intelligent NetOps begins at Cisco Live

Visit BlueCat’s booth or book a meeting now to learn more about how our solutions can help you build a network that supports constant change.

Read more
Stacked colorful wooden directional arrows on a post by a calm seaside with distant hills and blue sky

Replace BIND and ISC with Micetro DNS/DHCP Server (MDDS)

Tired of patching and manually configuring BIND DNS and ISC DHCP? Discover how Micetro MDDS appliances can replace them for modern DDI.

Read more
Row of orange industrial robotic arms positioned along an automated conveyor belt in a factory setting

Automate it all in Integrity with REST v2 API-first DDI management

Discover API-first DDI with Integrity X by using REST v2 to automate DNS, DHCP, and IPAM for scalable, secure network operations.

Read more