Ignore DNS at your Peril

When organizations don’t leverage the power of DNS, they’re missing out on network security, visibility, etc. How can we convince executives they need DNS?

IT professional studying DNS architecture diagrams sketched on a whiteboard, planning network and cybersecurity strategy
Key takeawaysThis key takeaway was generated through LLMs crawling the page and coming up with an overview of the content.

This article features Mathew Chase discussing the critical but often overlooked role of DNS in modern IT and cybersecurity. It explains that while Microsoft DNS typically auto-deploys in Active Directory and works most of the time, that reliability gap can cause major operational failures for services that must be highly available, since Active Directory and application authentication fundamentally depend on DNS. The piece argues that properly managed DNS, DHCP, and IPAM solutions provide network-level visibility and defenses — including DNS firewalls and DHCP/IP address monitoring — that significantly improve security posture with minimal end-user impact and reasonable administrative cost.

Why is relying on default Microsoft DNS in Active Directory environments potentially risky for high-availability services?

Relying on default Microsoft DNS is risky because it often results in a “set it and forget it” approach where administrators assume DNS will just work. While Microsoft DNS auto-deploys with Active Directory and functions about 90 percent of the time, that failure rate is unacceptable for critical, highly available services such as call centers or global load balancing scenarios. Moreover, Active Directory and Microsoft authentication systems are dependent on DNS; if DNS breaks or is misconfigured, authentication and inter-application communications can fail, causing significant operational impact.

How can DNS improve an organization’s cybersecurity posture according to the article?

The article explains that DNS provides valuable visibility into network activity and is an early indicator of malicious behavior because every web address request begins with DNS. DNS firewalls and policy-based blocking can disrupt malicious queries using threat feeds or custom rules, preventing access to harmful domains. Combined with DHCP and IP address management, DNS solutions allow administrators to see who requests IP addresses and what IP space is being used, aiding detection of compromised hosts and abnormal behavior without requiring significant changes from end users.

What operational trade-offs should IT leaders consider when adding DNS-based security solutions?

IT leaders should evaluate management overhead, costs, and return on investment when introducing DNS-based security. The article notes common concerns about whether new solutions will require more staff or budget. However, enterprise DNS, DHCP, and IPAM solutions can solve network-level problems with built-in reliability and redundancy and typically demand minimal end-user configuration. From a security perspective, these network-layer defenses often provide substantial benefit relative to their administrative cost, making them an attractive addition to the security stack.

Learn more from Mathew Chase’s webinar on how busy IT executives can leverage DNS or read his thoughts on cybersecurity in our Cybersecurity Spotlight series.

It’s easy to ignore DNS.

Microsoft in particular has made it so. Microsoft DNS automatically deploys in the Active Directory environment, so you set up your servers and forget about it. And 90 percent of the time, it works.

But ‘90 percent of the time’ in a high-functioning IT organization is a horrible metric. When you actually do something important that is truly reliant upon DNS or DHCP, like run a call center, something that works 90 percent of the time is a huge problem.

DNS is the fundamental backplane of your network. It’s how everyone inside your organization accesses resources in and outside your network. All of your applications that have to talk to each other rely upon it. In complicated load balancing scenarios on a global network, DNS is crucial. And let’s not forget this important point: Active Directory doesn’t function without DNS. Period. All of your authentication systems for Microsoft components are built on underlying DNS records.

The people who have often best understood and paid attention to DNS are, unfortunately, primarily on the other side of the fence – hackers. In the early days, DNS was the quick way to conduct reconnaissance to map networks and identify hostnames and prime targets on a network. For many network administrators, DNS is just a means to an end: ‘I put in my DNS server and I’m done.’ That’s where their understanding of it frequently stops.

Ignoring DNS is something you do at your own peril.

When properly administered and configured, DNS yields very good information. It tells us what’s happening, where people are going and what they’re doing. In modern cybersecurity environments, we’re always concerned about a bad actor on our network. How do we determine when people are either compromised or acting in a way that is uncommon for them to act? DNS can provide valuable clues.

Every malicious web address starts with a DNS request. DNS firewalls are exceptionally good at disrupting these queries, whether through a threat feed or custom-built policies. DNS-based security also allows for visibility into the IP address space and DHCP, allowing network administrators to see who’s requesting IP addresses on the network and where they’re going with them.

Of course, any addition to the security stack begs the question of how it will be managed. Is the new solution going to take more people? How much more money is it going to cost me? And what’s my return on investment? Good solutions that can solve problems at a network level, and don’t require a lot of end user configuration, can really help improve your security posture. DNS, DHCP, and IP address management enterprise solutions provide that, along with all the reliability and redundancy required in stable operations. But from a security perspective, you gain network layer defenses with almost no impact to end users. The cost of administration to security benefit has always weighed in my favor.

Mathew Chase

Mathew most recently was vice president of IT for Inovalon, which provides cloud-based platforms and data analytics for the healthcare industry. He has deep experience with DNS and its implications for cybersecurity and other digital transformation initiatives. He got his start in IT in the mid-90’s at the Las Vegas Review-Journal, when he was pulled off his desktop publishing shift to help the newsroom become one of the first in the U.S. to produce their paper electronically. Career highlights include the IT operations manager for resident shows at Cirque du Soleil and the CIO for a U.S. government health insurance commission.


An avatar of the author

BlueCat provides core services and solutions that help our customers and their teams deliver change-ready networks. With BlueCat, organizations can build reliable, secure, and agile mission-critical networks that can support transformation initiatives such as cloud adoption and automation. BlueCat’s growing portfolio includes services and solutions for automated and unified DDI management, network security, multicloud management, and network observability and health.

Related content

Flock of geese flying in formation across a blue sky, framed by a pink graphic border, symbolizing coordinated network migrat

Automate your DDI modernization path by migrating with Micetro

Automate cross-platform DNS and DHCP migration with Micetro to reduce risk, eliminate manual effort, and modernize infrastructure faster.

Read more
Close-up of interlocked metal chain links symbolizing connected network objects and relationships in IPAM

How to map your network with user-defined links in Integrity X

Map your network with user-defined links in Integrity X to define and manage custom relationships, such as dual-stack and NAT environments.

Read more
Three armored figures walking toward a futuristic Las Vegas skyline with pyramids, glowing orb, and "Welcome to Fabulous Las

Your journey to intelligent NetOps begins at Cisco Live

Visit BlueCat’s booth or book a meeting now to learn more about how our solutions can help you build a network that supports constant change.

Read more
Stacked colorful wooden directional arrows on a post by a calm seaside with distant hills and blue sky

Replace BIND and ISC with Micetro DNS/DHCP Server (MDDS)

Tired of patching and manually configuring BIND DNS and ISC DHCP? Discover how Micetro MDDS appliances can replace them for modern DDI.

Read more