For more than two decades, cybersecurity has evolved through distinct waves of innovation. Security investments have shifted from perimeter firewalls to endpoint protection, from identity and access management to cloud native security. Every transition has been necessary, driven by the changing nature of enterprise IT and an increasingly sophisticated threat landscape. Yet throughout this evolution, one foundational element of every digital interaction has remained surprisingly underprotected—the Domain Name System (DNS).
Every time a user opens a website, an application connects to a cloud service or a device communicates with an external resource, the very first action is a simple question: Where do I find this name? That question is answered by DNS, making it the starting point of nearly every legitimate business transaction and nearly every cyberattack. The irony is striking. Organizations spend millions securing the second, third and fourth stages of an attack chain, while the very first step often passes through infrastructure that was never designed with security in mind.
DNS: The internet's most trusted and least monitored protocol
When DNS was created in the early 1980s, its mission was simply to provide fast, reliable name resolution across a growing internet. Security was not part of its original design philosophy because the internet itself was built on trust. That assumption no longer exists. Today's enterprise environment is vastly more connected than ever before. A single modern webpage can generate more than 200 DNS lookups before it fully loads, while the average employee's laptop may initiate thousands of DNS requests every day. Every cloud application, SaaS platform, collaboration tool, IoT device and mobile application depends on DNS. Despite this enormous volume of activity, DNS often remains invisible within enterprise security operations.
Most security controls, including firewalls, secure web gateways, endpoint detection and response (EDR) and data loss prevention (DLP) solutions, implicitly trust that DNS has already done its job safely. Attackers understand this dependency exceptionally well. Rather than attempting to break DNS, they simply exploit the trust.
Why traditional detection models are no longer enough
For years, cybersecurity operated under a relatively predictable model. A malicious domain would be identified somewhere in the world, threat intelligence providers would catalog it and security vendors would distribute updated blocklists to everyone else. Organizations that consumed these feeds benefited from collective intelligence. That model is rapidly becoming obsolete. AI has fundamentally changed the economics of cybercrime. Threat actors can now automatically generate thousands of unique domains, weaponize them for a few hours, execute attacks and discard them before traditional reputation systems can identify them.
Industry research highlights the scale of this shift. DNSFilter's 2025 research found that approximately one in every 174 DNS requests is now malicious, compared to roughly one in a thousand only a year earlier. Even more concerning, Infoblox reported that 95% of threat-related domains were observed in only a single customer environment.
That statistic changes everything.
If a malicious domain is used only once, then any defense relying solely on historical reputation data is already behind the attacker. By the time the domain appears on a blocklist, the campaign has already ended. The future of DNS security cannot depend exclusively on remembering yesterday's attacks; it must anticipate tomorrow’s attacks.
DNS has become a preferred attack surface
Modern adversaries increasingly use DNS because it is universally allowed, rarely inspected in depth and essential for business operations. DNS enables multiple attack techniques across the cyber kill chain. Attackers register newly created or lookalike domains for phishing campaigns that closely resemble legitimate brands. Malware uses DNS queries, often through TXT records, to communicate with command-and-control infrastructure while blending into normal network traffic. Sensitive information can be exfiltrated via DNS tunneling, allowing data to leave the organization in encoded queries one at a time. Even abandoned cloud resources can become entry points when forgotten DNS records continue pointing to decommissioned services, creating opportunities for subdomain hijacking. None of these techniques necessarily triggers immediate alerts from traditional security controls because they exploit the infrastructure that every organization depends upon.
The missing layer in modern security architecture
This is not a criticism of existing security investments. Firewalls, EDR platforms, secure web gateways, email security, identity platforms and DLP solutions all perform the functions they were designed to perform. The challenge is architectural. Firewalls inspect network traffic but are not designed to analyze DNS resolution behavior in depth. Endpoint detection solutions monitor processes and system activity, but cannot always detect data hidden within DNS tunnels. Likewise, DLP programs inspect web traffic, email and file transfers, yet many organizations do not inspect DNS as a potential exfiltration channel. This creates a visibility gap. An organization may have mature controls across every major security domain while still allowing malicious DNS queries to pass unchecked. If DNS remains outside the organization's detection strategy, then security coverage remains incomplete.
Protective DNS: Shifting security to the earliest possible moment
Protective DNS (PDNS) shifts DNS's role from passive infrastructure to active security control. Rather than simply resolving domain names, Protective DNS continuously evaluates every DNS query and response. Suspicious or malicious destinations can be blocked, redirected or sinkholed before any network connection is established. Importantly, leading Protective DNS platforms increasingly leverage predictive threat intelligence and AI-driven analytics to identify attacker infrastructure before it is actively used. Instead of waiting for a domain to become known as malicious, they assess behavioral indicators, infrastructure characteristics, registration patterns and relationships that suggest malicious intent. This approach aligns closely with the industry's broader movement toward preemptive cybersecurity. Rather than reacting after compromise, organizations seek to anticipate attacker behavior, deny access to malicious infrastructure and disrupt attacks before they materialize.
Protective DNS delivers exactly that capability, which acts at the earliest point in the attack lifecycle. It is important to recognize, however, that PDNS is not intended to replace existing security controls. Traffic directed to hard-coded IP addresses without DNS resolution can bypass Protective DNS, making it one layer within a broader defense-in-depth strategy. Its greatest value lies in enriching firewalls, SIEM platforms and SOC operations with high-confidence DNS intelligence, strengthening the entire security ecosystem.
Industry momentum is clear
The cybersecurity community has increasingly recognized DNS as a strategic security layer rather than a simple network infrastructure. Recent guidance reflects this shift. NIST's SP 800-81 Revision 3 positions DNS security around resilient architecture, protective DNS and improved operational visibility. CISA has operated a Protective DNS capability for US federal agencies since 2022, while Microsoft's Zero Trust architecture emphasizes allowing outbound communication only after successful resolution through trusted DNS services. Collectively, these developments reinforce a simple principle: Organizations cannot truly adopt a ‘never trust, always verify’ philosophy while exempting DNS from verification.
Building a practical path forward
Fortunately, adopting Protective DNS does not require a complete security transformation. Organizations can begin with a DNS security assessment to understand how many potentially malicious domains are currently resolving through their environment. From there, hybrid deployments combining on-prem and cloud-based resolvers provide resilience while maintaining consistent protection across distributed environments. Encrypted DNS should be governed to ensure that endpoints continue to use trusted enterprise resolvers rather than bypassing organizational controls. Finally, enriched DNS telemetry should become part of everyday SOC operations, enabling analysts to identify attacker behavior much earlier in the attack lifecycle.
Making DNS your first line of defense
Cybersecurity has always been a race to reduce attacker advantage. For years, defenders have focused on detecting compromises after network connections are established, malware executes or data begins moving. Yet almost every one of those attacks begins with a single DNS lookup.
That first question, "Where do I find this name?" is the earliest observable signal available to defenders. The organizations that answer it with intelligence rather than assumptions will be better positioned to prevent attacks rather than simply respond to them.