DNS DNS Query

DNS query flood

High-volume DNS queries against resolvers or authoritative servers. Stresses query parsing, cache, and recursive resolution paths.

How it works

  1. UDP (or TCP) DNS queries hit port 53 with varied QNAME/QTYPE.
  2. Recursive resolvers may fan out upstream lookups under load.
  3. NXDOMAIN-heavy patterns can amplify resolver work without large responses.

Packet flow (illustrative)

Client query (QNAME) and server response (A/AAAA or NXDOMAIN).

Illustrative flow — not a live capture.

Typical pattern Query PPS to :53
Engarde metric Query rate, timeouts
Layer DNS / app-adjacent

What to watch in Engarde

  • Resolver latency and timeout rate under query spikes.
  • Authoritative server CPU when bypassing cache.
  • Any upstream provider DNS rate limiting.

Running this simulation

Engarde DNS simulation targets resolver or authoritative endpoints you authorize. Run short bursts first to baseline cache behavior.

Mitigation perspective

Response Rate Limiting (RRL), QPS caps, and anycast distribution; validate with simulation on staging DNS where possible.