The Era of Secure DNS: An Overview on Security and Best Practices — ICACNC 2025 | TechShield Publications
ICACNC 2025 · Conference Article

The Era of Secure DNS: An Overview on Security and Best Practices

Authors: Asad Ali Akbar Shirazi, Zain ul Abiden Akhtar, Mubashir Shaheen, Hafiz Muhammad Hamza Sohail

Abstract

The internet infrastructure functionally utilizes the Domain Name System (DNS), which translates domain names into IP addresses to create successful online connections. The basic infrastructure of the DNS system exposes security risks because weak protection measures allow attackers to perform DNS spoofing, cache poisoning, DDoS attacks, hijacking, tunneling, and advanced persistent threat attacks to steal data. This paper examines mitigation methods and techniques such as DNSSEC, DoH threat intelligence automation, and secure resolvers like Quad9 and Cloudflare, and their implementation for DNS security through an analysis of key DNS elements, detailing usual attack methods and the extensive risks of DNS breaches that manifest as noncompliance issues and operational breakdowns.

DNS Security DNSSEC DNS Spoofing DNS Tunneling DDoS Network Security

Cite This Paper

A. A. A. Shirazi, Z. Ul Abiden Akhtar, M. Shaheen, and H. M. H. Sohail, “The Era of Secure DNS: An Overview on Security and Best Practices,” Proc. Int. Conf. on AI, Cybersecurity, and Next-Gen Computing (ICACNC 2025), The Islamia University of Bahawalpur, Jun. 2025, doi: 10.67535/tsp.000001.030.