logo

Google Public DNS’s approach to fight against cache poisoning attacks

ID: 40f4210b-5aeb-56b7-98c8-020bae9d6a15

STIX ID: report--40f4210b-5aeb-56b7-98c8-020bae9d6a15

Feed Name: Google Online Security Blog

Date Published: 2024-03-28

Date Updated: 2026-04-27

Author: Kimberly Samra

...
...

Google Public DNS details its multi-layer defenses against DNS cache poisoning, including RFC 5452 source port/ID randomization, selective DNS Cookies (RFC 7873), global default 0x20 query name case randomization now covering over 90% of UDP traffic, and deployment of recursive-to-authoritative DNS-over-TLS per RFC 9539 (about 6% of egress), with exceptions and fallbacks for nonconformant servers; the post reports real-world effectiveness and urges DNS operators to adopt these mechanisms to strengthen DNS security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.