DNS Hijacking
Redirecting a domain's traffic by tampering with DNS resolution rather than its registration.
- glossary
DNS hijacking (also called DNS spoofing or cache poisoning) attacks the resolution layer rather than the registration itself: instead of seizing the domain at the registrar, the attacker corrupts what a DNS resolver or nameserver believes the domain points to, silently sending visitors to a malicious IP. In a cache poisoning attack, a forged DNS response is accepted by a recursive resolver and cached for the duration of the TTL, misdirecting every user that resolver serves — with no change visible in the authoritative DNS records. The primary technical countermeasure is DNSSEC, which cryptographically signs DNS responses so resolvers can detect tampering. Unlike traditional domain theft, DNS hijacking leaves ownership records untouched, making it harder to detect without active monitoring of where your domain actually resolves.
Related keywords
- DNS hijacking
- cache poisoning
- DNS spoofing
- DNSSEC
- traffic redirection
Contributors
Namefi is a collective of engineers, designers, and operators who obsess over building tools that make managing your onchain domain names effortless.
Victor Zhou is a technology founder and standards editor focused on digital identity and trust. He founded Namefi, edits Ethereum Improvement Proposals, and previously led smart-contract architecture work at Google Labs.
His work sits at the intersection of naming, ownership, and the systems people use to establish identity online. That perspective makes him especially interested in the way names move between personal meaning, public recognition, and digital infrastructure.
For Namefi, Victor edits and writes about domains as durable digital identity: how names become ownable onchain assets, how tokenization changes custody and trust, and what naming can learn from the systems people use to establish identity online.