The Mystery of Millions of Random DNS Queries from Google
2025-03-11

Verisign engineers detected an unusually high volume of random domain name queries from Google's DNS to root name servers. These queries contained 12-13 random characters and were not seen at the top-level domain servers. Investigation revealed this was due to Google's nonce prepending and query name minimization techniques to prevent Kaminsky attacks. While this explained much of the phenomenon, the excessively high query rate (2000x higher than expected) and low cache utilization remain unsolved. The case highlights the importance of collaboration in internet security.
Tech