Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

NXNSAttack is a DNS vulnerability that can make a recursive resolver send a large number of extra queries to authoritative DNS servers. Attackers exploit crafted DNS referrals to turn the resolver into a traffic amplifier, potentially overwhelming the targeted infrastructure. The headline 2020 study reported packet amplification greater than 1,620× in its tested attack scenarios; that is a research result, not a universal measure of attacks today.

How NXNSAttack works

When a recursive DNS resolver looks up a name, it follows referrals between authoritative DNS servers until it can return an answer. A referral can identify name servers that the resolver should contact for the next part of the lookup.

NXNSAttack abuses how some resolvers handle that referral data. An attacker supplies a crafted delegation that prompts a resolver to proactively look up many name-server addresses. Those additional queries can be directed toward authoritative DNS infrastructure selected by the attacker. The resolver therefore generates far more traffic than the initial request alone would require.

The attack depends on crafted DNS data being processed by a resolver and on the resolver making the resulting queries. It targets DNS infrastructure; it is not a vulnerability in a consumer device or a conventional user-facing application.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
TP-Link Deco 7 BE23 Dual-Band BE3600 WiFi 7 Mesh Wi-Fi Router
  • 𝐍𝐞𝐱𝐭-𝐆𝐞𝐧 𝐖𝐢-𝐅𝐢 𝟕 𝐰𝐢𝐭𝐡 𝟒-𝐒𝐭𝐫𝐞𝐚𝐦 𝐃𝐮𝐚𝐥-𝐁𝐚𝐧𝐝 𝐮𝐩 𝐭𝐨 𝟑.𝟔 𝐆?𝐩𝐬 - Designed with the latest Wi-Fi 7 technology, featuring Multi-Link Operation (MLO), Multi-RUs, and 4K-QAM, The Deco 7 BE23 delivers full speeds of up to 2882 Mbps on the 5GHz band, 688 Mbps on the 2.4GHz band with 4 streams and achieve optimized performance on latest WiFi 7 laptops and devices, like the iPhone 16 Pro, and Samsung Galaxy S24 Ultra.
  • 𝐖𝐢𝐝𝐞 𝐂𝐨𝐯𝐞𝐫𝐚𝐠𝐞 𝐰𝐢𝐭𝐡 𝐒𝐭𝐫𝐨𝐧𝐠 𝐂𝐨𝐧𝐧𝐞𝐜𝐭𝐢𝐨𝐧 - Enjoy seamless max Wi-Fi coverage up to 2,500 sq. ft (1-Pack) and 150 devices without compromising performance. 4x high-gain antennas per node and 4x high-power FEMs deliver far-reaching, reliable signals for remote workers, gamers, students, and more.
  • 𝐔𝐥𝐭𝐫𝐚-𝐅𝐚𝐬𝐭 𝟐.𝟓 𝐆𝐛𝐩𝐬 𝐖𝐢𝐫𝐞𝐝 𝐏𝐞𝐫𝐟𝐨𝐫𝐦𝐚𝐧𝐜𝐞 - Each Deco 7 BE23 unit is equipped with two 2.5 Gbps WAN/LAN ports, offering warp-speed connectivity for high-performance wired devices. Integrate with a multi-gig modem for gigplus internet.
  • 𝐎𝐮𝐫 𝐂𝐲𝐛𝐞𝐫𝐬𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐂𝐨𝐦𝐦𝐢𝐭𝐦𝐞𝐧𝐭 - TP-Link is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Secure-by-Design pledge. This device is designed, built, and maintained, with advanced security as a core requirement.
  • 𝐒𝐭𝐫𝐨𝐧𝐠𝐞𝐫, 𝐌𝐨𝐫𝐞 𝐑𝐞𝐥𝐢𝐚𝐛𝐥𝐞 𝐁𝐚𝐜𝐤𝐡𝐚𝐮𝐥 - The Deco 7 BE23 enhances stability with simultaneous wireless and wired backhaul, leveraging Wi-Fi 7 MLO for stronger, more stable connections.

What the reported amplification means

In their 2020 USENIX Security paper, Yehuda Afek, Anat Bremler-Barr, and Lior Shafir reported more than 1,620× amplification in the number of packets exchanged by the recursive resolver. This figure describes the researchers’ reported result, not a guaranteed multiplier for every resolver, configuration, or real-world attack. The paper also reported that the attack could saturate the resolver’s name-server cache section as well as its negative cache.

The authors proposed MaxFetch(k), a change to resolver behavior intended to limit unnecessary proactive fetches. They reported that their MaxFetch(1) implementation on BIND did not degrade throughput or latency in tests with real-world DNS query datasets. That finding applies to the implementation and tests described in the paper; it is not a performance guarantee for all software or workloads. Read the USENIX Security 20 paper.

Rank #2
pcWRT PW-AX1800 WiFi 6 Dual-Band Router with VLAN Support, OpenVPN/WireGuard/IPsec VPN Client/Server - Compatible with ExpressVPN/SurfShark etc., Parental Controls, Ad Blocking, Gigabit Ethernet
  • VLAN Network Segregation: This router includes five preconfigured VLANs that isolate IoT devices, guest users, and work systems into separate, secure networks. Each LAN port and every WiFi SSID can be assigned to a VLAN, giving you complete control over how traffic flows inside your home.
  • Dual VPN Client and Server Support: The router works as both a VPN client and a VPN server, supporting OpenVPN, IPsec, and WireGuard. You can route selected VLANs through a VPN while keeping others on your regular ISP connection, giving each device group the exact level of privacy it needs.
  • Full WiFi 6 on Both Bands: With dual-band WiFi 6 support, the router delivers modern wireless performance across 2.4GHz b/g/n/ax and 5GHz a/n/ac/ax. It improves capacity, stability, and speed while remaining compatible with older devices, making it ideal for busy homes with many connections. Wi-Fi Mesh is available after firmware update.
  • High-Performance Hardware Architecture: Powered by the IPQ6000 quad-core ARM processor at 1.2GHz, along with 128MB flash, 256MB RAM, and hardware NAT acceleration, the router handles multitasking, streaming, VPN traffic, and VLAN isolation smoothly without slowing your network.
  • Flexible and Powerful Parental Controls: You can use trusted services like OpenDNS, CleanBrowsing, and Cloudflare for filtering, then add custom block lists, allow lists, and schedules. The router includes defenses against common bypass attempts, letting families create rules that match each user. Best of all, it's subscription free!

Which DNS software was affected?

CERT-EU’s advisory of 20 May 2020 listed affected historical version ranges for several DNS implementations. Those ranges are a snapshot from 2020, not an inventory of currently vulnerable deployments. The advisory associated the issue with these CVEs:

DNS software CVE listed by CERT-EU
BIND CVE-2020-8616
Unbound CVE-2020-12662 and CVE-2020-12663
Knot Resolver CVE-2020-12667
PowerDNS Recursor CVE-2020-10995

For current exposure and remediation, identify the resolver and its exact release, then consult its vendor’s current security advisories and supported-release guidance. CERT-EU’s 2020 recommendation was to upgrade affected software to a non-affected version; do not use its historical version ranges alone to decide whether a present-day installation is patched. See CERT-EU’s advisory.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What operators should do

For recursive resolver operators

  • Check current security advisories for the specific resolver implementation and update to a supported release that addresses the issue.
  • Review resolver behavior and configuration against the vendor’s guidance, especially where the resolver processes queries from untrusted networks.
  • Monitor for unusual query volume or patterns that may indicate that the resolver is generating abnormal traffic.

For authoritative DNS operators

  • Keep authoritative DNS software and infrastructure maintained, and monitor for unexpected query surges.
  • Coordinate with upstream providers or mitigation services if traffic threatens availability; the attack can direct resolver-generated queries at authoritative infrastructure.

Windows DNS guidance is product-specific

Microsoft’s 2020 guidance recommends response rate limiting (RRL) for supported Windows DNS servers exposed at the network edge and monitoring internal DNS servers for unusual traffic. Microsoft noted that Windows Server 2012 and 2012 R2 do not support the RRL feature discussed in that guidance. These are Microsoft-specific recommendations and version notes, not universal instructions for every DNS implementation. Read Microsoft’s Windows DNS guidance.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Does DNS over HTTPS stop NXNSAttack?

No. DNS over HTTPS (DoH) protects the communication channel between a client and its recursive resolver. NXNSAttack concerns what the resolver does when communicating with authoritative DNS infrastructure, so encrypting the client-to-resolver connection does not address this attack mechanism. CERT-EU explicitly described DoH as irrelevant to the vulnerability.

Best Value
PUSR USR-TCP232-302 Tiny Size RS232 to TCP IP Converter Serial RS232 to Ethernet Server Module Ethernet Converter Support DHCP/DNS (1)
  • This is a serial RS232 to Ethernet server, used for data transparent transmission. USR-TCP232-302 is a low-cost serial device server,whose function is to realize bidirectional transparent transmission between RS232 and Ethernet. USR-TCP232-302 is internally integrated with TCP/IP protocol. User can apply it to device networking communication.
  • Support DHCP, automatically obtain an IP address and query IP address through serial setting protocol, Support DNS function, Set parameters through webpage, Upgrade firmware via network.
  • Auto-MDI/MDIX, RJ45 port with 10/100Mbps, Serial port baud rate from 600 bps to 230.4 Kbps, Check bit of None, Odd, Even, Mark and Space.
  • Work Mode: TCP Server, TCP Client, UDP Client, UDP Server, HTTPD Client. Support virtual serial port and provide corresponding software USR-VCOM, Heartbeat package mechanism to ensure connection is reliable, put an end to dead link, User-defined registration package mechanism, check connection status and use as custom packet header.
  • Under TCP Server mode, Client number ranges from 1 to 16; default number is 4, The global unique MAC address bought from IEEE, user can define MAC address, Across the gateway, switches, routers, Can work in LAN, also can work in the Internet (external network).

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.