An open resolver is a recursive DNS resolver accessible from unanticipated networks or users and willing to resolve queries for anyone. A recursive resolver receives a query, checks its cache and the DNS hierarchy servers, and returns a response. Making this service publicly available is not always a mistake, but an unprotected instance can be exploited for DDoS amplification, resource consumption, policy circumvention, or data gathering. The risk assessment depends on who should be allowed to use it, the applied limits, and the network configuration.
Amplification Risk
In a reflection attack, the attacker sends queries with a falsified source IP address of the victim to many open resolvers. If the responses are larger than the requests, the victim receives an amplified volume of traffic from servers that are unaware they are involved. The extent of amplification depends on query type, protocol, configuration, and response sizes. DNSSEC can increase some response sizes, but it is an integrity standard, not the sole cause nor a complete solution to the issue. Filtering spoofing and configuring access limits reduce abuse.
An open resolver may also be used to bypass geographic restrictions, hide query sources, or query internal domains if the network is misconfigured. Queries can reveal interests and activities to the resolver operator. If a public service is intentional, it must be sized, monitored, and managed with anti-abuse controls, proportional logging, and privacy protections. If the resolver is meant only for an enterprise network, access should be restricted to authorized subnets and clients.
Detection
Administrators can verify if recursion is available from the Internet using authorized tests and configuration tools without generating attack traffic. They check ACLs, firewalls, listening interfaces, recursive behavior, and software versions. Logs may show unexpected client queries, spikes, unusual record types, or anomalous responses. Simply having UDP/53 open does not prove a server is an open resolver—it might only serve an authoritative zone or limit recursion. Testing from the intended external perspective and reviewing actual configuration are essential.
In case of abuse, recursion should be restricted to authorized clients, rate limits applied, and software updated. The network provider can help filter falsified traffic. Changes must be monitored to ensure legitimate users continue resolving names. If the resolver is managed by a vendor, contact the responsible team instead of modifying systems outside your control.
Open Resolver vs. Authoritative Nameserver
A public authoritative nameserver must be reachable to serve its zone, but it does not necessarily need to accept recursion for any name. Open recursion is a distinct function from DNS authority. A server can be public and authoritative for a zone while refusing to look up external data on behalf of anonymous clients. Separating roles reduces exposure and simplifies policy. Modern infrastructures often use dedicated servers for authority and recursion.
In summary, an open resolver allows recursion for unanticipated clients and may become a tool for abuse or a privacy risk. Defense combines access restriction, rate limiting, monitoring, and separation between recursive and authoritative services. Proper configuration ensures that public resolvers do not inadvertently expose networks to misuse while maintaining necessary functionality for legitimate users.
← Full glossary