DNS Monitoring: Changes, TTL, DNSSEC — Turnkey Setup
Imagine your site works, the server responds, but visitors see nothing. The cause: a DNS A record was changed an hour ago, and you only learned about it from user complaints. DNS monitoring is what separates control from flying blind. According to statistics, 60% of companies experience at least one DNS attack per year, and the average detection time without monitoring exceeds 6 hours. We've seen cases where clients lost traffic for hours due to a registrar account breach and record tampering. Our experience shows: without dedicated DNS monitoring, you're blind to one of the most vulnerable parts of your infrastructure.
Why Standard Server Monitoring Doesn't Protect Against DNS Attacks
When a site goes down, the usual first steps are checking server load, application logs, and databases. But the fault might be in DNS: an unauthorized A-record change, a broken DNSSEC signature, or a sudden TTL drop can make your site unavailable to thousands of users while the server itself is healthy. We've handled a case where a client's domain was unreachable for 6 hours due to a missed renewal — losses were tens of thousands of dollars. Since then, we've made domain expiration checks a mandatory component.
Risks of Not Monitoring DNS
- A/AAAA changes: Site shows third-party content or a blank page.
- MX hijacking: Email flows are redirected to an attacker's server, compromising correspondence and passwords.
- NS attacks: Full domain control lost — traffic diverted to phishing pages.
- TTL manipulation: Abnormally low TTL (<60 s) often precedes an attack.
- Broken DNSSEC: 30% of users (browsers with validation) cannot reach your site.
- Domain expiration: Expired domain loses all DNS configuration.
DNS Records to Monitor
| Record Type | What We Check | Risk if Changed |
|---|---|---|
| A/AAAA | IP address unchanged | Site shows foreign content or blank page |
| MX | Mail servers unchanged | Email interception, phishing from your domain |
| NS | DNS servers correct | Complete loss of domain control |
| TXT | SPF, DKIM, DMARC intact | Email spoofing, delivery issues |
| CNAME | Canonical name unchanged | Redirect to malicious resource |
Additionally, we monitor:
- TTL: Automatic alert when TTL drops below 300 seconds.
- DNSSEC: Validate RRSIG presence and correctness. Per RFC 4033, DNSSEC authenticates DNS responses.
- Domain expiration: Daily check, alert at 30 days before expiry.
How We Set Up DNS Monitoring Turnkey
We use a combination of lightweight Python scripts for quick starts and Prometheus Blackbox Exporter for industrial scale.
- Audit current configuration — collect baseline records, verify DNSSEC, TTL, expiration date. Save baseline in a JSON snapshot.
- Deploy Python change monitoring script — query three public resolvers (Google, Cloudflare, OpenDNS) and compare responses to baseline. Alert via Telegram, Slack, or PagerDuty within one minute. Average detection time: 60 seconds.
-
Integrate with Prometheus via Blackbox Exporter — create a
dns_checkmodule for each domain, verifying expected IP. Metrics flow into Grafana; alerts trigger ifprobe_success == 0 for 2m. - DNSSEC validation — periodically resolve with the DO (DNSSEC OK) flag and check for RRSIG. Critical alert on validation error.
- WHOIS monitoring — daily check of days until domain expiration. Threshold: 30 days.
Example Python script for DNS check
import dns.resolver from dns.exception import DNSException def check_dns(domain, expected_ip): try: answers = dns.resolver.resolve(domain, 'A') for rdata in answers: if rdata.address != expected_ip: alert(f"DNS change detected for {domain}") except (DNSException, IndexError) as e: alert(f"DNS error for {domain}: {e}") Method comparison: Blackbox Exporter is preferable for 50+ domains — it provides ready metrics, Grafana integration, and scales without extra code. Python is convenient for rapid prototyping or custom checks (e.g., comparing records across resolvers).
What's Included
- Prepare and agree on list of monitored domains and records.
- Develop and deploy monitoring scripts (Python) or configure Blackbox Exporter.
- Set up alerts (Telegram, Slack, email, PagerDuty) with severity levels.
- Validate DNSSEC and WHOIS information.
- Document incident recovery procedures.
- 7-day test period with alert tuning.
- Handover and training for your team.
Timeline
| Component | Duration |
|---|---|
| Python script + alerts | 1–2 days |
| Prometheus + Blackbox Exporter | 1 day |
| DNSSEC validation | 0.5 day |
| WHOIS monitoring | 0.5 day |
| Full turnkey setup | 3–5 days |
Exact timeline depends on the number of domains and infrastructure complexity. Contact us to discuss monitoring for your domains — we'll analyze your configuration and propose an optimal solution.
Tools for Self-Check
-
dig +dnssec example.com— manual DNSSEC verification. - DNSCheck.tools — online check of all records.
- GitHub: dns-monitor — ready template for persistent monitoring (open-source).
For ongoing automated monitoring, scripts or Prometheus are essential. We share our code under open license.
Our Experience & Guarantees
Our engineers have 10+ years working with DNS infrastructure for high-load projects (up to 5000 RPS). We are certified in Prometheus, Python, BIND, and PowerDNS. We guarantee that the monitoring system will catch every change — if not, we'll reconfigure it for free.
DNS monitoring is an investment that pays off at the first incident. Order an audit today — get a consultation from our engineer and a timeline proposal.







