DNS Monitoring: Changes, TTL, DNSSEC — Turnkey Setup

DNS Monitoring: Changes, TTL, DNSSEC — Turnkey Setup

Development and maintenance of all types of websites:

Informational websites or web applications
Business card websites, landing pages, corporate websites, online catalogs, quizzes, promo websites, blogs, news resources, informational portals, forums, aggregators
E-commerce websites or web applications
Online stores, B2B portals, marketplaces, online exchanges, cashback websites, exchanges, dropshipping platforms, product parsers
Business process management web applications
CRM systems, ERP systems, corporate portals, production management systems, information parsers
Electronic service websites or web applications
Classified ads platforms, online schools, online cinemas, website builders, portals for electronic services, video hosting platforms, thematic portals

These are just some of the technical types of websites we work with, and each of them can have its own specific features and functionality, as well as be customized to meet the specific needs and goals of the client.

Our competencies:

Frequently Asked Questions

Latest works

  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1281
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1237
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    977
  • image_crm_chasseurs_493_0.webp
    CRM development for Chasseurs
    1025
  • image_website-sbh_0.webp
    Website development for SBH Partners
    1103
  • image_website-_0.webp
    Website development for Red Pear
    550

DNS Monitoring: Changes, TTL, DNSSEC — Turnkey Setup

Imagine your site works, the server responds, but visitors see nothing. The cause: a DNS A record was changed an hour ago, and you only learned about it from user complaints. DNS monitoring is what separates control from flying blind. According to statistics, 60% of companies experience at least one DNS attack per year, and the average detection time without monitoring exceeds 6 hours. We've seen cases where clients lost traffic for hours due to a registrar account breach and record tampering. Our experience shows: without dedicated DNS monitoring, you're blind to one of the most vulnerable parts of your infrastructure.

Why Standard Server Monitoring Doesn't Protect Against DNS Attacks

When a site goes down, the usual first steps are checking server load, application logs, and databases. But the fault might be in DNS: an unauthorized A-record change, a broken DNSSEC signature, or a sudden TTL drop can make your site unavailable to thousands of users while the server itself is healthy. We've handled a case where a client's domain was unreachable for 6 hours due to a missed renewal — losses were tens of thousands of dollars. Since then, we've made domain expiration checks a mandatory component.

Risks of Not Monitoring DNS

  • A/AAAA changes: Site shows third-party content or a blank page.
  • MX hijacking: Email flows are redirected to an attacker's server, compromising correspondence and passwords.
  • NS attacks: Full domain control lost — traffic diverted to phishing pages.
  • TTL manipulation: Abnormally low TTL (<60 s) often precedes an attack.
  • Broken DNSSEC: 30% of users (browsers with validation) cannot reach your site.
  • Domain expiration: Expired domain loses all DNS configuration.

DNS Records to Monitor

Record Type What We Check Risk if Changed
A/AAAA IP address unchanged Site shows foreign content or blank page
MX Mail servers unchanged Email interception, phishing from your domain
NS DNS servers correct Complete loss of domain control
TXT SPF, DKIM, DMARC intact Email spoofing, delivery issues
CNAME Canonical name unchanged Redirect to malicious resource

Additionally, we monitor:

  • TTL: Automatic alert when TTL drops below 300 seconds.
  • DNSSEC: Validate RRSIG presence and correctness. Per RFC 4033, DNSSEC authenticates DNS responses.
  • Domain expiration: Daily check, alert at 30 days before expiry.

How We Set Up DNS Monitoring Turnkey

We use a combination of lightweight Python scripts for quick starts and Prometheus Blackbox Exporter for industrial scale.

  1. Audit current configuration — collect baseline records, verify DNSSEC, TTL, expiration date. Save baseline in a JSON snapshot.
  2. Deploy Python change monitoring script — query three public resolvers (Google, Cloudflare, OpenDNS) and compare responses to baseline. Alert via Telegram, Slack, or PagerDuty within one minute. Average detection time: 60 seconds.
  3. Integrate with Prometheus via Blackbox Exporter — create a dns_check module for each domain, verifying expected IP. Metrics flow into Grafana; alerts trigger if probe_success == 0 for 2m.
  4. DNSSEC validation — periodically resolve with the DO (DNSSEC OK) flag and check for RRSIG. Critical alert on validation error.
  5. WHOIS monitoring — daily check of days until domain expiration. Threshold: 30 days.
Example Python script for DNS check
import dns.resolver from dns.exception import DNSException def check_dns(domain, expected_ip): try: answers = dns.resolver.resolve(domain, 'A') for rdata in answers: if rdata.address != expected_ip: alert(f"DNS change detected for {domain}") except (DNSException, IndexError) as e: alert(f"DNS error for {domain}: {e}") 

Method comparison: Blackbox Exporter is preferable for 50+ domains — it provides ready metrics, Grafana integration, and scales without extra code. Python is convenient for rapid prototyping or custom checks (e.g., comparing records across resolvers).

What's Included

  • Prepare and agree on list of monitored domains and records.
  • Develop and deploy monitoring scripts (Python) or configure Blackbox Exporter.
  • Set up alerts (Telegram, Slack, email, PagerDuty) with severity levels.
  • Validate DNSSEC and WHOIS information.
  • Document incident recovery procedures.
  • 7-day test period with alert tuning.
  • Handover and training for your team.

Timeline

Component Duration
Python script + alerts 1–2 days
Prometheus + Blackbox Exporter 1 day
DNSSEC validation 0.5 day
WHOIS monitoring 0.5 day
Full turnkey setup 3–5 days

Exact timeline depends on the number of domains and infrastructure complexity. Contact us to discuss monitoring for your domains — we'll analyze your configuration and propose an optimal solution.

Tools for Self-Check

  • dig +dnssec example.com — manual DNSSEC verification.
  • DNSCheck.tools — online check of all records.
  • GitHub: dns-monitor — ready template for persistent monitoring (open-source).

For ongoing automated monitoring, scripts or Prometheus are essential. We share our code under open license.

Our Experience & Guarantees

Our engineers have 10+ years working with DNS infrastructure for high-load projects (up to 5000 RPS). We are certified in Prometheus, Python, BIND, and PowerDNS. We guarantee that the monitoring system will catch every change — if not, we'll reconfigure it for free.

DNS monitoring is an investment that pays off at the first incident. Order an audit today — get a consultation from our engineer and a timeline proposal.