Browser-only demoSynthetic dataInteractive demo · no DNS traffic leaves your browser · modelled on the DNS Daddy v0.3 development interface.View project on GitHubVisit dnsdaddy.dev

Detections

Behavioural findings. Alert-only, and every detector is experimental.

Updated —

Behavioural detections alert only. They do not automatically block DNS traffic.

Each detector observes, scores and explains — blocking stays with threat intelligence and policy. All six detectors are experimental: the thresholds are calibrated against synthetic traffic, not a production network, so no real-world false-positive rate has been measured. These are statistical measurements, not machine-learning models.

High

1

Medium

3

Low

2

Detectors

6

All alert-only, all experimental

Findings

Select a finding to see the evidence behind it.

Detectors

The six behavioural detectors and what each one measures.

  • DNS tunnellingdns_tunnelExperimental

    High-volume encoded subdomain traffic under a single parent domain.

    Measures: Unique subdomains, label length, label entropy, TXT/NULL share.

  • DGA-like domainsdga_likeExperimental

    Algorithmic-looking names, often spread across several TLDs.

    Measures: Character distribution, label randomness, distinct parent domains.

  • NXDOMAIN anomalynxdomain_anomalyExperimental

    An unusual proportion of names that do not exist, versus the client's own baseline.

    Measures: NXDOMAIN ratio, distinct failing names, per-client baseline.

  • TXT anomalytxt_anomalyExperimental

    An unusual share of TXT lookups for a client, or unusually large TXT answers.

    Measures: TXT share of queries, answer size, distinct TXT names.

  • DNS beaconingdns_beaconingExperimental

    Highly regular query intervals to a single name.

    Measures: Mean interval, coefficient of variation, distinct names.

  • Resolution failureresolution_failureExperimental

    Repeated SERVFAIL or timeout responses for a client or upstream.

    Measures: SERVFAIL rate, timeout rate, affected upstream.

Want to watch these patterns build up in simulated traffic query by query?

Open the detection lab