Browser-only demoSynthetic dataInteractive demo · no DNS traffic leaves your browser · modelled on the DNS Daddy v0.3 development interface.View project on GitHubVisit dnsdaddy.dev

Detection lab

Simulated traffic scenarios behind the experimental detectors.

Updated —

Interactive DNS Security Simulation

Pick a scenario and watch how normal and suspicious DNS behaviour differ — with synthetic traffic only.

Everything here is synthetic

Traffic, devices and addresses are generated in your browser from reserved documentation ranges. No DNS query is resolved, no infrastructure is contacted, and nothing shown is telemetry from a real network. Where a detection represents behaviour DNS Daddy does not score yet, it is labelled Experimental concept or Research demonstration.

Start hereBaseline

Normal DNS

The baseline every detection is measured against

  • A DNS query is a device asking a resolver to turn a name into an address
  • Ordinary names are short, human-readable and heavily repeated
  • Almost everything resolves successfully
Open simulation
CoreExperimental concept

DNS Tunnelling

Data smuggled inside query names

  • Query names can carry data outbound even when web traffic is blocked
  • Detection comes from behaviour over time, not one bad-looking name
  • Unique-subdomain count under one parent is the strongest single clue
Open simulation
CoreResearch demonstration

NXDOMAIN Anomaly

A client asking for names that do not exist

  • NXDOMAIN means the name does not exist, not that it was blocked
  • A low background NXDOMAIN rate is completely normal
  • Sustained high NXDOMAIN from one client is worth a look
Open simulation
CoreResearch demonstration

Unusual TXT Traffic

A roomy record type, used oddly

  • TXT records are normal and necessary, mostly for SPF, DKIM and domain verification
  • Proportion matters far more than presence
  • Which host is asking, and how often, is the real signal
Open simulation
Start hereResearch demonstration

High-Entropy Subdomains

api.example.test versus aj39DKsl20ZmQ8.example.test

  • Entropy is a statistical property of the name, nothing more
  • Plenty of legitimate infrastructure uses random-looking hostnames
  • One signal is a lead; a finding needs corroboration
Open simulation
AdvancedResearch demonstration

DGA-like Traffic

Cycling through algorithmically generated names

  • A DGA is a shared algorithm producing the same names for attacker and malware
  • Most generated names are never registered, so failures dominate
  • The pattern is recognisable, but benign lookalikes exist
Open simulation
AdvancedExperimental concept

Beaconing

The same lookup, almost exactly on schedule

  • Regular intervals are a behavioural signal independent of the name itself
  • Implants check in on a timer, sometimes with deliberate jitter
  • Plenty of legitimate software also polls on a schedule
Open simulation

About DNS Daddy

An experimental, self-hosted protective DNS resolver