# DNS Protection

Secure, resilient DNS that keeps your applications reachable, defends against attacks, and delivers fast, reliable resolution at a global scale

## Always-on DNS security and resilience for critical applications

### Protect critical services

Mitigate DNS DDoS attacks by scrubbing queries through Imperva’s global network before they reach authoritative servers.

### Offer seamless user experience

Deliver low latency, highly available DNS using a global Anycast network.

### Get actionable insights

Gain DNS visibility with logs, traffic metrics, and attack analytics, plus APIs for alerting and policy control.

## Enterprise-ready DNS protection

## Always-on DNS DDoS Protection

Continuously protects authoritative DNS against volumetric and protocol-based DDoS attacks. Malicious queries are absorbed and mitigated across Imperva’s global network before they can overwhelm your infrastructure or disrupt resolution.

## Global Anycast DNS Network

Routes DNS queries to the nearest healthy point of presence using a globally distributed Anycast network. This delivers fast, reliable name resolution while improving resilience and availability, even during traffic spikes or attacks.

## DNS Visibility, Analytics, & Control

Provides deep insight into DNS traffic with real‑time metrics, detailed logs, and attack analytics. Teams gain the visibility and control needed to monitor performance, detect anomalies, and manage DNS policies with confidence.

## Protected DNS

DDoS attacks can take customers, revenue, and reputation in seconds. Imperva DDoS Protection stops malicious traffic fast, with automated mitigation and an industry-leading 3-second SLA, for volumetric, network layer attacks. Protect websites, networks, DNS, and IPs across on-premises and cloud environments. Keep services available during any application or network layer attack.

## **Ready to take your security to the next level?**

See for yourself. No strings attached.

## DNS Protection use cases

See how DNS Protection helps security and network teams defend critical services, absorb traffic spikes, and gain visibility into DNS activity.

### Stop DNS-based attacks before they reach your infrastructure

Protect your authoritative DNS servers from volumetric attacks, random subdomain (NXDOMAIN) floods, and amplification attempts. The service absorbs and filters malicious traffic at the edge, ensuring uninterrupted domain resolution and eliminating downtime risks.

### Maintain DNS performance during traffic surges

Handle sudden spikes in DNS query volumes, whether from attacks or legitimate events, without impacting response times. Intelligent traffic management and scaling ensure consistent resolution performance and a seamless user experience.

### Gain deep visibility into DNS traffic and threat activity

Get real-time insights into all DNS queries targeting your domains, including traffic patterns, geographic distribution, and query types. Identify anomalies such as NXDOMAIN spikes, suspicious sources, and attack vectors through built-in analytics and dashboards—enabling faster investigation, informed decision-making, and proactive threat mitigation.

## DNS Protection FAQs

- #### What is DNS Protection?

DNS Protection safeguards your authoritative DNS against attacks, outages, and abuse by filtering malicious queries and ensuring reliable resolution for legitimate users.

- #### Do I need to migrate my DNS zones to Imperva?

No. Imperva protects the DNS infrastructure you already operate. You keep control of your DNS servers and workflows.

- #### What happens during a DDoS attack?

All queries are routed through Imperva’s Anycast Scrubbing Centers. Malicious traffic is filtered, and clean queries reach your servers.

- #### Can Imperva protect hybrid or partially internal DNS?

Yes. Imperva supports on‑prem, cloud, hybrid, and custom DNS environments.
