Back to Projects
Business Systems House 2026

Domain Name System (DNS) Security Hardening & Split-Brain DNS

Domain Name System (DNS) Security Hardening & Split-Brain DNS
Windows Server DNS BIND Split-Brain DNS DNSSEC DNS Sinkholing Umbrella

Domain Name System (DNS) Security Hardening & Split-Brain DNS

Hardened internal and external DNS infrastructure to eliminate internal IP disclosure while enforcing secure domain resolution.

Key Features & Implementation

  • Split-Horizon / Split-Brain DNS: Configured separate internal and external DNS zones so corporate FQDNs resolve to private IPs internally and public IPs externally.
  • DNS Threat Sinkholing: Configured DNS recursion rules to sinkhole known malicious malware and command-and-control (C2) domains.
  • Cache Poisoning Mitigation: Enabled DNS socket pooling, response rate limiting (RRL), and restricted zone transfers to authorized secondary servers.
ROOT ACCESS GRANTED