At e-AGE18 in Amman, Internet Society Puts DNS Security and Privacy in the Spotlight
At the e-AGE18 conference in Amman, the Internet Society urged the Middle East networking community to pay closer attention to DNS security and privacy, key to safer internet browsing.
At the e-AGE18 conference in Amman, Jordan, the Internet Society put DNS security and privacy in the spotlight for the Middle East networking community. The event took place on 2 and 3 December 2018 at the Marriott Hotel, and was organised by the Arab States Research and Education Network.
The Domain Name System (DNS) is often described as the phonebook of the internet. When you type a website name like example.com into your browser, your device asks a DNS resolver, a specialised server, to translate that name into the numerical Internet Protocol (IP) address that computers use to find each other. Without DNS, you would have to remember long strings of numbers for every website you visit.
The problem is that traditional DNS queries are sent in plain text, meaning anyone on the network path, such as a Wi-Fi provider or an internet service provider, can see which websites you are trying to reach. Attackers can also interfere with these queries through techniques such as DNS spoofing, where a fake response redirects you to a malicious site instead of the one you asked for. By discussing DNS security at e-AGE18, the Internet Society aimed to help research and education networks in the region understand these risks and adopt stronger protections.
DNS data is also a privacy concern because the list of domains you look up reveals a detailed picture of your online activity, from the news you read to the services you use. Encrypted DNS protocols such as DNS over HTTPS (DoH), DNS over TLS (DoT) and DNS over QUIC (DoQ) wrap DNS queries in encryption so that outsiders cannot easily eavesdrop on them. While these technologies were still gaining adoption in 2018, they have since become standard tools for privacy-conscious users and organisations.
Another layer of protection is DNSSEC, short for Domain Name System Security Extensions. DNSSEC adds digital signatures to DNS records, allowing a resolver to verify that the answer it receives is authentic and has not been altered in transit. This helps prevent cache poisoning and other spoofing attacks that can silently redirect users to fraudulent websites.
Research and education networks connect universities, schools and scientific institutions, and they handle large volumes of sensitive data. If DNS is compromised on such a network, an attacker could redirect users to fake login pages, intercept email or disrupt access to critical resources. Raising awareness among network operators in the Middle East is therefore essential for protecting both individual privacy and institutional security.
For everyday internet users and website owners, the lessons from e-AGE18 remain relevant today. Choosing a DNS resolver that supports encryption and validates DNSSEC is a simple but effective step toward safer browsing. A privacy-first encrypted DNS service such as AEU DNS offers encrypted DNS queries and built-in filtering for known malicious domains, helping to reduce the risk of interception and unwanted tracking.
Terms explained
- DNS
- The system that translates human-friendly website names like example.com into numerical internet addresses that computers use to find each other.
- Encrypted DNS
- A way of protecting DNS requests by scrambling them so that only the intended DNS server can read them, using protocols such as DNS over HTTPS (DoH), DNS over TLS (DoT) or DNS over QUIC (DoQ).
- Resolver
- The server your device contacts to look up the internet address for a website name.
- Spoofing
- A trick where an attacker sends a fake response to a DNS request to send you to a malicious website instead of the one you intended.
- DNSSEC
- A security add-on for DNS that digitally signs records so you can be sure the answer you receive is genuine and has not been tampered with.
How to protect yourself
- Switch your device or home router to a DNS resolver that supports encrypted DNS (DNS over HTTPS or DNS over TLS) to keep your browsing history private from your internet provider.
- Check your router settings for an option called 'DNS over HTTPS' or 'DNS over TLS' and turn it on if available.
- Use a DNS service that blocks known malicious websites, which can stop phishing and malware before they load.
- Keep your operating system and web browser updated, because updates often include the latest DNS security protections.
- If you run a website, enable DNSSEC through your domain registrar to prevent attackers from spoofing your domain and redirecting visitors to fake pages.
Source: internetsociety.org
