---
id: "dns-hijacking"
kind: "glossary-term"
title: "DNS hijacking"
language: "en"
category: "Security and abuse"
updated: "2026-10-04T14:01:23Z"
canonical: "https://tldlog.com/glossary/dns-hijacking/"
translations:
  es: "https://tldlog.com/es/glosario/secuestro-dns/"
  de: "https://tldlog.com/de/glossar/dns-hijacking/"
  fr: "https://tldlog.com/fr/glossaire/detournement-dns/"
  it: "https://tldlog.com/it/glossario/dirottamento-dns/"
  pt-BR: "https://tldlog.com/pt/glossario/sequestro-dns/"
  ru: "https://tldlog.com/ru/glossariy/perekhvat-dns/"
  zh-Hans: "https://tldlog.com/zh/cihui/dns-jiechi/"
---

# DNS hijacking

An attack that changes the DNS answers users get for a domain, sending them to servers the attacker controls. Attackers may take over the registrar account, the DNS provider or the name server records, or tamper with resolvers or home routers. Registry lock and two-step login help protect the domain's own settings.

## related terms

- [domain hijacking](https://tldlog.com/glossary/domain-hijacking/)
- [registry lock](https://tldlog.com/glossary/registry-lock/)
- [pharming](https://tldlog.com/glossary/pharming/)
- [DNSSEC](https://tldlog.com/glossary/dnssec/)
