---
id: "dns-tunneling"
kind: "glossary-term"
title: "DNS tunneling"
language: "en"
category: "Security and abuse"
updated: "2026-10-04T14:01:23Z"
canonical: "https://tldlog.com/glossary/dns-tunneling/"
translations:
  es: "https://tldlog.com/es/glosario/tunelizacion-dns/"
  de: "https://tldlog.com/de/glossar/dns-tunneling/"
  fr: "https://tldlog.com/fr/glossaire/tunnel-dns/"
  it: "https://tldlog.com/it/glossario/tunneling-dns/"
  pt-BR: "https://tldlog.com/pt/glossario/tunelamento-dns/"
  ru: "https://tldlog.com/ru/glossariy/dns-tunnelirovanie/"
  zh-Hans: "https://tldlog.com/zh/cihui/dns-suidao/"
---

# DNS tunneling

A technique that hides other data inside DNS queries and answers. Because most networks let DNS traffic pass, malware can use it to receive commands or to smuggle stolen data out. The traffic goes to a domain and a name server run by the attacker. Blocking that domain does not reliably stop it, because attackers switch domains.

## related terms

- [malware](https://tldlog.com/glossary/malware/)
- [command and control domain](https://tldlog.com/glossary/c2-domain/)
- [name server](https://tldlog.com/glossary/name-server/)
- [protective DNS](https://tldlog.com/glossary/protective-dns/)
- [resolver](https://tldlog.com/glossary/resolver/)
