---
id: "fast-flux"
kind: "glossary-term"
title: "fast flux"
language: "en"
category: "Security and abuse"
updated: "2026-10-04T14:01:23Z"
canonical: "https://tldlog.com/glossary/fast-flux/"
translations:
  es: "https://tldlog.com/es/glosario/fast-flux/"
  de: "https://tldlog.com/de/glossar/fast-flux/"
  fr: "https://tldlog.com/fr/glossaire/fast-flux/"
  it: "https://tldlog.com/it/glossario/fast-flux/"
  pt-BR: "https://tldlog.com/pt/glossario/fast-flux/"
  ru: "https://tldlog.com/ru/glossariy/fast-flux/"
  zh-Hans: "https://tldlog.com/zh/cihui/kuaisu-tongliang/"
---

# fast flux

A technique where the IP addresses behind a domain name change every few minutes, cycling through many hacked machines. It hides the real server and defeats blocking by address. In double flux the name servers rotate too. Suspending the domain is often the remedy that works.

## related terms

- [botnet](https://tldlog.com/glossary/botnet/)
- [DNS abuse](https://tldlog.com/glossary/dns-abuse/)
- [TTL](https://tldlog.com/glossary/ttl/)
- [command and control domain](https://tldlog.com/glossary/c2-domain/)
- [takedown](https://tldlog.com/glossary/takedown/)
