Privacy controls
CyberFurl can load analytics only after you opt in. Core product features work without analytics consent.
Detect misconfigured DNS servers acting as open resolvers. Prevent your infrastructure from being weaponized in high-volume volumetric Distributed Denial of Service (DDoS) reflection attacks by validating recursion and rate-limiting policies against RFC 5358 and BCP 140.
DNS Amplification is an asymmetric reflection attack that leverages UDP's stateless nature and small spoofed queries to solicit disproportionately large responses (like ANY or DNSSEC-signed TXT records). A single misconfigured open resolver can amplify attack traffic by a factor of up to 50x to 100x, debilitating target networks, saturating upstream bandwidth, and potentially leading to infrastruc
DNS Amplification is an asymmetric reflection attack that leverages UDP's stateless nature and small spoofed queries to solicit disproportionately large responses (like ANY or DNSSEC-signed TXT records). A single misconfigured open resolver can ampli
Allowing unrestricted recursive queries from the public internet instead of limiting to internal subnets or trusted clients.
Sends a non-recursive DNS query to the target IP to verify basic DNS availability, then tests recursive query handling.
Issues a recursive ANY-record query and measures the byte-size ratio of query-to-response to calculate amplification factor.
Simulates burst query traffic to determine if the resolver implements Response Rate Limiting (RRL) as per RFC 8020.
Generates a comprehensive report highlighting open recursion vulnerabilities, amplification factor scores, and configuration fixes.
Accurately identifies if your DNS server processes recursive queries for arbitrary external domains, violating RFC 5358 best practices.
Measures the byte-size ratio of query-to-response using ANY or TXT queries to quantify the exact amplification multiplier your server provides.
Evaluates how your server handles EDNS0 pseudo-records and DNSSEC (DO flag) queries, which are frequently exploited for maximum payload size.
Checks both UDP (the primary vector for spoofing) and TCP handling to ensure complete coverage of your DNS transport layer security.
Simulates burst query traffic to determine if your resolver employs RRL mechanisms to truncate or drop abusive query volumes.
Provides actionable, platform-specific configuration snippets (e.g., BIND ACLs, CoreDNS policies) to securely lock down recursive functionality.
Stop your servers from being weaponized. Run a comprehensive open resolver test and close amplification vectors instantly.