DNS Sinkhole
Embed This Widget
Add the script tag and a data attribute to embed this widget.
Embed via iframe for maximum compatibility.
<iframe src="https://tldfyi.com/iframe/glossary/dns-sinkhole/" width="420" height="400" frameborder="0" style="border:0;border-radius:10px;max-width:100%" loading="lazy"></iframe>
Paste this URL in WordPress, Medium, or any oEmbed-compatible platform.
https://tldfyi.com/glossary/dns-sinkhole/
Add a dynamic SVG badge to your README or docs.
[](https://tldfyi.com/glossary/dns-sinkhole/)
Use the native HTML custom element.
DNS sinkhole là cấu hình [[dns-zone|DNS zone]] hoặc [[recursive-dns|resolver]] trả về địa chỉ IP không thể định tuyến hoặc được kiểm soát cho các tên miền liên quan đến phần mềm độc hại, máy chủ C&C botnet, trang web lừa đảo hoặc cơ sở hạ tầng độc hại khác. Các nhóm bảo mật và ISP triển khai sinkhole để vô hiệu hóa mối đe dọa bằng cách chuyển hướng lưu lượng độc hại đến một endpoint được kiểm soát thay vì để nó đến đích dự định. Sinkhole cũng cho phép phân tích lưu lượng: mỗi lần thử kết nối đến IP sinkhole đều tiết lộ một máy chủ bị nhiễm. Các dịch vụ thương mại như Cloudflare Gateway, Quad9 và nền tảng bảo mật DNS doanh nghiệp triển khai sinkholing như một tính năng cốt lõi.
Ví dụ
When Quad9 (9.9.9.9) receives a query for a known malware C2 domain, it returns a sinkhole IP instead of the real address, preventing the infected host from communicating with the attacker's server.