Almost every attack — phishing, malware delivery, or command-and-control call-home — has to make a DNS lookup before it can do anything. DNSFilter's 2026 annual security report shows that chokepoint is busier and more hostile than ever.
What the data shows
- Threats on the network grew 30% between October 2024 and September 2025.
- The average internet user encountered 66 threats per day in 2025, more than double the 29 seen in 2024.
- Over 7.6 million threat-related domains appeared between August and November 2025 — a 20% increase — much of it dormant infrastructure staged ahead of campaigns.
- Phishing made up roughly 30% of malicious DNS traffic, the leading category, followed by suspicious and malware domains.
Why it matters
Attackers increasingly register large volumes of domains and let them sit unused, so reputation and blocklists that rely on known-bad history miss them at launch. Combined with AI-assisted phishing, that means users face more convincing lures pointing at infrastructure that looks clean — until it isn't. Blocking the lookup is the earliest and cheapest place to break the chain.
