In an attempt to detect whether a network will hijack DNS queries, Google's Chrome browser and similar Chromium-based programs randomly generate three domain names between 7 and 15 characters to test, and if the response from two domains returns the same IP, the browser believes the network is being "hijacked" and redirects nonexistent domain requests.
This test is completed at startup and whenever IP or DNS settings change.
Because of the way DNS servers forward locally unknown domain queries to more authoritative name servers, the random domains used by Chrome find their way to DNS root servers, and, according to Verisign's principal engineer in the CSO applied research division, Matthew Thomas, these queries account for half of all queries to the root servers.

The data Thomas presented showed that as Chrome's market share increased after the feature in 2010, queries matching the pattern Chrome uses also increased.
“In the 10+ years since the feature was added, we now find that half of DNS root server traffic is likely due to crawlers ,” Thomas said in an APNIC blog post. “This equates to approximately 60 billion queries to the root server system on a typical day.”
Thomas added that half of the root servers' DNS traffic is used to support a browser's functionality, and with DNS monitoring being "certainly the exception rather than the rule," the traffic would be a distributed denial of service attack in any other scenario.
Earlier this month, Sans Institute Dean Johannes Ullrich looked at how many of the world's 2.7 million authentic name servers it would take to disable 80% of the internet.
“Only 2,302 name servers are needed,” Ullrich said.
“0.35% of name servers are responsible for 90% of all domain names.”
Ullrich found that GoDaddy was responsible for 94.5 million records, Google Domains had 20 million, the trio of dns.com, hichina, and IONOS had 15.6 million each, while Cloudflare had 13.8 million records.
“Using a cloud-based DNS service is simple and often more reliable than running your own name server. But this large concentration of name server services with a few entities significantly increases the risk to the infrastructure,” he said.
To reduce the risk of a provider being out of business by parts of the internet, Ullrich said people should run internal name servers and make sure to use more than one DNS provider.
Telstra provided an example of how a DNS failure can appear as an internet outage to users , and in this case, the telco successfully carried out a denial of service attack on its own.
"The massive messaging storm that presented itself as a denial of service attack has been investigated by our security teams and we now believe the incident was not malicious, but a Domain Name Server issue," the telco said earlier this month.
Last month, Cloudflare provided a similar example on a much larger scale.
