Summary
- On June 29, 2026, DNS root operators began seeing about twice the normal query rate: roughly 3.2 million queries per second, compared with a baseline near 1.6 million.
- An operator in a related autonomous system confirmed that the traffic came from its networks and followed recent recursive-resolver software updates. The report calls the change unintended, says root service suffered no measurable impact, and does not identify the network, vendor, version, or exact mechanism.
At noon UTC on June 29, the DNS root started receiving a very different workload. Root Server Operators (RSOs) reported that the system-wide average had climbed from approximately 1.6 million queries per second to 3.2 million. The increase appeared across root-server identities and multiple metro locations, particularly on the US East Coast and in Europe. Individual identities did not move in lockstep.
The traffic did not look like a flood of malformed packets. Operators found well-formed, query-name-minimized requests from tens of thousands of source IP addresses, concentrated on five top-level domains: .com, .net, .org, .info and .uk. Their early analysis pointed to several related autonomous systems. After repeated outreach, a representative of one originating AS confirmed on July 3 that the requests came from its own networks, rather than spoofed source addresses. The representative said recent recursive-resolver software updates had unintentionally produced the increase.
The chronology matters. Traffic briefly fell for about two hours on July 3, then returned to its elevated level. Following more outreach on July 6, it began returning to normal on July 7. The public account does not say whether the network held a rollout, changed a setting, rolled software back, or made some other correction. It identifies an update as the source of the behavior, but leaves the specific change undisclosed.
That distinction is useful because a root query is an upstream consequence, not a direct count of people looking up names. DNS resolvers cache answers; the Root Server Operators FAQ says only a small fraction of ordinary lookups normally require a new root contact. A software change in a large recursive network can therefore alter the workload seen by root operators without a matching increase in end-user demand. The report does not establish whether users noticed anything, nor does it quantify costs within the originating networks.
It does make a narrower service finding: operators detected no measurable effect on root-server availability or performance. They did not regard the increase as an intentional attack or an operational hazard, and did not mitigate it. That is evidence of capacity under this observed event, not proof that any traffic increase is harmless. The operators cited RSSAC001's expectation that each root operator make reasonable efforts to accommodate substantial traffic fluctuations.
The evidence also has limits. “All root-server identities” describes the report's observed identity-level scope; it does not establish identical load at every anycast instance. “Recent recursive-resolver software updates” is the attribution confirmed by an AS representative; the report names no AS, supplier, version, configuration change, or precise query-generation mechanism. It describes minimized queries, but does not say that QNAME minimisation caused the increase. RFC 9156 notes that resolver query counts can vary with cache and name structure, which is context rather than an explanation of this episode.
The best reading is neither “attack” nor “nothing happened.” A distributed update changed an upstream query pattern, root operators saw the change, and a conversation with the source network preceded normalization. The root remained available. The operational question is whether the next such signal can be connected to a deployment quickly enough to distinguish an unintended behavior change from malicious traffic or a capacity problem.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
