Skip to content

Double-Flux Behavior Detected

It indicates that both IP and NS (nameserver) records of a domain are changing frequently, a behavior known as 'Double-Flux'. This technique is commonly used by advanced threat actors to enhance infrastructure resilience and avoid takedown or tracking.

Also surfaces as:
Aggressive Double-Flux Activity
Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does 'Double-Flux Behavior Detected' mean?

It indicates that both IP and NS (nameserver) records of a domain are changing frequently, a behavior known as 'Double-Flux'. This technique is commonly used by advanced threat actors to enhance infrastructure resilience and avoid takedown or tracking.

Why it matters02

What is 'Aggressive Double-Flux Activity'?

This refers to an extreme variant of double-flux behavior where NS and IP changes occur within very short intervals. Such rapid cycling often indicates a highly dynamic and evasive malicious infrastructure.

How analysts use it03

Why is Double-Flux behavior a strong indicator of malicious activity?

Legitimate domains rarely need to rotate NS and IP records frequently. Double-flux techniques are characteristic of botnets, malware delivery networks, and resilient C2 architectures designed to resist disruption.

Often paired with:block_domain
Evidence shape

What Double-Flux Behavior Detected looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "too_many_ns_change",
  "name": "Double-Flux Behavior Detected",
  "group": "dns_history",
  "subgroup": "dns_records_mx_ns",
  "direction": "malicious",
  "evidence": {
    "ns_provider": "cloudflare.com",
    "ns_provider_tier": "paid_public",
    "ns_stability_days": 412,
    "mx_provider": "google.com",
    "mx_provider_tier": "paid_mail"
  }
}
See in API reference
Siblings

Peers in DNS Records (MX/NS)

8 other signals share the same subgroup. They detect related behaviors and often co-fire on the same IOC.

Self-Managed Mail Infrastructure Detected

It means the domain operates its own mail exchange (MX) servers instead of relying on trusted third-party providers like

MaliciousCore
Mail-Flux Behavior Detected

It indicates that the domain frequently changes its MX (Mail Exchange) records. Such behavior is often associated with s

Malicious
Self-Managed Name Server Detected

It indicates that the domain operates using its own name server infrastructure rather than a reputable third-party DNS p

Malicious
Free or Disposable Mail Service Used

It indicates that the domain relies on free or temporary mail providers. Such behavior is common among malicious or low-

Malicious
Show 4 more in DNS Records (MX/NS)
In the wild

See Double-Flux Behavior Detected fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to Double-Flux Behavior Detected. See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.