Skip to content

Self-Managed Name Server Detected

It indicates that the domain operates using its own name server infrastructure rather than a reputable third-party DNS provider. While legitimate organizations may self-host DNS for flexibility, threat actors often use this approach to maintain full control, obscure DNS changes, and avoid detection mechanisms.

Also surfaces as:
Newly Activated Self-Managed NS
Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does 'Self-Managed Name Server Detected' mean?

It indicates that the domain operates using its own name server infrastructure rather than a reputable third-party DNS provider. While legitimate organizations may self-host DNS for flexibility, threat actors often use this approach to maintain full control, obscure DNS changes, and avoid detection mechanisms.

Why it matters02

Why is self-managed NS considered a malicious indicator?

Because attackers can rapidly update DNS records, re-route traffic, or hide their infrastructure using self-controlled name servers. This behavior is common in phishing, command-and-control (C2), and malware delivery domains that require stealth and agility.

How analysts use it03

Why does 'Newly Activated Self-Managed NS' increase suspicion?

Recently created or switched self-managed NS infrastructure often signals preparation for a malicious campaign. Threat actors frequently deploy new NS configurations just before activating phishing or C2 operations to evade prior detection or blocklisting history.

Often paired with:alert_only
Evidence shape

What Self-Managed Name Server Detected looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "own_ns_usage",
  "name": "Self-Managed Name Server Detected",
  "group": "dns_history",
  "subgroup": "dns_records_mx_ns",
  "direction": "malicious",
  "evidence": {
    "ns_provider": "cloudflare.com",
    "ns_provider_tier": "paid_public",
    "ns_stability_days": 412,
    "mx_provider": "google.com",
    "mx_provider_tier": "paid_mail"
  }
}
See in API reference
Siblings

Peers in DNS Records (MX/NS)

8 other signals share the same subgroup. They detect related behaviors and often co-fire on the same IOC.

Self-Managed Mail Infrastructure Detected

It means the domain operates its own mail exchange (MX) servers instead of relying on trusted third-party providers like

MaliciousCore
Double-Flux Behavior Detected

It indicates that both IP and NS (nameserver) records of a domain are changing frequently, a behavior known as 'Double-F

MaliciousCore
Mail-Flux Behavior Detected

It indicates that the domain frequently changes its MX (Mail Exchange) records. Such behavior is often associated with s

Malicious
Paid Public NS Usage Premium Provider

It indicates that the domain is backed by a paid, reputable DNS provider rather than free or disposable nameservers. Thi

Safe
Show 4 more in DNS Records (MX/NS)
In the wild

See Self-Managed Name Server Detected fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to Self-Managed Name Server Detected. See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.