Unexpected redirects: investigate router DNS tampering

Distinguish local DNS tampering, website redirects and certificate failures using repeatable checks.

Contents of this article

Compare networks and devices

CNCERT’s June 1, 2026 notice links some unexpected redirects to altered router DNS settings. If several devices fail on one Wi-Fi network but work elsewhere, investigate local networking before concluding that the website origin is compromised.

Separate resolution from redirects

Record the time, original hostname, destination page, resolver and answers. Inspect WAN, LAN and DHCP settings; a local router address may represent DNS forwarding. CDN answers can legitimately vary, so compare configuration and observations from trusted networks.

Respect HTTPS validation

DNS tampering does not automatically give an attacker a valid certificate. Do not bypass browser certificate errors or enter credentials. Operators should separately inspect certificate names, validity, redirects and authoritative DNS change history.

Follow up after restoring DNS

Update firmware, restore trusted DNS and secure router administration according to vendor guidance. If credentials were entered on a suspicious page, change them and revoke suspect sessions. Retest multiple devices and watch for repeated configuration changes.

References

CNCERT DNS risk notice

Continue reading

Read related content

Back to industry insights Contact technical support