Unexpected redirects: investigate router DNS tampering
Distinguish local DNS tampering, website redirects and certificate failures using repeatable checks.
Contents of this article
Compare networks and devices
CNCERT’s June 1, 2026 notice links some unexpected redirects to altered router DNS settings. If several devices fail on one Wi-Fi network but work elsewhere, investigate local networking before concluding that the website origin is compromised.
Separate resolution from redirects
Record the time, original hostname, destination page, resolver and answers. Inspect WAN, LAN and DHCP settings; a local router address may represent DNS forwarding. CDN answers can legitimately vary, so compare configuration and observations from trusted networks.
Respect HTTPS validation
DNS tampering does not automatically give an attacker a valid certificate. Do not bypass browser certificate errors or enter credentials. Operators should separately inspect certificate names, validity, redirects and authoritative DNS change history.
Follow up after restoring DNS
Update firmware, restore trusted DNS and secure router administration according to vendor guidance. If credentials were entered on a suspicious page, change them and revoke suspect sessions. Retest multiple devices and watch for repeated configuration changes.
