Skip to main content

DNS Channel (dns)

  • Default Mode: "block"
  • Target: Core node:dns and dns.promises resolution APIs.
The dns channel intercepts hostname resolution queries to prevent exfiltration through domain lookups and DNS tunneling.

Intercepted APIs

envtrap wraps both callback-style and Promise-style methods:
  • dns.lookup
  • dns.resolve, dns.resolve4, dns.resolve6
  • dns.resolveCname, dns.resolveMx, dns.resolveTxt, dns.resolveSrv
  • All dns.promises.* equivalents

Detection Capabilities

Direct Secret In Hostname

Checks if the requested hostname contains an active secret value (≥8\ge 8 characters). If found, the lookup is blocked before the OS resolver is queried.

Shannon Entropy Tunneling

Splits hostnames into individual subdomain labels and computes their Shannon entropy. Subdomains with length ≥12\ge 12 and entropy ≥3.5\ge 3.5 trigger tunneling warnings.

Cloud Provider Allowlist

Recognizes standard cloud infrastructure suffixes (*.amazonaws.com, *.cloudfront.net, *.azure.com, *.azurewebsites.net, *.mongodb.net, *.googleapis.com, *.google.com) to prevent false-positive tunneling alerts.

FQDN Normalization

Automatically normalizes fully qualified domain names by stripping trailing dots (e.g., api.stripe.com. -> api.stripe.com) prior to evaluation.

Enforcement Modes

Throws a synchronous Error:
The query never reaches external DNS nameservers.

Configuration Example

envtrap.json