Hacked DNS or Hacked Website? Telling Them Apart

By · Updated · 4 min read

Visitors are seeing content that is not yours. You log into the server, and your files are exactly as they should be — nothing modified, nothing added, database clean. That combination is confusing until you realize that your domain name and your website are two separate systems, and an attacker who controls the first does not need to touch the second at all.

Two different systems

Your website is files and a database on a server. Your DNS is a set of records, held by whoever manages your domain, that tells the world which server to contact for your domain name. They are operated separately, often by different companies, and secured by completely different credentials.

Change the DNS and you redirect the entire internet to a different server without touching yours. Your real site sits there untouched and unvisited while everyone sees whatever the attacker is hosting. That is why a thorough site cleanup can change absolutely nothing about the symptom.

How to tell which you have

The decisive test is to check where your domain currently points and compare it against where it should point. If the address in your DNS records is not your hosting server, the problem is DNS. If it is your server and your server is serving the wrong content, the problem is the site.

Supporting evidence for DNS: your files and database are demonstrably clean, the change affected everything at once rather than appearing gradually, your email stopped working at the same moment, and requesting the site by its server address directly shows your real content. Supporting evidence for a site hack: modified files, suspicious database rows, entries in your access logs showing the compromise, and content that changed progressively rather than all at once.

What to check in your DNS

Log into wherever your DNS is managed — that may be your registrar, your host, or a service like Cloudflare — and review every record. The A record should point at your hosting server's address. CNAME records should point where you expect. MX records control your email, and altering those lets someone intercept your mail, which is both a serious problem in itself and a route to taking over accounts through password resets.

Look for added records too, not just altered ones. A subdomain you did not create, pointing at an unfamiliar server, is a common way to host phishing pages under your domain's good name while leaving your main site alone so you do not notice. TXT records deserve a look as well, since they carry mail authentication and domain verification tokens.

Fixing DNS control

Change the password on whatever account manages your DNS, enable two-factor authentication, and then correct the records. Check the account for additional users or API keys that were added, since removing an attacker's password accomplishes nothing if they also hold an API token.

Then be patient about propagation. DNS changes take time to spread — anywhere from minutes to a day or so depending on the previous record's cache lifetime — so visitors may keep seeing the wrong content for a while after you have fixed it. That delay is normal and does not mean the fix failed.

When it is worse than DNS

If your DNS was changed because someone got into your registrar account, that is a more serious situation, because from there a domain can be transferred away entirely. My guide on domain hijacking covers that scenario and the steps for getting a domain back.

Check whether the domain is still registered to you, whether a transfer is pending, and whether the registrar lock is still enabled. Enable the lock if it has been turned off. A hijacked domain is recoverable but the process is slow and formal, so catching it early matters a great deal.

Do not assume it is only one

It is entirely possible to have both problems, particularly if the same stolen password opened both doors. A DNS change is a strong reason to also check the site properly rather than concluding it must be fine because the DNS explained the symptom.

Work through both: verify DNS records are correct and the managing account is secure, then check the site for modifications, rogue administrator accounts and backdoors. My guide on identifying website hacks covers the site side, and if you cannot get a clear picture of which layer is compromised, sorting that out is routine work for my malware removal service.

Common questions

How do I check where my domain actually points?

Use any public DNS lookup tool, or your operating system's built-in lookup command, and compare the returned address against your hosting server's address. If they do not match, your DNS has been changed and no amount of work on the server will alter what visitors see.

Can DNS be hacked without my site being hacked?

Yes, and it is a completely separate compromise. DNS is controlled by an account at your registrar or DNS provider, secured by its own credentials. Someone with that access redirects your domain to their server while your site sits untouched, which is exactly why cleaning the site changes nothing.

Why did my email stop working at the same time?

Because MX records live in the same DNS zone. An attacker changing where your domain points frequently changes mail routing too, either to intercept your messages or simply as a side effect of replacing the zone. Mail failing alongside a website problem is a strong indicator that DNS is the layer involved.

How long until a DNS fix takes effect?

Anywhere from a few minutes to about a day, depending on the cache lifetime set on the previous records and on intermediate resolvers. Visitors may keep seeing the old destination during that window. It is normal, and it does not mean your correction failed.

Could both my DNS and my site be compromised?

Certainly, especially if one reused password opened both. Finding a DNS problem is not a reason to skip checking the site. Verify the records and secure the managing account, then still examine the site for modified files, unexpected administrator accounts and backdoors.