الرئيسية / English / Study Finds Widespread DNS Weaknesses in Saudi Domains

Study Finds Widespread DNS Weaknesses in Saudi Domains

More than half of the domains measured showed at least one DNS delegation defect. The findings, however, do not mean that half of Saudi websites are hacked, insecure or offline.

أقرأ النسخة العربية

By: Abdulrahman Abotaleb
By: Abdulrahman Abotaleb

Before a user reaches a hospital, university, government agency or company website, a largely invisible layer of the internet has to direct that request to the right place.

That layer is the Domain Name System, or DNS, the infrastructure that translates human-readable website names into the numerical addresses computers use to communicate.

A recent study of Saudi Arabia’s DNS infrastructure has found widespread weaknesses in the Domain Name System (DNS). It found delegation defects in more than half of the domains it measured across the categories examined. It also identified substantial differences in resilience between domain groups, with health-related .med.sa domains ranking lowest in a composite resilience assessment developed by the researchers.

Researchers examined 25,811 Saudi domains, about 35.2% of the registered domains reported in registry statistics available during the study. Across the domain categories assessed, between 51.3% and 53.3% showed at least one DNS delegation defect.

DNS delegation tells the internet which name servers are responsible for a domain. Misconfigurations can increase delays or contribute to resolution failures, although the study did not examine actual outage records.

That distinction is important: the findings do not mean that half of Saudi websites are hacked, insecure or offline. They describe weaknesses in externally visible DNS configurations, not the overall cybersecurity of the websites or organisations behind them.

Health domains rank lowest

The researchers assessed resilience across seven areas, including server redundancy, delegation correctness, network consistency, Anycast and DNSSEC adoption, third-party provider dependence and caching efficiency.

They combined these measures into a Composite DNS Resilience Index (CDRI). Health-related .med.sa domains ranked last among the ten categories, scoring 0.097, compared with 0.623 for .sa and 0.549 for .gov.sa.The score does not mean health domains are “9.7% secure.” CDRI is a relative index for comparing categories within the study, not an absolute measure of cybersecurity.

Still, the health category remained last when the researchers recalculated the index using alternative weighting schemes, suggesting that its position was not simply a product of the original weighting choices.

Individual measurements reinforce that finding. Only 4.7% of .med.sa domains used Anycast, a technology that distributes DNS services across multiple network locations, compared with 13.4% of government domains. Parent–child DNS inconsistencies affected 9.1% of health domains, compared with 4% of .sa domains.

But the researchers caution that these measurements cannot establish that Saudi Arabia’s healthcare sector is broadly cyber-insecure. They capture externally observable DNS infrastructure, not internal backup systems, recovery arrangements or other security controls.

Limited deployment of DNS protections

 The study also found relatively limited adoption of DNSSEC, which uses cryptographic signatures to help verify that DNS information is authentic and has not been altered.

Government .gov.sa domains recorded the highest DNSSEC adoption in the study at 13.2%. The researchers stress that DNSSEC primarily protects the authenticity and integrity of DNS data; its absence does not by itself mean that a website is unavailable or insecure overall.

Network diversity was another concern. The average number of authoritative name servers ranged from 2.16 to 2.79 per domain, depending on category. For health domains with multiple name servers, only 25.1% distributed them across more than one autonomous network system, limiting protection against failures affecting a single network.

A broad snapshot, not a complete census

 Although the study uses historical DNS observations dating from 1994 to 2024, the resilience measurements themselves were collected during a much shorter period, from 4 September to 30 December 2024. The historical data were primarily used for domain discovery and reconstructing the observable ecosystem.

The authors also acknowledge important limitations. The dataset is not a complete census of Saudi domains, and some active measurements were conducted from a single geographic vantage point. Some indicators, including Anycast deployment, were inferred from external network measurements and may not capture internal resilience arrangements.

The researchers do not claim the problems are unique to Saudi Arabia. Similar DNS weaknesses have been documented internationally, while differences in datasets and methods make direct country-to-country comparisons unreliable.

Their recommendations include correcting delegation errors, increasing network diversity, and expanding DNSSEC and Anycast deployment.

The study’s central message is therefore narrower — but more consequential — than a claim that Saudi websites are broadly insecure: a critical layer used to reach digital services shows measurable resilience gaps, with health-related domains emerging as the weakest category in the study.

شاهد أيضاً

shutterstock_1978889621-1721128721

Dynamic Web Mining Could Make E-Learning More Personalized, Yemeni researchers Finds

SANAA, Yemen — Dynamic web usage mining techniques are increasingly replacing traditional data mining approaches …