DOMAINTOOLS’ investigation details an unprecedented surge in DNS activity in March 2026 that pointed to VPN-over-DNS activity rather than a conventional DNS anomaly. The flood began around 07:00 UTC on 1 March 2026, rapidly escalating to more than 40 billion observations across the network within days. The spike centred on a single domain, supaghost[.]cc, with DNS TXT records containing highly structured payloads.
The data suggested bidirectional VPN-like traffic carried over DNS, using TXT records and algorithmically generated subdomains to move data in and out of networks and to an exit node, often via inexpensive or secondary servers. The observed RDATA payload appeared to be multiple binary packets multiplexed into TXT records, decoded and delivered through a VPN-over-DNS architecture.
The team’s analysis linked the surge to patterns consistent with VPN-over-DNS activity, noting that several NS records under supaghost[.]cc and related domains were used to route traffic via auxiliary resolvers, sometimes resolving to a Cloudflare-protected exit. By early March 2026, the flood had spread beyond a single domain to dozens, with Iranian top‑level domains disproportionately represented among the clusters.
While the analysts emphasise that they did not decrypt the data and cannot prove attribution, multiple indicators pointed toward Iranian-origin traffic and regional data transit to an ally, versus civilian background noise. The report stresses that the observation is technical and observational, inviting other researchers to share corroborating evidence while avoiding speculative conclusions.