Does a DNS query prove that somebody visited a website?¶
A DNS query shows that a device or network asked for information about a domain. It is useful evidence of interest or system activity, but the next question is what caused it and what followed.
Why the query may exist¶
A person may have typed an address or clicked a link. Queries can also be generated by:
- browser prefetching;
- advertising, analytics, images or fonts loaded by another page;
- apps and background services;
- email previews and automated link scanners;
- security software; and
- operating-system updates or connectivity checks.
For example, Dave receives an email containing an image hosted at news.example. His mail application previews the message and looks up that domain before he opens a browser. The DNS record is genuine, but the cause is automated content loading rather than a deliberate website visit.
Build the conclusion from joined records¶
| Evidence available | What it can support | What remains open |
|---|---|---|
DNS query for news.example | The logging system received a request for information about the name | Which application or process caused it |
| DNS query plus connection to the returned address | A related connection may have followed | Whether the traffic was a web page, embedded content or another service |
Proxy, browser or application record naming news.example | The named application or service handled the event | What a person saw or intended, unless the record captures that context |
| Service-side session or account event | The service recorded a corresponding activity | Who controlled the account or device at the time |
The evidence becomes more specific as independent records join the name lookup to a connection, application and service event. Compare timestamps, device or client identifiers and session context before treating them as one chain.
What to do next¶
Use the DNS query log as the starting point and look for activity around the same time:
- a connection to an address returned by DNS;
- a hostname, URL or SNI value in network records;
- browser history or cached content;
- proxy or application logs;
- account activity; or
- access records held by the service.
Also identify where the DNS record was created. A local resolver may identify the requesting device, while an authoritative server may show only the public resolver that asked the question.
If there is no DNS query¶
The device may have used a cached answer, another resolver, encrypted DNS, a VPN, a local configuration or the IP address directly. Check the other available records before treating the absence as significant.
A useful way to describe it¶
The query supports the conclusion that the device or network sought DNS information about the domain at the recorded time. The surrounding records can then show whether a connection followed and what the user or application did.
Operational takeaway
A DNS query is useful evidence of a name lookup, not proof of a website visit. Identify the process or device that caused it, then join it to connection, application and service records.