> Source: [sk184533](https://support.checkpoint.com/results/sk/sk184533)

# sk184533 - Security Gateway initiates outbound DNS queries to external domains that appear suspicious

| Property | Value |
|----------|-------|
| Solution ID | sk184533 |
| Date Created | 2026-01-07 |
| Last Modified | 2026-01-08 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- Continuous outbound DNS queries originate directly from the Security Gateway IP address toward external domains that appear suspicious (for example, randomized domain names, dynamic hosting platforms, or free hosting domains).

These DNS queries:

* Are visible in packet captures and connection tables as sourced from the Security Gateway IP
* Target large volumes of domains
* Appear repetitive or continuous
* Originate from the Security Gateway itself (not from NATed internal clients)

## Cause

In some deployments, the Security Gateway initiates outbound DNS queries as part of normal policy enforcement. This can occur when the installed policy includes domain-based matching elements, such as:

* Domain Objects (FQDN or non-FQDN modes)
* External Network Feeds that contain domain names (FQDNs or wildcard domains)
* Other dynamic or updatable objects that include domain entries

To enforce these objects, the Security Gateway must periodically resolve domain names to IP addresses and refresh cached results according to DNS Time-to-Live (TTL) and object or feed update intervals.

If the referenced lists contain many entries, dynamic domains, or domains that appear suspicious (for example, free-hosting or randomized subdomains), the resulting DNS activity can look unusual even though it is expected.

Therefore, outbound DNS queries sourced from the Security Gateway IP addresses are not necessarily an indication of compromise, but can be a by-design outcome of configured policy objects that require DNS resolution.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
