DNS servers are a favorite tool of attackers for DDoS strikes. Most large-scale DDoS events are innocently assisted by DNS servers as they amplify traffic by repeating and increasing the size of packets sent to DDoS attack targets.
The FortiGuard Domain Reputation Service provides a regularly updated list of known malicious fully qualified domain names (FQDNs). This service is used to prevent DNS servers from reaching known malicious sites and helps prevent attacks that obfuscate source IPs using hijacked domain names.