How to Verify DNS Sinkholing on 9.0 and 9.1

How to Verify DNS Sinkholing on 9.0 and 9.1

Created On 03/31/20 17:31 PM - Last Modified 05/13/20 13:57 PM


Before PAN-OS 9.0, performing a DNS query to a malicious domain that matches Palo Alto Networks DNS signature will resolve to the sinkhole IP address:

From PAN-OS 9.0 onward performing a DNS query to a malicious domain that matches Palo Alto Networks DNS signature or DNS Security service does not resolve to sinkhole IP addresses.

When a DNS lookup to a malicious domain is performed, this CNAME will be returned instead of an A or AAAA record This is why when you look at the DNS Sinkhole settings box you see Sinkhole IPv4 Palo Alto Networks Sinkhole IP ( instead of what you used to see on older OSs, Palo Alto Networks Sinkhole IP (

When moving from 8. OS lines this can be confusing. We are used to seeing the Palo Alto Sinkhole address. (



To test DNS sinkhole functions it is best to get a new URL from the latest published list of malicious URLs.
To get this list go to the Device tab and select Dynamic Updates and check the release notes for the currently installed AV content.
User-added image
The list will show up in a new window, simply scroll down the list until New Spyware Signatures is seen.

User-added image
Select any Domain from the list. Be sure you only select the FQDN and not the signature.
The first part is the signature name
Backdoor.bladabindi the second half is the FQDN which is the part you need to use to test.
For example
the only part you need is

When performing an Nslookup on a firewall with an OS of 8.1 we see the Palo Alto Sinkhole IP
User-added image
Now with 9.0 we see the non authoritative answer but no address. This is because the response is a cname not an address.
User-added image
If we type in >set type=cname we get the following.
User-added image
As you can see the DNS request now returns the Cname of

If you need an IP address to show it is recommended to use one of your own sinkhole IP addresses or the loopback address.
User-added image
On 9.0 and 9.1 Palo Alto Networks DNS signature or DNS Security service does not resolve to sinkhole IP addresses. It will only resolve a Cname and only if you set nslookup to show it.
The request will still be sinkholed and blocked it just does not resolve an IP address.

If set to the loopback address or an address of your choosing the return will be that address, and the request will still be sinkholed.


  • Print
  • Copy Link

Choose Language