09-09-2015 06:01 AM
I have been noticing that under my domains, I am getting a lot of weird handles. For instance, from pages/services I don't use.
One of them would be yahoo.com/mail.yahoo.com, and the the second being either or sometimes both www.kik.com and talk700an.kik.com. Some days, there will only be say 6 requests... other days there will be upwards of 30.
I don't use yahoo, or have anything relating to yahoo on my computer or droid... same with kik on either. Could this just be some partner port?
09-09-2015 11:05 AM
Everything you see in your domain stats are DNS lookups out of your network as long as you registered the right IP address information with OpenDNS. DNS activity is not necessarily related to human activity and especially not necessarily related to web browser activity, but raised automatically for many reasons, by nearly all networking applications and devices.
Another source of useless DNS queries are browsers where DNS prefetching is enabled, often by default. You may want to disable this.
To find out what devices and applications certain DNS lookups come from, you had to install a sniffer program on all devices in question or on a central device with logging facilities where all DNS traffic goes through.
Not sure though what you could mean by "partner port"...
09-09-2015 11:58 AM
You know its funny, I have been sniffing but haven't noticed anything yet. So far from what it looks like, the DNS activity for this one is coming from an android phone (my phone), as the "an" in talk700an.kik.com points to the android version (the iphone version is talk7XXip.kik.com). What I am concerned about is that I do not have kik, and have never installed kik. I am the only user of my network (verified this).
What I meant by partner port (please excuse me, I don't know the lingo), sometimes an application will have multiple services including that of other companys (for instance, google hangout using parts of kik... note this is just an example and would most likely not be true).
Thanks for the help.
09-09-2015 11:30 PM
Ok, it seems you have it narrowed down. What you can do else is to configure the OpenDNS resolver addresses only on the Android phone for a day or two, and not on any other device or the router. If the unexpected domains still appear, you can be pretty sure that the DNS lookups come out of your smartphone.
09-10-2015 08:19 AM
Ok rotblitz, I will give that a try.
Thank you for your help!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide