Skip to content

Decoys

A decoy is a hostname you plant that no real program on your network has any reason to resolve. A lookup almost always means something is exploring your network, such as a compromised device or a script that tries names until one answers. This is the canary idea applied to DNS, and it costs nothing to run.

Try it: the decoys demo runs Ward’s decision path on a mock home network in your browser.

  • Ward checks decoys before allowlists and blocklists, so nothing can mask a hit.
  • The query is answered locally with the block response and is never forwarded upstream. Forwarding would leak the decoy name to a third party.
  • Ward logs an alert at warning level with the client address, the decoy list id and the matched name. The alert also includes the next step: find out why that client asked.

Pick names that look plausible to something scanning your network and that nothing real uses:

nas-backup.home.arpa
printer-admin.lan
vault.internal.home.arpa

Avoid names that exist in public DNS, and avoid names that a device on your network might try on its own.

ward config export prints your validated configuration so you can share or back it up. Decoys are left out by construction, because the export format has no field for them. Anyone who reads a shared config learns nothing about where your tripwires are.

Decoys only catch lookups. A program that connects straight to an IP address never asks DNS and never trips one. Decoys complement the other tiers and do not replace them.