STIGQter STIGQter: STIG Summary: Microsoft Windows Server Domain Name System (DNS) Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Jul 2026:

Windows DNS response rate limiting (RRL) must be enabled.

DISA Rule

SV-259417r961155_rule

Vulnerability Number

V-259417

Group Title

SRG-APP-000247-DNS-000036

Rule Version

WDNS-22-000120

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

As an administrator, run PowerShell and enter the command "Set-DnsServerResponseRateLimiting" to apply default values or "Set-DnsServerResponseRateLimiting -WindowInSec 7 -LeakRate 4 -TruncateRate 3 -ErrorsPerSec 8 -ResponsesPerSec 8".

These settings are just an example. For more information, go to:
https://learn.microsoft.com/en-us/powershell/module/dnsserver/set-dnsserverresponseratelimiting?view=windowsserver2022-ps

Check Contents

As an administrator, run PowerShell and enter the following command:
"Get-DnsServerResponseRateLimiting".

If "Mode" is not set to "Enable", this is a finding.

Vulnerability Number

V-259417

Documentable

False

Rule Version

WDNS-22-000120

Severity Override Guidance

As an administrator, run PowerShell and enter the following command:
"Get-DnsServerResponseRateLimiting".

If "Mode" is not set to "Enable", this is a finding.

Check Content Reference

M

Target Key

5576