Pharming sends you to a fake website even when you type the correct address. Instead of tricking you with a link, the attacker corrupts the step that turns a domain name into a server address: your device’s hosts file, its DNS settings, your home router, a DNS resolver, or the domain’s own DNS records. This page walks through each of those five points.
The word joins phishing and farming, because one change can harvest many victims at once. If you want the short comparison with ordinary phishing, read the difference between phishing and pharming. Here we stay with the mechanics.
What normally happens when you type an address
Computers connect to IP addresses, not names. When you type a bank’s web address, a lookup happens before the page loads:
- Your device checks its own hosts file and its recent lookups.
- If it has no answer, it asks a DNS resolver. Which resolver depends on your device settings, which usually come from your router, which usually points to your internet provider.
- The resolver asks the domain’s authoritative name servers, which hold the real records set by the domain owner through a registrar or DNS host.
- The answer, an IP address, comes back and is cached for a while at each step.
Every step in that chain trusts the step after it. Pharming means planting a false answer at one of them.
The five places pharming happens
1. The hosts file on your device
Every computer has a small local file that maps names to addresses and is checked before any DNS server. Malware that adds a line such as the bank’s name next to the attacker’s IP address redirects that one device, quietly and permanently, until the line is removed.
2. The DNS settings on your device
Instead of editing the hosts file, malware can switch the device to a DNS server the attacker runs. That server answers honestly for most sites and lies about the few that matter. This is how DNSChanger worked. In November 2011 US prosecutors announced Operation Ghost Click, which led to the arrest of seven people who had infected millions of computers with it, as described in CISA’s DNSChanger alert.
3. Your home or office router
A router hands out DNS settings to every phone and laptop that joins the network. If an attacker logs into its admin page, often with a default password, or exploits old firmware, one change redirects every device in the house or office. The devices themselves look clean, which makes this hard to notice.
4. A DNS resolver’s cache
Resolvers cache answers so they don’t have to ask every time. Cache poisoning means getting a forged answer into that cache, so everyone who uses the resolver receives it. The CERT Coordination Center’s note VU#800113, first released in July 2008, describes how weaknesses in the DNS protocol and common DNS software made this possible. One example it gives: the protocol’s transaction ID has only 16 bits, so even a properly random ID takes on average 32,768 guesses to match. Resolver software has since added source port randomisation, and DNSSEC lets resolvers check that answers were signed by the domain owner.
5. The domain’s own DNS records
The most damaging version skips the user entirely. The attacker steals the login for the account at the registrar or DNS host and edits the real records. In January 2019 CISA issued Emergency Directive 19-01 after attackers did this to US government domains. The directive explains that they changed address, mail (MX) and name server records to point at servers they controlled, and could then read web and mail traffic before passing it on.
Why the padlock doesn’t save you here
With most phishing, a wrong domain name gives the game away. With pharming, the address bar shows the right name. In the registrar attack, it can show a valid padlock too. Emergency Directive 19-01 notes that an attacker who can set a domain’s DNS records can also obtain valid encryption certificates for it, so users receive no warning at all.
In the device and router attacks, the attacker usually can’t get a certificate for the real domain, so a certificate warning on a site you use every day is one of the few visible clues. Don’t click through it.
How to defend against each type
| Attack point | What protects you |
|---|---|
| Hosts file and device DNS settings | Up to date security software, no admin rights for daily use, periodic checks of the configured DNS server |
| Router | Change the default admin password, update the firmware, turn off remote administration |
| Resolver cache | A resolver that validates DNSSEC and is kept patched |
| Domain records | MFA on registrar and DNS accounts, registry lock, DNSSEC signing, alerts on any record change |
| All of them | Passkeys or hardware security keys, which won’t sign in to a server that isn’t the real site |
Organisations should also watch Certificate Transparency logs for certificates they didn’t request, which is one of the actions Emergency Directive 19-01 required. A new certificate for your domain that nobody on your team ordered is an early sign that someone has your DNS. Our guide to domain name protection covers registrar security in more detail, and these pharming prevention strategies cover what users can do day to day.
FAQ
Can HTTPS protect me from pharming?
Partly. If your device or router was tampered with, the fake server usually can’t present a valid certificate for the real domain, so your browser shows a warning. Heed it. If the attacker controls the domain’s DNS records, they can get a valid certificate and HTTPS shows no warning. That is why domain owners need MFA, registry lock and certificate monitoring.
Is pharming the same as DNS spoofing?
They overlap. DNS spoofing means giving a false DNS answer, and it is one way to carry out pharming. Pharming is the wider goal of sending people to a fake site through the address system, which can also be done by editing a hosts file, changing a router’s settings or taking over a registrar account. All of them end with a correct name and the wrong server.
How do I check whether my router’s DNS has been changed?
Log in to the router’s admin page using the address printed on the device and look at the DNS server fields under internet or WAN settings. They should be empty, set to automatic, or set to a resolver you chose deliberately. Unknown addresses are a warning sign. Reset the router, change the admin password and install the latest firmware.
