# DNS DDoS via multiple exit relays causing performance issues?

**URL:** https://forum.torproject.org/t/dns-ddos-via-multiple-exit-relays-causing-performance-issues/8016
**Category:** Relay Operator
**Created:** [June 15, 2023, 10:38pm UTC](https://forum.torproject.org/t/dns-ddos-via-multiple-exit-relays-causing-performance-issues/8016 "2023-06-15T22:38:17Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![cozybeardev](https://forum.torproject.org/letter_avatar_proxy/v4/letter/c/90ced4/32.png) [@cozybeardev](https://forum.torproject.org/u/cozybeardev)
#### Post date: [June 15, 2023, 10:38pm UTC](https://forum.torproject.org/t/dns-ddos-via-multiple-exit-relays-causing-performance-issues/8016/1 "2023-06-15T22:38:17Z")

</div>

Hi,

I’ve never observed this before, and want to ask if anyone has experienced this themselves. On a few exit nodes, I have the issue that unbound suddenly goes to a sustained 100% CPU usage. It’s killing my relay bandwidth and DNS performance (normal circuits / users are not able to resolve anymore). A restart of the service solves, but sometimes the issue returns. The only reasonable explanation I’ve been able to come up with, is that someone is using my relays to perform DNS based DDOS attacks. Is this really a plausable scenario? I don’t have any custom unbound config, it’s just install and go.

---

<div class="post-metadata">

### Author: ![gus](https://forum.torproject.org/user_avatar/forum.torproject.org/gus/32/16_2.png) [@gus](https://forum.torproject.org/u/gus)
#### Post date: [June 15, 2023, 10:43pm UTC](https://forum.torproject.org/t/dns-ddos-via-multiple-exit-relays-causing-performance-issues/8016/2 "2023-06-15T22:43:33Z")

</div>

Hello, yes, some exit operators reported that issue last year.  
You may find this project by Artikel10 useful:

> **[GitHub - artikel10/surgeprotector: Block Tor Exit traffic to flooded IP...](https://github.com/artikel10/surgeprotector)**
>
> Block Tor Exit traffic to flooded IP addresses via ExitPolicy. - GitHub - artikel10/surgeprotector: Block Tor Exit traffic to flooded IP addresses via ExitPolicy.

From tor-relays mailing list:

> [@\[tor-relays\] Performance issues/DoS from outgoing Exit connections](https://forum.torproject.org/t/tor-relays-performance-issues-dos-from-outgoing-exit-connections/5262):
>
> Hello, on the evening of 2022-10-18, we (Artikel10) started getting alerts about our Tor servers, while our traffic declined sharply. When we investigated, we found that there were hundreds of thousands of TCP connections (per server) open to a single address, orders of magnitude more than any other address. We blocked this address via “ExitPolicy reject”, then another one, and since then things seem to have improved. I have thrown together a small Python script to detect this and generate “Ex…

---

<div class="post-metadata">

### Author: ![system](https://forum.torproject.org/uploads/default/original/2X/d/d3424bed34f4ec18b2e99178c2801ba6dfb655d6.png) [@system](https://forum.torproject.org/u/system)
#### Post date: [June 22, 2023, 6:51pm UTC](https://forum.torproject.org/t/dns-ddos-via-multiple-exit-relays-causing-performance-issues/8016/3 "2023-06-22T18:51:09Z")

</div>

This topic was automatically closed 24 hours after the last reply. New replies are no longer allowed.
