Lessons from C3SA's webinar on "The State of DNS Resilience in Southern Africa"
Cape Town — 29 July 2026. More than 70 participants from academia, government, industry, and civil society joined a webinar hosted by the Cybersecurity Capacity Centre for Southern Africa (C3SA), led by Professor Wallace Chigona, in partnership with the University of Cape Town, to examine a piece of internet infrastructure most users never think about: the Domain Name System. The message from the panel was consistent: DNS abuse across the region persists, driven primarily by a critical lack of DNS sovereignty, weak technical configurations, systemic infrastructure vulnerabilities, regulatory gaps, and low awareness of the evolving threat landscape.
The session, titled "The State of DNS Resilience in Southern Africa," brought together Dr. Josiah Chavula of UCT, Dr. Adebunmi Adeola of ISOC Nigeria, and Mr. Kuben Reddy of Liquid C2, with additional input from Mark Elwins of Posix Systems and Dr. Luzuko Tekeni of UCT. Dr. Laban Bagui moderated the discussion. A dedicated conversation on DNS resilience has become urgent as African nations confront increasingly sophisticated domain name system abuse across critical digital infrastructure.
"On Sovereignty: DNS Control Is a Security Imperative" (Mr Kuben Reddy)
DNS sovereignty is not a technical nicety; it is the precondition for regional security, and right now the region does not have it. South Africa anchors Southern Africa's connectivity through major subsea cable landings (including WACS, 2Africa, and Equiano), but landlocked neighbouring states remain dependent on coastal transit, and the region as a whole leans heavily on foreign-operated public resolvers such as Cloudflare's 1.1.1.1 and Google's 8.8.8.8. That dependency has a cost: a 62-minute global outage of Cloudflare's resolver on 14 July 2025 was enough to disrupt resolution across dependent networks. By contrast, Mr Reddy pointed to South Africa's locally managed .za namespace, under ZADNA, as a model for the sovereignty the region needs more of.
Internet Exchange Points emerged as the region's best defence against exactly this kind of exposure. NAPAfrica, peaking at 6 Tbps across more than 680 networks, keeps query traffic local and allows DNS resolution to continue even when international subsea cables are cut, provided root and ccTLD anycast instances are hosted at the exchange itself. But Reddy warned that security gaps persist even within well-governed namespaces: although .za's top-level zone is signed and locally managed, fewer than 1% of second-level .za domains carry DNSSEC, leaving the region exposed to a growing wave of AI-generated, single-use malicious domains. Roughly a quarter of newly observed domains in the region are now flagged as malicious or suspicious.
Encrypted DNS and VPNs drew a nuanced verdict: while they protect the last mile of a query from tampering, routing that traffic to offshore endpoints bypasses local IXP caches, adds latency, and creates new single points of failure. Reddy's recommendation was not to abandon encryption but to keep resolution local: pairing encrypted, locally hosted recursive resolvers with resolver diversity, scaled DNSSEC and RPKI adoption, and edge security architectures such as SASE and Zero Trust Network Access deployed at local points of presence.
"DNS Abuse often starts with Weak or Lazy Configuration" (Dr Josiah Chavula)
Dr. Chavula argued that DNS abuse in Southern Africa is overwhelmingly a hosting problem, not a protocol problem. The region faces four pressing threats: DDoS and DNS amplification, DNS hijacking and adversary-in-the-middle attacks, compromised hosting behind legitimate domains, and weak configuration paired with registry opacity.
His research shows that brute-force attacks, compromised web applications, and hijacked SSH access accounted for 57.5% of categorised abuse incidents, while DNS compromise and DNS poisoning combined made up just 0.14%. In practice, this means legitimate domains are being hijacked through poorly secured servers rather than through attacks on DNS itself, so hardening resolvers alone will not solve the problem. Web hosting hygiene and registry accountability need equal attention. Chavula's research also exposed what he described as a severe local "visibility deficit." Of 5,150 attributed abuse reports involving Malawian (.mw) and Mozambican (.mz) domains, only two originated from within Africa (both from South Africa), with none generated locally in Malawi or Mozambique itself. Compounding the problem, over half of the region's ccTLD infrastructure (51.6%) is hosted in the United States, against just 8.03% hosted locally in South Africa, turning routine takedowns into slow cross-border negotiations.
Perhaps the starkest contradiction Chavula presented was what he termed the "validation vs. signing paradox." Malawi validates 99% of incoming DNS queries and Zimbabwe validates 79%, yet both countries' own top-level domains, .mw and .zw, remain unsigned with DNSSEC. South Africa's .za zone has been signed since 2016, but fewer than 1% of domains registered under it use DNSSEC. The barrier is not technical capacity, Chavula argued, but economics: registrants absorb the cost and risk of signing with no visible reward, while registrars treat DNSSEC as a support burden rather than a service worth selling. Registry opacity adds a further obstacle: three of the nine SADC ccTLD registries analysed (Eswatini, Comoros, and Zimbabwe) offer no public WHOIS or RDAP query interface at all, stalling abuse reporting before it can start.
Due to the scarcity of labelled DNS attack datasets in Southern Africa, unsupervised machine learning presents a useful alternative for identifying malware domain-generation algorithms (DGAs) and DNS tunnelling. Dr. Chavula emphasised that AI operates as a force multiplier rather than a standalone replacement for foundational capacity: deploying AI across an unbaselined namespace without a dedicated CERT or CSIRT produces noise, not actionable security.
"Bridging Regional DNS Governance Gaps Requires Aligning Regulatory Frameworks With Infrastructure Reality" (Dr Adebunmi Adeola)
Dr. Adeola's analysis widened the lens from technical measurement to institutional maturity, and found the region's governance frameworks trailing its infrastructure needs. Small domestic domain markets limit registry revenue, which in turn restricts investment in 24/7 security operations and DNSSEC deployment, while limited internet exchange points and thin autonomous system diversity continue to bottleneck regional connectivity. Data protection and cybercrime legislation is slowly being enacted across Southern Africa, Adeola noted, but enforcement remains weak or absent in several member states, and the near-total absence of explicit DNS abuse protocols in national cyber strategies leaves ccTLD registries exposed to jurisdictional confusion when incidents occur.
Adeola's research also mapped a widening divide between "frontrunner" states with dedicated CSIRTs and current privacy policies, and "emerging adopters" that still lack foundational cybersecurity frameworks. Regional maturity scores bear this out: Cyber Culture & Training sits at just 22% and DNS Technical Standards at 28%, both well below global averages. Her recommendations centred on institutionalising DNS security education through regional ICANN and AfTLD training centres, diversifying name server infrastructure across multiple ASNs, and building the multi-stakeholder alliances (registries, ICANN, AfTLD, ISPs, and regulators) needed to align cybersecurity law across SADC.
A shared problem, not just a technical one
Across all three presentations, one theme recurred: DNS resilience in Southern Africa cannot be solved by technical teams working in isolation. End-user awareness, registrar incentives, registry transparency, cross-border cooperation, and national policy all shape whether the region's namespace holds up under pressure, and right now, several of those pieces are misaligned.
C3SA described the webinar as the opening session in what it intends to be an ongoing conversation, with further sessions planned to track the region's evolving DNS threat landscape and the collective work needed to build a more secure and resilient digital ecosystem.
Recommendations for DNS resilience in Southern Africa
Taken together, the panel's presentations point to five priorities for the region.
- Invest in local capacity. Expand dedicated CERTs and CSIRTs across SADC member states and formalise DNS security education through ICANN and AfTLD's regional training centres, so that AI-assisted threat detection has trained teams able to act on what it flags, rather than generating noise no one is resourced to chase.
- Reduce dependence on foreign infrastructure. Grow local peering capacity at exchanges such as NAPAfrica, encourage more root and ccTLD anycast instances to be hosted within the region, and pair any move to encrypted DNS with locally hosted recursive resolvers rather than routing queries offshore.
- Close the DNSSEC gap with incentives, not just awareness. Since the barrier is economic rather than technical, registries should consider subsidised signing, mandates for government and public-sector domains, and registrar incentive schemes that make DNSSEC worth selling rather than a support burden to avoid.
- Make registry data open and interoperable. Every SADC ccTLD registry should operate a public WHOIS or RDAP interface, and regional bodies should formalise cross-border abuse-reporting channels so takedowns no longer depend on slow, ad hoc negotiation.
- Align policy and law across the region. National cyber strategies need to explicitly address DNS abuse, cybercrime and data protection legislation needs consistent enforcement, and SADC member states should coordinate their laws so jurisdictional gaps stop giving abusers somewhere to hide. Wider ICANN-accredited registrar participation, sustained investment in universal acceptance, and clearer differentiation of second-level domains by sector would reinforce all of the above.