THE WIRE
NOW · DYN.COM POINTS TO ORACLE DNS2023 · LEGACY ENTERPRISE DNS RETIRED2016 · THE ATTACK THAT EXPOSED A SHARED DEPENDENCY

COMPANY · INTERNET INFRASTRUCTURE

Dyn and the day the internet lost its address book

A New Hampshire company made a business of helping everyone find everyone else online. Then an attack on its DNS network exposed how many famous websites shared the same front door.

On October 21, 2016, a perfectly healthy website could be impossible to visit. Its servers could be humming. Its software could be behaving. Its owners could have paid every bill. Somewhere between a person typing a name and a computer finding an address, the journey stopped. A company called Dyn occupied that small, consequential space.

THE STORY IN FOUR LINES
  • Dyn sold the DNS and traffic tools that helped people reach websites.
  • It grew from a student project into a supplier to Netflix, Twitter and Pfizer.
  • The 2016 attack exposed a dependency shared by otherwise separate businesses.
  • Oracle bought the company; its old enterprise DNS products have since retired.

Dyn’s predicament was rather awkward for an infrastructure company: doing its job well usually made it invisible. The moment it struggled, it became famous. Behind that reversal sits a useful business story about selling an unglamorous service, earning trust, and discovering exactly what a customer has outsourced.

A name that stays put

Start with a smaller inconvenience. A home internet connection can receive a different public IP address over time. Someone trying to reach a computer or camera from elsewhere needs a dependable way to find it. Dynamic DNS supplies a hostname whose associated address can be updated when the connection changes. The name stays familiar while the number moves.

That was the neighbourhood in which Dyn began. Incorporated in 2001, the company grew out of work associated with Worcester Polytechnic Institute. Its founders were Jeremy Hitchcock, Tom Daly, Tim Wilde and Chris Reinhardt. Hitchcock later recalled wanting to work on a lab paper and print it somewhere else, an ordinary irritation that invited some networking experiments.

“There was no business plan”

Jeremy Hitchcock, recalling Dyn’s beginnings at WPI in 2015

The commercial insight arrived through repetition: other people had related problems. Today’s DynDNS Pro still addresses that recognisable need. Dyn’s documentation describes access to CCTV systems, DVRs and home automation devices. A client updates the hostname as the public address changes. A little administrative chore becomes a subscription.

The simplicity has boundaries. A hostname does not make a device reachable through every router or firewall. Dyn’s setup guide separates local connectivity, external access, hostname creation and the update client into different steps. If the updater stops, the address can become stale. Buying a memorable name does not finish the network configuration.

Dyn co-founder Jeremy Hitchcock in a blue shirt
A man with an address book to run. Jeremy Hitchcock, pictured in his 2012 Stark Insider interview. Photograph published by Stark Insider.

The subscription behind the subscription

For an enterprise, the same basic act of finding an address becomes more complicated. A website may operate across several locations. One destination may be healthier or faster than another. Someone has to publish the authoritative DNS answers and help direct visitors toward an appropriate endpoint. Dyn sold companies that operating responsibility.

Its historical portfolio combined managed DNS, traffic management, outgoing email delivery and domain registration. Email was another dependency customers could hand to a specialist: messages had to get delivered, not merely dispatched. Dyn’s pitch concerned the machinery beneath a customer’s own product, the services whose failure could embarrass everything above them.

In a 2012 interview, Hitchcock described the attraction succinctly: “It’s one less thing that our customers have to think about.” That sentence also describes the business model. Customers paid recurring fees or enterprise contracts for expertise and infrastructure they preferred not to operate themselves.

Dyn’s distinction was its concentration on these underlying services, with traffic control extending beyond simple record hosting. In 2014 it acquired Renesys, whose global sensor network monitored internet routing and performance. The purchase added a view of conditions outside the networks customers directly controlled. Seeing a route and choosing a route could now belong to the same conversation.

The market included dedicated DNS operators and cloud platforms. Amazon Route 53, Cloudflare, Google Cloud DNS and UltraDNS offered alternative ways to place those responsibilities elsewhere. Dyn’s question for buyers was whether its specialised operations, traffic tools and visibility justified a separate supplier. For businesses selling their own online subscriptions, Dyn was a subscription underneath the subscription.

Eleven years before the cheque

Dyn did not begin with a large venture round. It bootstrapped for more than a decade before raising $38 million in 2012, led by North Bridge with Borealis Granite Fund participating. Pamplona supplied another $50 million growth-equity investment in May 2016. Those two announced rounds totalled $88 million.

What changed Hitchcock’s mind about investors? In a Forbes interview after the first round, he said North Bridge’s offer was straightforward and brought skills to help Dyn scale. Capital could buy expansion; the relationship could bring people and experience. The timing matters. Dyn already had a business for the investment to enlarge.

There was a regional ambition, too. Dyn supported technical education and the surrounding startup economy. WPI documented its Hackademy program and support for student projects and a user-experience laboratory. Helping develop technical talent made sense for a company recruiting outside the usual technology centres. An ecosystem is a considerably more useful recruiting perk than another office sofa.

When the first request cannot get through

The October 2016 attack targeted Dyn’s managed DNS infrastructure with distributed denial-of-service traffic. Monitoring firm ThousandEyes identified the Mirai botnet of compromised consumer devices as one source. In plain language, attackers used many machines to crowd a service that legitimate visitors needed.

What failed first for those visitors was name resolution. A browser could not reliably obtain the answer needed to reach a customer’s website. The application itself did not have to fail. Dyn said the incident was not a system-wide outage: some users could still reach the same services from other regions.

A SIMPLIFIED WEB REQUEST
01Type a nameYour browser needs an address.
02Ask DNSDisruption here can stop the journey.
03Reach the siteA healthy server can still be out of reach.
The doorbell fails before anyone gets to inspect the house.

The incident travelled through dependencies. Cloudflare’s account described DNS failures affecting requests connected to Dyn-backed records, even though its own DNS service remained available. Infrastructure has relatives. Your supplier’s supplier can turn up in your incident report without ever appearing on your invoice.

The practical lesson was to inspect the chain before the next outage. Check authoritative DNS providers, linked hostnames and the path a fresh visitor takes. Test from outside your own network. A familiar browser with cached information can have a more comfortable experience than someone arriving for the first time.

Another provider can offer a separate route to DNS answers. But a second contract brings work: records must agree, traffic-steering behaviour must be compatible, and changes must reach both systems. That approach is less useful when the providers depend on the same failing component or when mismatched answers send visitors to the wrong place. Redundancy deserves a rehearsal.

A 2022 study of the aftermath found that owners of more popular domains were more likely to increase the diversity of their authoritative DNS service. The reaction varied by industry as well. Downtime changed some minds; it did not produce one universal architecture. The sensible amount of insurance depends on the consequences of being unreachable and the cost of operating it.

The company went to Oracle. The names got complicated.

On November 21, 2016, Oracle announced its agreement to acquire Dyn. Its announcement reported more than 3,500 enterprise customers and 40 billion daily traffic optimisation decisions, with Netflix, Twitter, Pfizer and CNBC among the named customers. These were figures from the acquisition announcement, not a current census.

The timing invites a tidy story about the attack causing the sale. Public chronology alone cannot establish that. Oracle’s stated rationale was to add Dyn’s DNS and internet performance capabilities to its cloud platform. The buyer wanted infrastructure with an existing enterprise audience.

For someone shopping today, the product distinction matters. Dyn’s legacy Managed and Standard DNS services retired in 2023. The dyn.com website now leads to Oracle Cloud Infrastructure DNS, whose offerings include public and private DNS and traffic steering. Oracle’s page separately directs dynamic DNS users toward hostname services.

The public DynDNS Pro purchase page, checked in September 2026, lists $55 for one year, $99 for two and $220 for five. That is the surviving dynamic-hostname offer, not a price for the old enterprise service. Dyn’s history now has two destinations: cloud infrastructure for the enterprise lineage, and a name that keeps following a changing address for the smaller, older problem.

For builders, the business lesson is pleasantly unromantic. Find a recurring nuisance that people will pay to hand over. Get good at the operational details. For buyers, the question is equally concrete: if this supplier stops answering, how does the next customer find you?