I noticed a (relatively) huge amount of dns packets in my wireshark recording while only visiting plain websites. Sites like amazon, facebook, comodoca and many others are requested by dns packets. So does it make sense to use dns packets as an indicator for ALL resources (servers) that are involved when loading a website for example?
When I look at my dns packets carefully, there shouldn't be anything, that is hidden from me, right? Every domain or server that is potentially requested when visiting a website will be seen?
Wouldn't that be a good way to check if malicious code is loaded from strange (unexpaected) resources?