Protective DNS (PDNS)

DNSFilter offers all the features required of a compliance Protective DNS service provider out of the box, including extra features like application blocking, remote protection, and defense against zero-day attacks.

Secure DNS is No Longer Optional

The National Security Agency (NSA) and Cybersecurity and Infrastructure Security Agency (CISA) released a joint statement highlighting how DNS is central to the operation of the entire internet in 2021. They further emphasized that prioritizing its protection is critical to combating cyber threats. This statement has since been used to advocate for the widespread adoption of protective DNS measures.

DNS is at the core of all internet operations but ironically, securing the DNS layer has always been treated as a luxury rather than a necessity by most organizations. This strong stance by the NSA and CISA on having a protected DNS layer further emphasizes the point that having a secure network starts with shielding your DNS operations from threat actors. 79% of all cyberattacks can be prevented by protecting the DNS layer.

DNS Protection Shield Icon

DNS Protection Services

DNSFilter offers robust end-user DNS protection services, powered by machine learning and backed by the largest global DNS network in the industry. On a daily basis, we block 12 million threats, scan and categorize 1 million domains, and process 107 billion DNS requests.

On a daily basis our DNS Protective services:

  • block 12 million threats
  • scan and categorize 1 million domains
  • process 130 billion DNS requests

What are the Benefits of Protective DNS?

SecuritySecurity:

PDNS blocks malicious websites and prevents cyber threats like malware, phishing, and ransomware at the DNS level, securing your network and devices.

Visibility Visibility:

Provides real-time monitoring and logs of DNS queries, allowing businesses to track user activity, detect suspicious traffic, and analyze network behavior.

 Better Control of Devices/NetworkBetter Control of Devices/Network:

Allows centralized management of DNS traffic, enabling you to block unwanted content, enforce security policies, and maintain compliance across all connected devices.

Frequently Asked Questions

How does PDNS work?

Most DNS security setups that validate DNS records (DNS Security Extensions, DNSSEC), or encrypt DNS traffic for protection against malicious eavesdropping (DNS-over-TLS/ DoT or DNS-over-HTTPS/DoH) do not address the trustworthiness of upstream DNS infrastructure that may be compromised or maliciously provisioned. PDNS addresses these concerns by using an external DNS resolver that implements standard protective DNS policies.


One of the main functions of the resolver is to examine the domain name queries and the returned IP addresses against threat intelligence. This way, the resolver can help prevent connections to known and suspected malicious domains. Protective DNS (PDNS) operates as a service and is not itself a DNS protocol.

What is PDNS and why is it important?

DNS is at the heart of internet operations, but it is not built with security out of the box. Because of this, malicious actors find it attractive to design attacks around the protocol.

These attacks can lead to data exfiltration from compromised hosts, installation of malicious software, the spread of network worms, and ransomware.

Cybersecurity teams, in looking to strengthen the safety of company networks, leverage PDNS to secure an ever-expanding collection of devices, access points, and users. Proper DNS protection offers a zero-trust security solution for any end-user accessing the internet on your network. These services create a secure environment requiring no action or training on your end.


Read the full overview on What Protective DNS is and Why it is Important.

PDNS Compliance with NSA & CISA

Following the joint statement, the NSA and CISA also released a report listing the guidelines for selecting a Protective DNS provider. These criteria, though not exhaustive, are considered to be the most important attributes to look out for when choosing a Protective DNS provider.


The list below shows how DNSFilter satisfies the requirements stated in the report:

-Blocks Malware Domains

-Blocks Phishing Domains

-Malware Domain Generation Algorithm (DGA) Protection

-Leverages machine learning or other heuristics to augment threat feeds

-Content filtering

-Supports API access for SIEM integration or custom analytics

-Web Interface dashboard

-Validates DNSSEC

-DoH/DoT capable

What is the difference between DNS and PDNS?

Traditional DNS translates domain names into IP addresses but doesn’t filter harmful sites. PDNS adds an extra layer of security by filtering out malicious or suspicious domains, providing an additional barrier to threats.

What types of businesses benefit the most from PDNS?

Organizations of all sizes benefit from PDNS, but it’s particularly useful for:

 

  • Small and Medium Businesses (SMBs): Offers affordable, easy-to-implement security without the need for extensive IT infrastructure.

  • Managed Service Providers (MSPs): Provides an additional security layer to clients, improving overall service offerings.

  • Government and Public Sector: Enhances security and privacy for sensitive data by blocking access to harmful sites.

Customers love us, threats hate us