Secure DNS
DNS filtering that blocks malicious and newly registered domains for every device, with query logs that feed your security monitoring.
- NIST CSF 2.0 functions
- Protect
- Relevant for
-
- Banking and financial services
- Telecommunications
- Government and public sector
- Oil and gas
Overview
Almost every attack needs DNS. Malware looks up its control servers, phishing sites are reached by name and stolen data can leave hidden in DNS queries. Few organizations log or filter this traffic.
We help you block malicious domains for every device, keep DNS, DHCP and IP addresses under central control and send DNS logs to the team that investigates incidents.
What you get
- Known malicious, phishing and command-and-control domains blocked at the DNS layer
- Protection for users, servers and devices that cannot run security agents
- DNS logs that show which device contacted which domain
- Central control of DNS, DHCP and IP addresses with change tracking
What we cover
- Protective DNS and domain reputation filtering
- Category policies and blocking of newly registered domains
- DNS query logging and SIEM integration
- Detection of DNS tunneling and data exfiltration
- Central DNS, DHCP and IP address management (DDI)
- DNS high availability and change control
How we work
-
Review
We review your DNS and DHCP servers, address plan and how names are resolved today.
-
Design
We design the DNS architecture, filtering policies and logging to your SIEM.
-
Deploy
We migrate resolvers in stages, starting in monitor mode, within agreed change windows.
-
Tune and hand over
We review blocked and allowed domains with you, document procedures and train administrators.
Deliverables
- DNS and IP address architecture design
- Deployed protective DNS and DDI platform
- Filtering policies and logging integration
- Administrator training and as-built documentation
Questions buyers ask
Will DNS filtering block legitimate sites?
Occasionally. We start in monitor mode, review the results with you and give you a simple way to allow a site that was blocked by mistake.
Does it replace a web proxy?
No. DNS filtering is a light, early layer that works for every device. A web gateway inspects traffic in more depth. They work well together.
Related offerings
-
Next-Generation Firewall (NGFW)
Next-generation firewalls that control traffic by application, user and content, with a clean, documented rule base.
NIST CSF function: Protect -
Security Information & Event Management (SIEM)
Central collection, correlation and investigation of security logs, with use cases built around your real risks and regulatory needs.
NIST CSF function: Detect NIST CSF function: Respond -
SASE / SSE
Secure access to the web, cloud and private applications for branches and remote users, enforced in the cloud instead of through a central data center.
NIST CSF function: Protect