Solutions
Home & FamilyBusinessMSP / MSSP
Tools
Domain CheckerDNS Leak TestThreat Intel
Company
PricingGuidesDocsAboutContact
Home / Guides / DNS filtering for MSPs

DNS filtering for MSPs: a managed service that pays.

DNS filtering is one of the easiest security services an MSP can add: quick to deploy, low-touch to run, and easy to explain to clients.

For MSPs · Updated September 30, 2026 · 6 min read

In shortPick a platform that is truly multi-tenant, so each client has its own policies, logs and reports. Make sure it fits your stack (PSA, SIEM, SSO), and that its pricing leaves room for margin at your client sizes. Deploy client by client at the firewall, and bundle it into your security package rather than selling it alone.

Why MSPs add DNS filtering

What an MSP-ready platform needs

NeedWhy it mattersDNSAFE
Multi-tenant portalOne login, every client separateYes: each client is a tenant with its own IPs, rules and logs
Per-client policiesA dental office and a school need different rulesYes: categories, allow and block lists, schedules and IP groups per client
ReportsProof of value for clientsYes: per-client reports and CSV export, plus a weekly summary email
White-labelYour brand, not oursYes on Growth and Enterprise: your logo, colors and custom domain
PSA integrationAlerts become ticketsYes on Enterprise: ConnectWise Manage and Autotask
SIEM streamingFeeds your SOCYes on Growth and Enterprise
Team roles, SSO and MFASafe access for your techniciansYes: team roles and audit log; SAML SSO and Duo on Enterprise
Roaming devicesProtects laptops away from the officeYes, per device with encrypted DNS and no agent. Each device counts as one IP

Pricing models, and why they matter to margin

Providers price DNS filtering to MSPs in two main ways:

With flat pricing, your cost doesn't rise as clients hire, so the margin on a per-user resale price grows over time. Model your own numbers with the MSP revenue calculator.

Become a DNSAFE partner: multi-tenant portal, white-label, PSA tickets. 14 days free.

Start partner trial

A deployment playbook

  1. Onboard the client: create a tenant and register the site's public IP.
  2. Apply a baseline policy: threats on for everyone, plus the categories your standard agreement covers.
  3. Point the firewall: set DHCP DNS to the resolver addresses, or AD forwarders for domain networks. See firewall steps.
  4. Lock it down: block outbound DNS except to your resolvers, and turn off browser DoH by policy. See bypass protection.
  5. Wire up alerts: send threat spikes and offline networks to your PSA or team chat.
  6. Review monthly: send the report and adjust the policy with the client.

How to package it

Most MSPs don't sell DNS filtering on its own. It works best as part of a security bundle alongside endpoint protection, email security, backups and MFA, priced per user. The per-user price covers your tooling, time and margin, and DNS filtering is one of the tools that makes the bundle visibly valuable in monthly reports.

Frequently asked questions

Can each client have different filtering rules?

Yes. Each client is a separate tenant with its own categories, allow and block lists, schedules and IP groups, and you can manage them all from one portal.

Can my clients log in to see their own reports?

Reports can be exported and emailed from your portal, and business clients can have their own DNSAFE account. A dedicated client-view login inside the MSP portal isn't available yet.

Is there a free trial for MSPs?

Yes. Partner accounts get a 14-day trial with every feature, and no card is needed. Partner sign-up may be reviewed before the account is switched on.

Protect every device on your network.

Point your router or firewall at DNSAFE. 14 days free, no card.