Why MSPs add DNS filtering
- Fast to deploy: one firewall setting per client site, with no agents to roll out.
- Low support load: once tuned, it runs quietly. Most tickets are "please allow this site".
- Visible value: monthly reports showing blocked threats make the service easy to justify at renewal.
- Insurance and compliance: cyber insurers and frameworks increasingly ask about web and DNS filtering.
What an MSP-ready platform needs
| Need | Why it matters | DNSAFE |
|---|---|---|
| Multi-tenant portal | One login, every client separate | Yes: each client is a tenant with its own IPs, rules and logs |
| Per-client policies | A dental office and a school need different rules | Yes: categories, allow and block lists, schedules and IP groups per client |
| Reports | Proof of value for clients | Yes: per-client reports and CSV export, plus a weekly summary email |
| White-label | Your brand, not ours | Yes on Growth and Enterprise: your logo, colors and custom domain |
| PSA integration | Alerts become tickets | Yes on Enterprise: ConnectWise Manage and Autotask |
| SIEM streaming | Feeds your SOC | Yes on Growth and Enterprise |
| Team roles, SSO and MFA | Safe access for your technicians | Yes: team roles and audit log; SAML SSO and Duo on Enterprise |
| Roaming devices | Protects laptops away from the office | Yes, per device with encrypted DNS and no agent. Each device counts as one IP |
Pricing models, and why they matter to margin
Providers price DNS filtering to MSPs in two main ways:
- Per user or device, per month, usually with a monthly minimum. Cost grows with every seat, including guest devices at some vendors.
- Flat per partner, by number of client tenants. DNSAFE works this way: Starter is $49/month for up to 5 clients, Growth $149/month and Enterprise $399/month for unlimited clients.
With flat pricing, your cost doesn't rise as clients hire, so the margin on a per-user resale price grows over time. Model your own numbers with the MSP revenue calculator.
Become a DNSAFE partner: multi-tenant portal, white-label, PSA tickets. 14 days free.
Start partner trialA deployment playbook
- Onboard the client: create a tenant and register the site's public IP.
- Apply a baseline policy: threats on for everyone, plus the categories your standard agreement covers.
- Point the firewall: set DHCP DNS to the resolver addresses, or AD forwarders for domain networks. See firewall steps.
- Lock it down: block outbound DNS except to your resolvers, and turn off browser DoH by policy. See bypass protection.
- Wire up alerts: send threat spikes and offline networks to your PSA or team chat.
- Review monthly: send the report and adjust the policy with the client.
How to package it
Most MSPs don't sell DNS filtering on its own. It works best as part of a security bundle alongside endpoint protection, email security, backups and MFA, priced per user. The per-user price covers your tooling, time and margin, and DNS filtering is one of the tools that makes the bundle visibly valuable in monthly reports.
Frequently asked questions
Can each client have different filtering rules?
Yes. Each client is a separate tenant with its own categories, allow and block lists, schedules and IP groups, and you can manage them all from one portal.
Can my clients log in to see their own reports?
Reports can be exported and emailed from your portal, and business clients can have their own DNSAFE account. A dedicated client-view login inside the MSP portal isn't available yet.
Is there a free trial for MSPs?
Yes. Partner accounts get a 14-day trial with every feature, and no card is needed. Partner sign-up may be reviewed before the account is switched on.