What is protective DNS?
Protective DNS is a recursive DNS service that checks each query against threat intelligence and blocks the malicious ones. It's the same technology as DNS filtering, with the emphasis on security rather than content control.
In the guidance, the NSA and CISA describe PDNS as able to greatly reduce the effectiveness of ransomware, phishing, botnet and malware campaigns by blocking known-malicious domains. It's cheap to deploy because it uses the DNS protocol every device already speaks.
Why the agencies recommend it
- It works early. Almost every attack needs a DNS lookup: to load a phishing page, download a payload or reach a command server. Blocking the lookup stops the chain.
- It covers everything. Unmanaged devices such as printers and cameras are protected without an agent.
- It creates useful logs. DNS query logs show which device tried to reach what, which helps during incident response.
In the UK, the NCSC runs a PDNS service for public-sector bodies, and in the US, CISA offers one to federal civilian agencies. Private businesses use commercial providers.
The capabilities to look for
The NSA/CISA document compares providers against a list of capabilities. Here they are as a practical checklist, with how DNSAFE handles each today:
| Capability | What to ask | DNSAFE |
|---|---|---|
| Blocks malware, phishing and C2 domains | Where do the threat feeds come from, and how often do they update? | Yes: merged feeds (including abuse.ch URLhaus, Hagezi Threat Intelligence and Phishing Army), refreshed daily |
| Domain categorization | Can you block categories, not just threats? | Yes: category packs and per-network allow and block lists |
| Query logging and reports | How long are logs kept, and can you export them? | Yes: 30 days to 1 year by plan, CSV export |
| SIEM integration | Can events stream to your SIEM? | Yes: webhook, Splunk HEC, Elastic and syslog on Business, Growth and Enterprise |
| Encrypted DNS | Does the service offer DNS-over-HTTPS and DNS-over-TLS? | Yes: DoH and DoT at dns.dnsafe.net |
| Bypass resistance | How does it handle browser DoH and relay services? | Signals browsers to turn off automatic DoH, and can block known DoH and relay endpoints |
| Roaming and remote devices | Are laptops protected off the network? | Yes: each laptop or phone can get its own encrypted DNS setup (DoH or DoT), with no agent to install |
| Redundancy | How many resolver locations, and what happens if one fails? | Three regions (US, UK, Singapore) with health-checked failover on resolver.dnsafe.net |
The agencies stress that their comparison is information, not a recommendation of any provider. Test a service on your own network before you commit.
Try DNSAFE on your own network: 14 days free, no card, set up in minutes.
Start free trialHow to roll out protective DNS
- Start with one site. Register its public IP, point DHCP (or your DNS server's forwarders) at the service, and watch the logs for a week. See firewall setup steps.
- Tune. Allow anything business-critical that was blocked by mistake, and add categories that match your acceptable-use policy.
- Close the bypass routes. Block outbound DNS to other servers, and turn off browser DoH by policy. See stopping DNS bypass.
- Connect alerts. Send threat alerts to email, Teams, Slack or your SIEM so someone sees them.
- Roll out to the rest. Add every office and guest network.
Frequently asked questions
Is protective DNS the same as DNS filtering?
They use the same technology. "Protective DNS" is the term US and UK government agencies use for DNS filtering focused on blocking threats; "DNS filtering" often also covers content categories.
Does protective DNS replace antivirus or a firewall?
No. The NSA/CISA guidance presents PDNS as one layer in a layered defense. Keep endpoint protection and a firewall; PDNS reduces how much reaches them.
Can a small business use protective DNS?
Yes. Commercial services work with any router or firewall that lets you set DNS servers. DNSAFE business plans start at $19 a month with a 14-day free trial.