Solutions
Home & FamilyBusinessMSP / MSSP
Tools
Domain CheckerDNS Leak TestThreat Intel
Company
PricingGuidesDocsAboutContact
Home / Guides / Protective DNS

Protective DNS: what NSA and CISA recommend.

Protective DNS (PDNS) blocks lookups to malicious domains. US and UK cyber agencies call it one of the most cost-effective defenses an organization can add.

Getting started · Updated September 30, 2026 · 6 min read

In shortProtective DNS is DNS filtering aimed at security: it refuses lookups for domains tied to malware, phishing, botnets and ransomware. The NSA and CISA guidance on selecting a PDNS service lists what to check: threat coverage, how the service fits a layered defense, how it handles devices trying to go around it, and how it supports hybrid and remote work.

What is protective DNS?

Protective DNS is a recursive DNS service that checks each query against threat intelligence and blocks the malicious ones. It's the same technology as DNS filtering, with the emphasis on security rather than content control.

In the guidance, the NSA and CISA describe PDNS as able to greatly reduce the effectiveness of ransomware, phishing, botnet and malware campaigns by blocking known-malicious domains. It's cheap to deploy because it uses the DNS protocol every device already speaks.

Why the agencies recommend it

In the UK, the NCSC runs a PDNS service for public-sector bodies, and in the US, CISA offers one to federal civilian agencies. Private businesses use commercial providers.

The capabilities to look for

The NSA/CISA document compares providers against a list of capabilities. Here they are as a practical checklist, with how DNSAFE handles each today:

CapabilityWhat to askDNSAFE
Blocks malware, phishing and C2 domainsWhere do the threat feeds come from, and how often do they update?Yes: merged feeds (including abuse.ch URLhaus, Hagezi Threat Intelligence and Phishing Army), refreshed daily
Domain categorizationCan you block categories, not just threats?Yes: category packs and per-network allow and block lists
Query logging and reportsHow long are logs kept, and can you export them?Yes: 30 days to 1 year by plan, CSV export
SIEM integrationCan events stream to your SIEM?Yes: webhook, Splunk HEC, Elastic and syslog on Business, Growth and Enterprise
Encrypted DNSDoes the service offer DNS-over-HTTPS and DNS-over-TLS?Yes: DoH and DoT at dns.dnsafe.net
Bypass resistanceHow does it handle browser DoH and relay services?Signals browsers to turn off automatic DoH, and can block known DoH and relay endpoints
Roaming and remote devicesAre laptops protected off the network?Yes: each laptop or phone can get its own encrypted DNS setup (DoH or DoT), with no agent to install
RedundancyHow many resolver locations, and what happens if one fails?Three regions (US, UK, Singapore) with health-checked failover on resolver.dnsafe.net

The agencies stress that their comparison is information, not a recommendation of any provider. Test a service on your own network before you commit.

Try DNSAFE on your own network: 14 days free, no card, set up in minutes.

Start free trial

How to roll out protective DNS

  1. Start with one site. Register its public IP, point DHCP (or your DNS server's forwarders) at the service, and watch the logs for a week. See firewall setup steps.
  2. Tune. Allow anything business-critical that was blocked by mistake, and add categories that match your acceptable-use policy.
  3. Close the bypass routes. Block outbound DNS to other servers, and turn off browser DoH by policy. See stopping DNS bypass.
  4. Connect alerts. Send threat alerts to email, Teams, Slack or your SIEM so someone sees them.
  5. Roll out to the rest. Add every office and guest network.

Frequently asked questions

Is protective DNS the same as DNS filtering?

They use the same technology. "Protective DNS" is the term US and UK government agencies use for DNS filtering focused on blocking threats; "DNS filtering" often also covers content categories.

Does protective DNS replace antivirus or a firewall?

No. The NSA/CISA guidance presents PDNS as one layer in a layered defense. Keep endpoint protection and a firewall; PDNS reduces how much reaches them.

Can a small business use protective DNS?

Yes. Commercial services work with any router or firewall that lets you set DNS servers. DNSAFE business plans start at $19 a month with a 14-day free trial.

Sources

Protect every device on your network.

Point your router or firewall at DNSAFE. 14 days free, no card.