How DNS works, in one minute
Computers find each other by IP address, but people use names like example.com. The Domain Name System (DNS) turns names into addresses. Before a laptop, phone, printer or camera connects to anything on the internet, it sends a DNS query: "what is the address for this name?"
Most networks send those queries to whatever DNS server their internet provider hands out. That server answers every question, including questions about domains that were registered yesterday to steal passwords.
What a DNS filter does differently
A DNS filter is a DNS server with a policy. For each lookup it checks the domain against threat intelligence and your own rules, then either:
- answers normally, so the site loads as usual, or
- refuses, so the device never learns the address. The connection to the malicious server is never made.
Because the decision happens before any traffic flows, DNS filtering stops threats earlier than tools that inspect downloads or scan files after they arrive. It also works for devices that can't run security software, such as printers, IP cameras, smart TVs and guest phones.
What DNS filtering stops
| Threat | How DNS filtering helps |
|---|---|
| Phishing | Blocks known credential-harvesting domains, including lookalikes such as micros0ft-login.com. |
| Malware and ransomware delivery | Blocks the domains that host payloads, so a malicious link or macro can't fetch the next stage. |
| Command-and-control (C2) | Infected machines usually look up their controller by name. Blocking that lookup cuts the attacker off. |
| Cryptojacking | Blocks mining pools and in-browser mining scripts. |
| Unwanted content | Category blocking (adult, gambling, social media and so on) enforces an acceptable-use policy. |
| Ads and trackers | Optional. Fewer malicious ads, faster pages, less tracking. |
What DNS filtering doesn't do
DNS filtering is one strong layer, not the whole stack. Be clear about its limits:
- It sees domains, not full web addresses. It can block
badsite.com, but not one page on a site that is otherwise fine. That's the job of a secure web gateway or proxy. - It doesn't replace endpoint protection. A file already on a USB stick isn't a DNS lookup. Keep antivirus or EDR on your computers.
- It only covers devices that use it. A laptop at a coffee shop uses the café's DNS unless something on the laptop sends lookups to the filter. Network-level DNS filtering protects the office, not staff working elsewhere.
- Devices can try to go around it. Browsers with their own encrypted DNS, VPNs and hard-coded DNS servers can skip your filter unless you close those routes. See how to stop DNS filtering bypass.
How it's deployed
There are three common ways to point a network at a DNS filter:
- At the router or firewall. Set the DNS servers handed out by DHCP to the filter's addresses. Every device that joins the network is covered. This is the most common setup and takes a few minutes: see step-by-step instructions for FortiGate, Meraki, UniFi, pfSense, SonicWall and Windows Server.
- On an internal DNS server. If you run Active Directory, keep your domain controllers as the clients' DNS and set the filter as their forwarder. Internal names keep working and internet lookups get filtered.
- On each device. With encrypted DNS (DNS-over-HTTPS or DNS-over-TLS) or an agent. Useful for laptops that leave the office.
Try DNSAFE on your own network: 14 days free, no card, set up in minutes.
Start free trialWhat it costs
Pricing models differ a lot. Some providers charge per user or per device per month, often with a monthly minimum. Others, including DNSAFE, charge per network. For an office, per-network pricing is usually simpler, because guest phones, printers and cameras don't count as extra seats.
DNSAFE business plans start at $19 a month for up to 25 registered public IP addresses, with a 14-day free trial. See pricing for every plan.
How to choose a DNS filtering provider
- Threat intelligence quality: where the block lists come from and how often they update.
- Coverage: resolver locations near your offices, plus encrypted DNS support.
- Visibility: query logs, reports and alerts you'll actually read, with a sensible retention period.
- Control: per-network policies, allow and block lists, category filtering and schedules.
- Integrations: SIEM streaming, an API, single sign-on and MFA for admins.
- Bypass protection: how the service handles browsers' own encrypted DNS and relay services.
The US National Security Agency and CISA publish a checklist for this. We walk through it in Protective DNS: what NSA and CISA recommend.
Frequently asked questions
Does DNS filtering slow down the internet?
Usually not noticeably. A DNS lookup takes milliseconds, and a nearby filtering resolver is often as fast as your ISP's DNS. Devices also cache answers, so most lookups never leave the device.
Is DNS filtering the same as a firewall?
No. A firewall decides which connections are allowed by address and port. A DNS filter decides which names get answered. They work well together: the DNS filter stops most bad connections before the firewall ever sees them.
Can DNS filtering see what my staff do on websites?
No. It sees the domain names looked up, such as example.com, not the pages visited, searches typed or anything inside an encrypted connection.
Does DNS filtering work with HTTPS sites?
Yes. The lookup happens before the encrypted connection starts, so HTTPS doesn't affect it. The only difference is what users see: a blocked HTTPS site shows a browser error rather than a branded block page, unless the device trusts the filter's certificate.