Solutions
Home & FamilyBusinessMSP / MSSP
Tools
Domain CheckerDNS Leak TestThreat Intel
Company
PricingGuidesDocsAboutContact
Home / Guides / What is DNS filtering?

What is DNS filtering, and how does it protect a business?

DNS filtering checks every website lookup your network makes and refuses the dangerous ones, before a connection is ever opened.

Getting started · Updated September 30, 2026 · 7 min read

In shortEvery time a device visits a website, it first asks a DNS server for the site's address. A DNS filter answers "no" for domains known to spread malware, run phishing pages or fall into categories you've blocked. Because it works at the network, one setting on your router or firewall protects every device behind it, with no software to install.

How DNS works, in one minute

Computers find each other by IP address, but people use names like example.com. The Domain Name System (DNS) turns names into addresses. Before a laptop, phone, printer or camera connects to anything on the internet, it sends a DNS query: "what is the address for this name?"

Most networks send those queries to whatever DNS server their internet provider hands out. That server answers every question, including questions about domains that were registered yesterday to steal passwords.

What a DNS filter does differently

A DNS filter is a DNS server with a policy. For each lookup it checks the domain against threat intelligence and your own rules, then either:

Because the decision happens before any traffic flows, DNS filtering stops threats earlier than tools that inspect downloads or scan files after they arrive. It also works for devices that can't run security software, such as printers, IP cameras, smart TVs and guest phones.

What DNS filtering stops

ThreatHow DNS filtering helps
PhishingBlocks known credential-harvesting domains, including lookalikes such as micros0ft-login.com.
Malware and ransomware deliveryBlocks the domains that host payloads, so a malicious link or macro can't fetch the next stage.
Command-and-control (C2)Infected machines usually look up their controller by name. Blocking that lookup cuts the attacker off.
CryptojackingBlocks mining pools and in-browser mining scripts.
Unwanted contentCategory blocking (adult, gambling, social media and so on) enforces an acceptable-use policy.
Ads and trackersOptional. Fewer malicious ads, faster pages, less tracking.

What DNS filtering doesn't do

DNS filtering is one strong layer, not the whole stack. Be clear about its limits:

How it's deployed

There are three common ways to point a network at a DNS filter:

  1. At the router or firewall. Set the DNS servers handed out by DHCP to the filter's addresses. Every device that joins the network is covered. This is the most common setup and takes a few minutes: see step-by-step instructions for FortiGate, Meraki, UniFi, pfSense, SonicWall and Windows Server.
  2. On an internal DNS server. If you run Active Directory, keep your domain controllers as the clients' DNS and set the filter as their forwarder. Internal names keep working and internet lookups get filtered.
  3. On each device. With encrypted DNS (DNS-over-HTTPS or DNS-over-TLS) or an agent. Useful for laptops that leave the office.

Try DNSAFE on your own network: 14 days free, no card, set up in minutes.

Start free trial

What it costs

Pricing models differ a lot. Some providers charge per user or per device per month, often with a monthly minimum. Others, including DNSAFE, charge per network. For an office, per-network pricing is usually simpler, because guest phones, printers and cameras don't count as extra seats.

DNSAFE business plans start at $19 a month for up to 25 registered public IP addresses, with a 14-day free trial. See pricing for every plan.

How to choose a DNS filtering provider

The US National Security Agency and CISA publish a checklist for this. We walk through it in Protective DNS: what NSA and CISA recommend.

Frequently asked questions

Does DNS filtering slow down the internet?

Usually not noticeably. A DNS lookup takes milliseconds, and a nearby filtering resolver is often as fast as your ISP's DNS. Devices also cache answers, so most lookups never leave the device.

Is DNS filtering the same as a firewall?

No. A firewall decides which connections are allowed by address and port. A DNS filter decides which names get answered. They work well together: the DNS filter stops most bad connections before the firewall ever sees them.

Can DNS filtering see what my staff do on websites?

No. It sees the domain names looked up, such as example.com, not the pages visited, searches typed or anything inside an encrypted connection.

Does DNS filtering work with HTTPS sites?

Yes. The lookup happens before the encrypted connection starts, so HTTPS doesn't affect it. The only difference is what users see: a blocked HTTPS site shows a browser error rather than a branded block page, unless the device trusts the filter's certificate.

Sources

Protect every device on your network.

Point your router or firewall at DNSAFE. 14 days free, no card.