DNSFilter
The cheapest control you can turn on this afternoon
Every connection starts with a name lookup. DNSFilter answers those lookups, refuses the ones heading somewhere known or judged to be malicious, and does it for laptops wherever they are rather than only on your office network.
See What It Would BlockStopping the lookup stops most of what follows
A phishing link, a malware download and a compromised machine calling home all have one step in common. Each needs to turn a name into an address before anything can happen.
Refusing that step is unusually efficient. There is no file to inspect, no certificate to unwrap and no traffic to decrypt, because the connection is never established. It is also the rare security control that reduces support tickets, since the user sees a clear block page instead of a slow mystery.
| Threat step | Needs a lookup? |
|---|---|
| User clicks a phishing link | Yes |
| Malware downloads its payload | Usually |
| Compromised host calls home | Usually |
| Data is sent out to an attacker | Often |
| Attack already running in memory | Not necessarily |
Your protection has to travel with the laptop
Filtering configured on the office router protects people in the office. It does nothing for the same laptop on home broadband, in a hotel, or on the coffee shop network where the risk is highest.
DNSFilter's roaming client is the part that matters for most organizations now. It is deployed silently through your management tooling, replaces the system resolver, and applies the same policy wherever the machine connects. The vendor has also added a capability aimed specifically at unmanaged networks that interfere with DNS configuration.
Point your resolvers or push the client through your management tooling. This is among the fastest controls to put in place.
Clients exist for Windows, macOS, iOS, Android and Chrome devices, which covers the population most filtering misses.
Domains are classified automatically rather than waiting for a human list, which matters because malicious domains are often hours old.
Security filtering and acceptable use are the same switch
Most organizations buy this for security and then discover the other half is equally useful: blocking categories that have no business on a work device, and being able to show what was requested and refused.
That reporting is frequently what an insurer or a customer questionnaire is asking about when it uses the phrase web filtering. Being able to produce it is worth more than the block page itself.
| Use | What it delivers |
|---|---|
| Threat blocking | Malicious and newly registered domains refused |
| Content policy | Categories disallowed by device group or user |
| Reporting | Evidence of what was requested and blocked |
| Guest and shared devices | Coverage without an agent on every machine |
What it will not do
It is a coarse control, deliberately
DNS filtering works at the level of the whole domain. It cannot distinguish a malicious page from a safe one on the same site, so it is a broad early filter rather than a precise one.
It can be bypassed
An application using its own encrypted resolver, or a determined user changing settings, can go around it. Good deployments lock this down at the device, which is a configuration task worth doing properly rather than assuming.
It is not endpoint or email security
An attack that arrives as an attachment and runs in memory may never make a lookup you can block. This layer reduces exposure; it does not replace detection on the device or filtering on the mail.
Where it is the strongest value
Organizations with laptops off the network, shared or guest devices, or no web filtering at all today. For the cost and the effort involved, few controls return as much, which is exactly why it should be first rather than last.
Ask what filters a laptop at home
If the honest answer is nothing, this is the least expensive gap on your list to close, and it can be closed this week.
Start The ConversationGet in touch with Your Company
Questions about this solution? Reach us directly.