Skip to content
Techno Trader
Home

Security & DNS

Protective DNS Filtering

Recursive DNS filtering that blocks malware, phishing and command-and-control domains before a connection is ever made, applied to offices and roaming devices.

Protective DNS filtering appliance blocking malicious lookups shown as interrupted light paths
QUERY FILTERING · Protective DNS Filtering

Engineering capabilities

  • Policy design per site, group and device
  • Roaming client rollout on laptops and mobiles
  • Category and threat-feed tuning to cut false positives
  • Reporting on blocked requests and repeat offenders

Security & hardening

  • Blocks known malicious resolution before traffic starts
  • Encrypted DNS transport to the resolver
  • Bypass prevention on local resolvers and hard-coded servers

Protective DNS resolution path

Every lookup is answered by a filtering resolver, so known malicious destinations fail to resolve before any connection is attempted.

  1. 01

    Clients

    • Office devices
    • Roaming laptops
    • Mobile devices
    • Servers

    Roaming clients keep policy off-network, where most incidents actually start.

  2. 02

    Resolver

    • Filtering resolver
    • Encrypted DNS transport
    • Site policy

    Policy can differ by site, group or device class.

  3. 03

    Intelligence

    • Malware and phishing feeds
    • Command-and-control lists
    • Category policy

    Threat feeds are tuned so blocking does not disrupt legitimate business tools.

  4. 04

    Assurance

    • Blocked-request reporting
    • Bypass prevention
    • Exception workflow

    Hard-coded resolvers on devices are blocked so filtering cannot be sidestepped.

Frequently asked questions

Does DNS filtering replace endpoint protection?

No. It removes a large share of commodity threats early and cheaply, but it does not inspect files or process behaviour u2014 endpoint protection still does that.

What about false positives?

An exception workflow is set up on day one so a blocked business tool is released in minutes rather than becoming a reason to disable filtering.

Can staff bypass it?

Not where devices are managed: hard-coded public resolvers are blocked at the firewall and encrypted DNS is pointed at the filtering service.

Scope the work before you commit budget

Send the environment details and get an engineered proposal with assumptions, risks and a rollback path.

Request a Quote WhatsApp