VeraDNS is an on-premise DNS firewall and filtering platform — a protective DNS solution that inspects every DNS query on your network and blocks malware, phishing, ransomware, and command-and-control (C2) domains the instant they are requested, before a single TCP connection is made. No endpoint agents, no client software — deploy via Docker, point your network DNS to VeraDNS, and every device is protected.
Built for security and network teams that demand full data sovereignty, VeraDNS runs entirely on your own infrastructure — DNS queries, policy data, and audit logs never leave your environment. With live-in-under-60-minutes deployment, auto-updating threat feeds, one-click compliance reports mapped to NIST 800-53, CIS v8, ISO 27001 and NCSC, and a live real-time query console, VeraDNS gives enterprises complete DNS control without cloud dependency.
How DNS filtering works
Every DNS query from every device flows through the on-premise VeraDNS engine, where it is inspected, matched against policy and threat intelligence, and then resolved or blocked — with full local logging and visibility at every step.
Vera Insight — live visibility
The Vera Insight console turns every DNS query into live visibility — a risk-posture score, allowed/blocked metrics, a real-time query stream, a world-map threat landscape, and resolver health at a glance — all generated locally on your infrastructure.
Platform features
VeraDNS provides a complete suite of DNS security and visibility controls, all running locally on your infrastructure. Every feature ships as part of the platform — no third-party plugins required.
Technical specifications
- Deployment
- Docker on any Linux server; self-managed on-premise, private cloud, or your own VMs — no cloud dependency.
- Requirements
- Minimum 2 vCPU, 2 GB RAM; HA via multiple resolver instances behind a load balancer.
- DNS protocols
- Standard DNS (port 53), DNS-over-HTTPS (DoH), DNS-over-TLS (DoT), DNS-over-QUIC (DoQ), and DNSSEC validation.
- Throughput
- Starter 2,000 qps · Professional 10,000 qps · Advanced 20,000+ qps; <2 ms median resolver response.
- User scale
- Starter 100 · Professional 500 · Advanced 1,000+ users.
- Threat feeds
- Auto-updating blocklists — malware, phishing, ransomware, C2, adware, trackers — 2M+ rules across 15+ categories (Cloudflare Radar, URLhaus, ThreatFox, and more); extended library on Pro+.
- RBAC
- Admin / Editor / Viewer; JWT authentication with HttpOnly cookies; configurable session expiry; API-level enforcement.
- Compliance
- Reports mapped to NIST 800-53, CIS v8, ISO 27001, NCSC; PDF / CSV / HTML; generated locally, never transmitted.
- SIEM export
- REST API — JSON or CSV; Splunk, Microsoft Sentinel, Elastic, and any compatible SIEM (Pro & Advanced).
- SSO
- SAML 2.0 and LDAP/Active Directory SSO on the Advanced plan.
- Data privacy
- Zero external transmission — all queries, policies, and logs stay on your infrastructure; 90+ days default audit-log retention.
- Setup time
- Live in under 60 minutes — point your network DNS to VeraDNS after the Docker deploy.
Pricing tiers
Three tiers scale from a single-site office to enterprise and MSP deployments. Every tier runs on your own infrastructure; the Professional plan includes a 7-day free trial.
| Feature | Essentials | ProfessionalMost popular | Advanced |
|---|---|---|---|
| Throughput | 2,000 qps | 10,000 qps | 20,000+ qps |
| Users | 100 | 500 | 1,000+ |
| Best for | Small teams · single-site | Growing orgs · SIEM users | Enterprises & MSPs |
| Blocklist library | Standard | Extended | Extended |
| RBAC roles | Admin & Viewer | Admin · Editor · Viewer | Admin · Editor · Viewer |
| SIEM & REST API export | — | ✓ | ✓ |
| SSO (SAML 2.0 / LDAP/AD) | — | — | ✓ |
| Custom integration dev | — | — | ✓ |
| Support | Priority email & chat | SLA-backed 24/7 | |
| Free trial | — | 7-day | — |
Advanced Threat add-on
Deeper threat intelligence, malware sandboxing, and command-and-control (C2) detection beyond the standard feeds. Layer on top of any plan.
Advanced Analytics add-on
Extended dashboards, behavioural anomaly detection, and custom report builders — designed for your SOC team. Available on any plan.
Why VeraDNS?
100% on-premise
Your DNS queries, policies, and audit logs never leave your infrastructure — full data sovereignty by design, not as an option.
Zero agents
Network-wide protection with no endpoint software to deploy, manage, or update. Every device is covered the moment you point DNS.
Live in 60 minutes
Deploy via Docker, update one DNS setting — and every device on your network is protected. No complex configuration required.
Complete query visibility
Every DNS request logged with domain, client IP, type, latency, answer, and block status — plus real-time risk scoring and world-map threat visualisation.
Audit-ready compliance
One-click reports mapped to NIST 800-53, CIS v8, ISO 27001, and NCSC — generated locally, ready for your auditor with no manual effort.
No cloud dependency
Unlike cloud DNS services, VeraDNS resolves within your perimeter — no external availability dependency and no third-party visibility into your traffic.
Common use cases
Enterprise perimeter defense
Replace or augment firewalls at the DNS layer — block malware, C2, and phishing across all devices, including IoT and OT, without deploying agents.
Compliance & data sovereignty
For regulated industries (finance, healthcare, government) needing on-premise data control, local audit logs, and reports mapped to NIST, CIS, ISO 27K, and NCSC.
Multi-site & branch networks
Protect remote offices and branches at the DNS layer without endpoint software — a single VeraDNS resolver covers every device on the site.
SOC & threat hunting
Give your SOC live query telemetry; stream logs to Splunk, Sentinel, or Elastic; detect C2 beaconing, DGA, and lateral movement via DNS.
IoT & OT security
Devices that can't run agents are secured at the network layer — blocking threats at the resolver before any connection is established.
MSP / multi-tenant
Run DNS security for multiple clients; role-based access separates environments; the Advanced plan adds custom integration and 24/7 SLA.
Secure your network at the DNS layer.
7-day free trial with full Professional features — no credit card, running on your own infrastructure. Data never leaves your network · live in under 60 minutes · zero agents.