Vera Soft · DNS Security

VeraDNS

On-premise DNS firewall & filtering. Stop threats before the connection — zero agents, data never leaves your network.

VeraDNS is an on-premise DNS firewall and filtering platform — a protective DNS solution that inspects every DNS query on your network and blocks malware, phishing, ransomware, and command-and-control (C2) domains the instant they are requested, before a single TCP connection is made. No endpoint agents, no client software — deploy via Docker, point your network DNS to VeraDNS, and every device is protected.

Built for security and network teams that demand full data sovereignty, VeraDNS runs entirely on your own infrastructure — DNS queries, policy data, and audit logs never leave your environment. With live-in-under-60-minutes deployment, auto-updating threat feeds, one-click compliance reports mapped to NIST 800-53, CIS v8, ISO 27001 and NCSC, and a live real-time query console, VeraDNS gives enterprises complete DNS control without cloud dependency.

How DNS filtering works

Every DNS query from every device flows through the on-premise VeraDNS engine, where it is inspected, matched against policy and threat intelligence, and then resolved or blocked — with full local logging and visibility at every step.

VeraDNS — How DNS Filtering WorksNetwork ClientsWorkstations / PCsMobile DevicesIoT / OT DevicesServersRemote BranchesVeraDNS EngineQuery InspectionPolicy EngineThreat IntelligenceEncrypted DNSFull Query LoggingOn-premise · blocks before any connectionAllowedResolved · Logged · countedBlockedNXDOMAIN · No connection · alertedVisibilityVera Insight · SIEM · REST API · Compliance · Audit logClick Allow or Block to trace a query's path — or click any node for details
VeraDNS DNS filtering flow: network clients to the on-premise engine, then allow or block, with full visibility

Vera Insight — live visibility

The Vera Insight console turns every DNS query into live visibility — a risk-posture score, allowed/blocked metrics, a real-time query stream, a world-map threat landscape, and resolver health at a glance — all generated locally on your infrastructure.

Vera Insight — Live Dashboardlive · on-premiseRISK SCORE73/ 100ModerateAuto-block ≥ 8015+ categoriesTRAFFIC1.24MqueriesAllowed96.8%Blocked3.2%QUERIES TODAY1.24M↑ 4.2%RESOLVER HEALTH<2 msmedian response2,481 qpsGlobal threat landscapeCloudflare RadarLive query streamc2.badhost.ruBlockedapi.github.comAllowedlogin.micros0ft.coBlockedcdn.company.comAllowedads.tracker.netBlockedThe Vera Insight console — click any widget for details
An example Vera Insight console: risk score, query metrics, live query stream, threat world-map, and resolver health

Platform features

VeraDNS provides a complete suite of DNS security and visibility controls, all running locally on your infrastructure. Every feature ships as part of the platform — no third-party plugins required.

VeraDNS Platform FeaturesNetwork-Wide FilteringEvery device — PCs, servers, IoT/OTZero agents to deployInstant estate-wide rollout2,000–20,000+ qpsReal-Time Threat IntelAuto-updating blocklist feedsMalware · phishing · ransomware · C2Advanced Threat add-on: sandboxingAuto-updated · no manual workRole-Based Access (RBAC)Admin · Editor · ViewerJWT, API-level enforcementEvery change loggedAPI-enforced · not just UIEncrypted DNSStandard DNS (port 53)DoH · DoT · DoQDNSSEC validationDoH + DoT + DNSSECProgrammable PolicyAllow/block by categoryPer group, client, or time windowCustom allow/block listsZero-downtime policy changesOne-Click ComplianceNIST 800-53 · CIS v8ISO 27001 · NCSCPDF / CSV / HTMLAuditor-ready in one clickSIEM & API ExportSplunk · Sentinel · ElasticREST API — JSON or CSVData stays in your pipelinePro & Advanced plansVera Insight ConsoleLive query stream — 2,481+ qpsRisk score + category breakdownWorld-map threat visualisationReal-time · fully localEvery feature ships with the platform — click any for details
The eight VeraDNS platform feature modules

Technical specifications

Deployment
Docker on any Linux server; self-managed on-premise, private cloud, or your own VMs — no cloud dependency.
Requirements
Minimum 2 vCPU, 2 GB RAM; HA via multiple resolver instances behind a load balancer.
DNS protocols
Standard DNS (port 53), DNS-over-HTTPS (DoH), DNS-over-TLS (DoT), DNS-over-QUIC (DoQ), and DNSSEC validation.
Throughput
Starter 2,000 qps · Professional 10,000 qps · Advanced 20,000+ qps; <2 ms median resolver response.
User scale
Starter 100 · Professional 500 · Advanced 1,000+ users.
Threat feeds
Auto-updating blocklists — malware, phishing, ransomware, C2, adware, trackers — 2M+ rules across 15+ categories (Cloudflare Radar, URLhaus, ThreatFox, and more); extended library on Pro+.
RBAC
Admin / Editor / Viewer; JWT authentication with HttpOnly cookies; configurable session expiry; API-level enforcement.
Compliance
Reports mapped to NIST 800-53, CIS v8, ISO 27001, NCSC; PDF / CSV / HTML; generated locally, never transmitted.
SIEM export
REST API — JSON or CSV; Splunk, Microsoft Sentinel, Elastic, and any compatible SIEM (Pro & Advanced).
SSO
SAML 2.0 and LDAP/Active Directory SSO on the Advanced plan.
Data privacy
Zero external transmission — all queries, policies, and logs stay on your infrastructure; 90+ days default audit-log retention.
Setup time
Live in under 60 minutes — point your network DNS to VeraDNS after the Docker deploy.

Pricing tiers

Three tiers scale from a single-site office to enterprise and MSP deployments. Every tier runs on your own infrastructure; the Professional plan includes a 7-day free trial.

FeatureEssentialsProfessionalMost popularAdvanced
Throughput2,000 qps10,000 qps20,000+ qps
Users1005001,000+
Best forSmall teams · single-siteGrowing orgs · SIEM usersEnterprises & MSPs
Blocklist libraryStandardExtendedExtended
RBAC rolesAdmin & ViewerAdmin · Editor · ViewerAdmin · Editor · Viewer
SIEM & REST API export
SSO (SAML 2.0 / LDAP/AD)
Custom integration dev
SupportEmailPriority email & chatSLA-backed 24/7
Free trial7-day

Advanced Threat add-on

Deeper threat intelligence, malware sandboxing, and command-and-control (C2) detection beyond the standard feeds. Layer on top of any plan.

Advanced Analytics add-on

Extended dashboards, behavioural anomaly detection, and custom report builders — designed for your SOC team. Available on any plan.

Why VeraDNS?

100% on-premise

Your DNS queries, policies, and audit logs never leave your infrastructure — full data sovereignty by design, not as an option.

Zero agents

Network-wide protection with no endpoint software to deploy, manage, or update. Every device is covered the moment you point DNS.

Live in 60 minutes

Deploy via Docker, update one DNS setting — and every device on your network is protected. No complex configuration required.

Complete query visibility

Every DNS request logged with domain, client IP, type, latency, answer, and block status — plus real-time risk scoring and world-map threat visualisation.

Audit-ready compliance

One-click reports mapped to NIST 800-53, CIS v8, ISO 27001, and NCSC — generated locally, ready for your auditor with no manual effort.

No cloud dependency

Unlike cloud DNS services, VeraDNS resolves within your perimeter — no external availability dependency and no third-party visibility into your traffic.

Common use cases

Enterprise perimeter defense

Replace or augment firewalls at the DNS layer — block malware, C2, and phishing across all devices, including IoT and OT, without deploying agents.

Compliance & data sovereignty

For regulated industries (finance, healthcare, government) needing on-premise data control, local audit logs, and reports mapped to NIST, CIS, ISO 27K, and NCSC.

Multi-site & branch networks

Protect remote offices and branches at the DNS layer without endpoint software — a single VeraDNS resolver covers every device on the site.

SOC & threat hunting

Give your SOC live query telemetry; stream logs to Splunk, Sentinel, or Elastic; detect C2 beaconing, DGA, and lateral movement via DNS.

IoT & OT security

Devices that can't run agents are secured at the network layer — blocking threats at the resolver before any connection is established.

MSP / multi-tenant

Run DNS security for multiple clients; role-based access separates environments; the Advanced plan adds custom integration and 24/7 SLA.

Secure your network at the DNS layer.

7-day free trial with full Professional features — no credit card, running on your own infrastructure. Data never leaves your network · live in under 60 minutes · zero agents.