DNS & SASE

What is DNS filtering?

6 min readDNS & SASE

DNS filtering, also called protective DNS, stops threats at the very first step of almost every online interaction: the domain name lookup. Before a browser or application can connect to a site, it asks a DNS resolver to translate the domain into an IP address. DNS filtering inspects that request and blocks it if the domain is malicious — stopping malware, phishing and command-and-control before a single connection is ever made.

How DNS works — and where filtering fits

Every connection begins with a DNS query. When you visit a site, your device asks a resolver, "what is the IP address for this domain?" A protective DNS resolver checks the requested domain against constantly updated threat intelligence. If the domain is known-bad — a phishing page, malware host, or ransomware control server — the resolver simply refuses to answer, and the connection never happens.

Why blocking at the DNS layer is powerful

DNS filtering is uniquely efficient because it works before the connection. There is no malicious payload to inspect, no exploit to detonate — the threat is neutralised at the request stage. It is also network-wide and agentless: point your network's DNS to the protective resolver and every device is covered, including IoT and OT equipment that cannot run endpoint software. That breadth, at low cost, is why protective DNS has become a security baseline.

What DNS filtering blocks

  • Malware and ransomware domains — including the command-and-control servers infected hosts call home to.
  • Phishing and credential-theft sites — before the user can enter their password.
  • Newly registered and algorithmically generated domains commonly used in attacks.
  • Policy-violating categories — adult content, gambling and other sites by organisational policy.
  • Data-exfiltration and DNS-tunnelling attempts that abuse DNS to smuggle data out.

DNS filtering and encrypted DNS

Modern protective DNS supports encrypted transport — DNS-over-HTTPS (DoH), DNS-over-TLS (DoT) and DNS-over-QUIC (DoQ) — plus DNSSEC validation. Encryption prevents attackers from intercepting or tampering with lookups, while still allowing your chosen resolver to enforce policy. The result is privacy and protection together, rather than a trade-off between them.

On-premises vs cloud DNS security

Protective DNS can be delivered from the cloud or run on your own infrastructure. Cloud services are quick to adopt, while on-premises resolvers keep every query, policy and log inside your environment — important for organisations that require data sovereignty or operate sensitive networks. On-premises also removes dependence on an external service's availability for a function as fundamental as DNS.

How iconnet helps

iconnet deploys VeraDNS, an on-premise DNS firewall and filtering platform that blocks malware, phishing, ransomware and C2 at the DNS layer with zero endpoint agents — plus encrypted DNS, compliance reporting and a live query console. Contact us to add protective DNS to your defence-in-depth, on your own infrastructure.

Talk to a security specialist

Tell us about your environment and goals. Our engineers will help you scope the right solution — no obligation.