Protect people from risky links
Help prevent employees from reaching phishing and other malicious destinations through the protected DNS path.
Employees · Managed devicesProtect your people and workloads from risky destinations. DNS Shield brings FraudGuard threat intelligence into DNS resolution, so you can block or redirect lookups for hostile infrastructure.
callback.exampleThreat signal matches your block policy
The lookup is denied under your policy.
Protect the outbound path
Bring destination checks to the DNS
requests your people and systems make.
Help prevent employees from reaching phishing and other malicious destinations through the protected DNS path.
Employees · Managed devicesApply DNS policy to malware callbacks and command-and-control destinations used by compromised servers or workloads.
Servers · Cloud workloadsDefine which destinations to allow, deny, or sinkhole, with exceptions for the services your organization depends on.
Trusted services · Custom policyHow it works
A device or workload sends its DNS request through your protected resolution path.
Your users and systemsFraudGuard intelligence adds threat context to the destination. Your policy and exceptions inform the decision.
ACE intelligence + your rulesAllow normal resolution, deny the lookup, or redirect it to a sinkhole, according to your deployment.
Enforcement at resolution timeBuilt around your network
We scope the deployment around your resolvers, users, workloads, and change-control requirements.
Plan the DNS routing, trusted exceptions, query handling, and availability requirements before rollout.
Unbound is supported today. We review your current DNS architecture, internal domains, and forwarding requirements to confirm how DNS Shield fits your environment and what changes are needed.
Coverage depends on those systems sending requests through the protected DNS path. Include remote access, VPNs, branch offices, and cloud networks in your deployment plan so the routing matches the coverage you need.
Yes. Customer allowlists and internal exceptions are part of the policy design. Identify trusted services and partner destinations during planning so enforcement supports your business needs.
Keep both in place. DNS Shield adds protection at name resolution. Direct-IP connections, alternative resolvers, and traffic using already-cached answers need complementary network and endpoint controls.
DNS Shield is custom scoped and quoted separately from standard API plans. Pricing depends on delivery model, volume, and support needs. Contact us for a quote built around your environment.
Tell us how you run DNS today, which users or workloads need protection, and your approximate query volume. Add your policy goals, availability needs, and any data-handling requirements so we can scope a useful first conversation.
Let’s map out the right fit
Bring your network requirements.
We’ll help scope the protection, deployment, and price.