DNS Filtering

DNS filtering resolution path and common bypass routes

DNS filtering stops a connection before it is made. It is the cheapest security control you can deploy, and the easiest one for a modern browser to walk around.

  • Glossary
  • Network

The short answer

DNS filtering intercepts the domain name lookup that precedes almost every network connection. The requested domain is checked against threat feeds and category lists, and a blocked domain simply never resolves, so no connection is attempted. It works across every port and protocol, not only web traffic.

The trade is that it sees domains and nothing else. Everything after the slash is invisible to it.

How DNS filtering works

Request Device asks for a domain Filtering resolver Receives the lookup Check Threat feed, category Allow Returns the IP Block No IP returned All of this happens before any packet reaches the destination. There is no session to inspect, no certificate to break and no payload to scan, which is why it is fast and why it cannot see very much.
What gets blockedWhy it works at this layer
Malware command and controlMalware calls home by domain. Blocking resolution cuts the channel even after infection
Phishing domainsThe link never resolves, so the credential page never loads
Newly registered domainsDomains registered in the last few days are disproportionately malicious and can be blocked as a class
Category policyGambling, adult content and similar categories, usually an acceptable-use requirement rather than a security one
Known bad infrastructureDomains tied to ransomware, cryptomining pools and botnets
Typosquatted domainsLookalikes of your own or your vendors’ domains, which supports the gap DMARC leaves open

Why it is the cheapest control

PropertyWhat it buys you
Pre-connectionNothing is downloaded and nothing is executed, because no session is ever established
Protocol agnosticCovers any application that resolves a name, not just browsers. Malware rarely uses port 443 exclusively
No decryptionNo certificate handling, no privacy debate, no performance cost from inspecting traffic
Fast to deployA resolver change or an agent setting, measured in hours
Works after infectionAn EDR miss is contained if the payload cannot reach its controller

That combination makes it a strong first control for a small team. It is not a substitute for endpoint protection, and treating it as one is the common mistake.

Where DNS filtering is bypassed

BypassHow it defeats the filter
Encrypted DNSDNS over HTTPS or TLS sends lookups directly to an external resolver inside encrypted traffic, invisible to yours
Hardcoded IP addressesMalware that connects to an address rather than a name never performs a lookup at all
Personal VPNAll traffic including resolution leaves through the tunnel
Mobile hotspotThe device leaves your network entirely, and with it your resolver
Shared hostingThe malicious page sits on a domain you cannot block without blocking a legitimate service
Cached entriesA previously resolved domain keeps working until the record expires

Encrypted DNS is the one that actually matters

Modern browsers can enable DNS over HTTPS by default, sending name lookups to their own provider over port 443. Your filtering resolver is never consulted, no policy is applied, and nothing appears in your logs to indicate it happened. The filter still reports healthy. Closing this requires either enterprise browser policy that disables the feature, or an endpoint agent that enforces resolution locally rather than relying on the network handing out a resolver.

DNS, URL and web filtering

Three overlapping terms that operate at different depths.

PropertyDNS filteringURL filteringSecure web gateway
SeesThe domain onlyThe full pathPath plus the content of the response
ActsBefore any connectionDuring the requestThroughout the session
Needs decryptionNoUsually yesYes
Covers non-web trafficYes, anything resolving a nameNoNo
Can block one page on a shared domainNoYesYes
Cost and complexityLowModerateHigh

Content filtering is the umbrella term covering all three, usually with acceptable-use policy in mind rather than threat blocking. In a SASE architecture the gateway component absorbs the deeper two, but DNS filtering keeps earning its place because it is the only one of the three that catches traffic which never touches a browser.

Where Osto fits

Content filtering runs inside the endpoint module rather than as a separate network appliance, which matters for the bypass problem above. Enforcement travelling with the device covers the laptop on a home network or a mobile hotspot, where a resolver configured at the office gateway stops applying the moment someone leaves the building.

The controls around it come from the same stack. Endpoint protection and device control govern what runs and what connects. Inbound email security removes most phishing before a user is ever asked to click. Private access means internal resources are unreachable regardless of what resolves, and blocked lookups land in the same SIEM as endpoint and identity events, so a repeated attempt to reach a known controller reads as an infected device rather than an isolated log line.

For evidence, filtering supports the acceptable-use and malicious-code controls sampled under SOC 2, ISO 27001 Annex A and HIPAA, all from one control set.

Platform walkthrough

Filtering that leaves the office with the laptop

Content filtering, endpoint protection and private access enforced on the device, with blocked lookups correlated against identity and endpoint events. One owner, one dashboard.

Book a demo

Evidence from live controls · 200+ frameworks mapped · One platform, everything

Frequently asked questions

What is DNS filtering?

A control that checks every domain lookup against threat and category lists, refusing to resolve blocked domains. Because it acts before a connection is established, nothing is downloaded or executed.

What is the difference between DNS filtering and URL filtering?

DNS filtering sees the domain only and acts before the connection. URL filtering sees the full path and usually requires decrypting traffic, so it can block a single page on a domain you otherwise allow. DNS filtering covers all protocols; URL filtering covers web traffic.

Can DNS filtering be bypassed?

Yes. Encrypted DNS in the browser, hardcoded IP addresses, personal VPNs and mobile hotspots all route around it. Encrypted DNS is the significant one, because it happens silently and by default in some browsers.

Does DNS filtering replace antivirus?

No. It reduces exposure and can cut an infected machine off from its controller, but it inspects no files and detects nothing running locally. Endpoint protection and EDR cover what happens on the device.

Does it work for remote staff?

Only if enforcement travels with the device. A resolver configured on the office network stops applying the moment a laptop joins a home network or a hotspot, which is why endpoint-level filtering is the durable form for distributed teams.