DNS filtering stops a connection before it is made. It is the cheapest security control you can deploy, and the easiest one for a modern browser to walk around.
The short answer
DNS filtering intercepts the domain name lookup that precedes almost every network connection. The requested domain is checked against threat feeds and category lists, and a blocked domain simply never resolves, so no connection is attempted. It works across every port and protocol, not only web traffic.
The trade is that it sees domains and nothing else. Everything after the slash is invisible to it.
On this page
How DNS filtering works
| What gets blocked | Why it works at this layer |
|---|---|
| Malware command and control | Malware calls home by domain. Blocking resolution cuts the channel even after infection |
| Phishing domains | The link never resolves, so the credential page never loads |
| Newly registered domains | Domains registered in the last few days are disproportionately malicious and can be blocked as a class |
| Category policy | Gambling, adult content and similar categories, usually an acceptable-use requirement rather than a security one |
| Known bad infrastructure | Domains tied to ransomware, cryptomining pools and botnets |
| Typosquatted domains | Lookalikes of your own or your vendors’ domains, which supports the gap DMARC leaves open |
Why it is the cheapest control
| Property | What it buys you |
|---|---|
| Pre-connection | Nothing is downloaded and nothing is executed, because no session is ever established |
| Protocol agnostic | Covers any application that resolves a name, not just browsers. Malware rarely uses port 443 exclusively |
| No decryption | No certificate handling, no privacy debate, no performance cost from inspecting traffic |
| Fast to deploy | A resolver change or an agent setting, measured in hours |
| Works after infection | An EDR miss is contained if the payload cannot reach its controller |
That combination makes it a strong first control for a small team. It is not a substitute for endpoint protection, and treating it as one is the common mistake.
Where DNS filtering is bypassed
| Bypass | How it defeats the filter |
|---|---|
| Encrypted DNS | DNS over HTTPS or TLS sends lookups directly to an external resolver inside encrypted traffic, invisible to yours |
| Hardcoded IP addresses | Malware that connects to an address rather than a name never performs a lookup at all |
| Personal VPN | All traffic including resolution leaves through the tunnel |
| Mobile hotspot | The device leaves your network entirely, and with it your resolver |
| Shared hosting | The malicious page sits on a domain you cannot block without blocking a legitimate service |
| Cached entries | A previously resolved domain keeps working until the record expires |
Encrypted DNS is the one that actually matters
Modern browsers can enable DNS over HTTPS by default, sending name lookups to their own provider over port 443. Your filtering resolver is never consulted, no policy is applied, and nothing appears in your logs to indicate it happened. The filter still reports healthy. Closing this requires either enterprise browser policy that disables the feature, or an endpoint agent that enforces resolution locally rather than relying on the network handing out a resolver.
DNS, URL and web filtering
Three overlapping terms that operate at different depths.
| Property | DNS filtering | URL filtering | Secure web gateway |
|---|---|---|---|
| Sees | The domain only | The full path | Path plus the content of the response |
| Acts | Before any connection | During the request | Throughout the session |
| Needs decryption | No | Usually yes | Yes |
| Covers non-web traffic | Yes, anything resolving a name | No | No |
| Can block one page on a shared domain | No | Yes | Yes |
| Cost and complexity | Low | Moderate | High |
Content filtering is the umbrella term covering all three, usually with acceptable-use policy in mind rather than threat blocking. In a SASE architecture the gateway component absorbs the deeper two, but DNS filtering keeps earning its place because it is the only one of the three that catches traffic which never touches a browser.
Where Osto fits
Content filtering runs inside the endpoint module rather than as a separate network appliance, which matters for the bypass problem above. Enforcement travelling with the device covers the laptop on a home network or a mobile hotspot, where a resolver configured at the office gateway stops applying the moment someone leaves the building.
The controls around it come from the same stack. Endpoint protection and device control govern what runs and what connects. Inbound email security removes most phishing before a user is ever asked to click. Private access means internal resources are unreachable regardless of what resolves, and blocked lookups land in the same SIEM as endpoint and identity events, so a repeated attempt to reach a known controller reads as an infected device rather than an isolated log line.
For evidence, filtering supports the acceptable-use and malicious-code controls sampled under SOC 2, ISO 27001 Annex A and HIPAA, all from one control set.
Platform walkthrough
Filtering that leaves the office with the laptop
Content filtering, endpoint protection and private access enforced on the device, with blocked lookups correlated against identity and endpoint events. One owner, one dashboard.
Book a demoEvidence from live controls · 200+ frameworks mapped · One platform, everything
Frequently asked questions
What is DNS filtering?
A control that checks every domain lookup against threat and category lists, refusing to resolve blocked domains. Because it acts before a connection is established, nothing is downloaded or executed.
What is the difference between DNS filtering and URL filtering?
DNS filtering sees the domain only and acts before the connection. URL filtering sees the full path and usually requires decrypting traffic, so it can block a single page on a domain you otherwise allow. DNS filtering covers all protocols; URL filtering covers web traffic.
Can DNS filtering be bypassed?
Yes. Encrypted DNS in the browser, hardcoded IP addresses, personal VPNs and mobile hotspots all route around it. Encrypted DNS is the significant one, because it happens silently and by default in some browsers.
Does DNS filtering replace antivirus?
No. It reduces exposure and can cut an infected machine off from its controller, but it inspects no files and detects nothing running locally. Endpoint protection and EDR cover what happens on the device.
Does it work for remote staff?
Only if enforcement travels with the device. A resolver configured on the office network stops applying the moment a laptop joins a home network or a hotspot, which is why endpoint-level filtering is the durable form for distributed teams.

