{"id":1208,"date":"2026-09-13T18:49:09","date_gmt":"2026-09-13T18:49:09","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1208"},"modified":"2026-09-13T18:49:09","modified_gmt":"2026-09-13T18:49:09","slug":"dns-filtering","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/dns-filtering\/","title":{"rendered":"DNS Filtering"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: DNS FILTERING\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">DNS filtering stops a connection before it is made. It is the cheapest security control you can deploy, and the easiest one for a modern browser to walk around.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Network<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>DNS filtering intercepts the domain name lookup that precedes almost every network connection. The requested domain is checked against threat feeds and category lists, and a blocked domain simply never resolves, so no connection is attempted. It works across every port and protocol, not only web traffic.<\/p>\n<\/div>\n\n<p>The trade is that it sees domains and nothing else. Everything after the slash is invisible to it.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#how\">How DNS filtering works<\/a><\/li>\n    <li><a href=\"#why\">Why it is the cheapest control<\/a><\/li>\n    <li><a href=\"#bypass\">Where DNS filtering is bypassed<\/a><\/li>\n    <li><a href=\"#versus\">DNS, URL and web filtering<\/a><\/li>\n    <li><a href=\"#osto\">Where Osto fits<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"how\">How DNS filtering works<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 194\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"DNS filtering path: request, filtering resolver, category and threat check, then allow or block before any connection.\">\n  <defs><marker id=\"dn\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6.5\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <rect x=\"10\" y=\"20\" width=\"150\" height=\"76\" rx=\"12\" fill=\"#e2eff7\"\/>\n  <text x=\"85\" y=\"50\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#2f6f96\">Request<\/text>\n  <text x=\"85\" y=\"71\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Device asks for a domain<\/text>\n  <line x1=\"164\" y1=\"58\" x2=\"182\" y2=\"58\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#dn)\"\/>\n\n  <rect x=\"188\" y=\"20\" width=\"150\" height=\"76\" rx=\"12\" fill=\"#cfd5f2\"\/>\n  <text x=\"263\" y=\"50\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#1c267a\">Filtering resolver<\/text>\n  <text x=\"263\" y=\"71\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Receives the lookup<\/text>\n  <line x1=\"342\" y1=\"58\" x2=\"360\" y2=\"58\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#dn)\"\/>\n\n  <rect x=\"366\" y=\"20\" width=\"150\" height=\"76\" rx=\"12\" fill=\"#efe4f0\"\/>\n  <text x=\"441\" y=\"50\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#6b4576\">Check<\/text>\n  <text x=\"441\" y=\"71\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Threat feed, category<\/text>\n  <line x1=\"520\" y1=\"58\" x2=\"538\" y2=\"58\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#dn)\"\/>\n\n  <rect x=\"544\" y=\"20\" width=\"98\" height=\"76\" rx=\"12\" fill=\"#e3f0e9\"\/>\n  <text x=\"593\" y=\"50\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#3a6f5d\">Allow<\/text>\n  <text x=\"593\" y=\"71\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Returns the IP<\/text>\n\n  <rect x=\"650\" y=\"20\" width=\"100\" height=\"76\" rx=\"12\" fill=\"#fbe9dc\"\/>\n  <text x=\"700\" y=\"50\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#a2603a\">Block<\/text>\n  <text x=\"700\" y=\"71\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">No IP returned<\/text>\n\n  <rect x=\"10\" y=\"114\" width=\"740\" height=\"62\" rx=\"12\" fill=\"#e9ecfa\"\/>\n  <text x=\"380\" y=\"136\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#1c267a\">All of this happens before any packet reaches the destination.<\/text>\n  <text x=\"380\" y=\"155\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#3f4796\">There is no session to inspect, no certificate to break and no payload to scan,<\/text>\n  <text x=\"380\" y=\"170\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#3f4796\">which is why it is fast and why it cannot see very much.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>What gets blocked<\/th><th>Why it works at this layer<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Malware command and control<\/td><td>Malware calls home by domain. Blocking resolution cuts the channel even after infection<\/td><\/tr>\n    <tr><td>Phishing domains<\/td><td>The link never resolves, so the credential page never loads<\/td><\/tr>\n    <tr><td>Newly registered domains<\/td><td>Domains registered in the last few days are disproportionately malicious and can be blocked as a class<\/td><\/tr>\n    <tr><td>Category policy<\/td><td>Gambling, adult content and similar categories, usually an acceptable-use requirement rather than a security one<\/td><\/tr>\n    <tr><td>Known bad infrastructure<\/td><td>Domains tied to ransomware, cryptomining pools and botnets<\/td><\/tr>\n    <tr><td>Typosquatted domains<\/td><td>Lookalikes of your own or your vendors&#8217; domains, which supports the gap DMARC leaves open<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"why\" class=\"c-sage\">Why it is the cheapest control<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Property<\/th><th>What it buys you<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Pre-connection<\/td><td>Nothing is downloaded and nothing is executed, because no session is ever established<\/td><\/tr>\n    <tr><td>Protocol agnostic<\/td><td>Covers any application that resolves a name, not just browsers. Malware rarely uses port 443 exclusively<\/td><\/tr>\n    <tr><td>No decryption<\/td><td>No certificate handling, no privacy debate, no performance cost from inspecting traffic<\/td><\/tr>\n    <tr><td>Fast to deploy<\/td><td>A resolver change or an agent setting, measured in hours<\/td><\/tr>\n    <tr><td>Works after infection<\/td><td>An <a href=\"https:\/\/www.osto.one\/resources\/glossary\/edr\/\">EDR<\/a> miss is contained if the payload cannot reach its controller<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>That combination makes it a strong first control for a small team. It is not a substitute for endpoint protection, and treating it as one is the common mistake.<\/p>\n\n<h2 id=\"bypass\" class=\"c-plum\">Where DNS filtering is bypassed<\/h2>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Bypass<\/th><th>How it defeats the filter<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Encrypted DNS<\/td><td>DNS over HTTPS or TLS sends lookups directly to an external resolver inside encrypted traffic, invisible to yours<\/td><\/tr>\n    <tr><td>Hardcoded IP addresses<\/td><td>Malware that connects to an address rather than a name never performs a lookup at all<\/td><\/tr>\n    <tr><td>Personal VPN<\/td><td>All traffic including resolution leaves through the tunnel<\/td><\/tr>\n    <tr><td>Mobile hotspot<\/td><td>The device leaves your network entirely, and with it your resolver<\/td><\/tr>\n    <tr><td>Shared hosting<\/td><td>The malicious page sits on a domain you cannot block without blocking a legitimate service<\/td><\/tr>\n    <tr><td>Cached entries<\/td><td>A previously resolved domain keeps working until the record expires<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Encrypted DNS is the one that actually matters<\/p>\n  <p>Modern browsers can enable DNS over HTTPS by default, sending name lookups to their own provider over port 443. Your filtering resolver is never consulted, no policy is applied, and nothing appears in your logs to indicate it happened. The filter still reports healthy. Closing this requires either enterprise browser policy that disables the feature, or an endpoint agent that enforces resolution locally rather than relying on the network handing out a resolver.<\/p>\n<\/div>\n\n<h2 id=\"versus\" class=\"c-sky\">DNS, URL and web filtering<\/h2>\n\n<p>Three overlapping terms that operate at different depths.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Property<\/th><th>DNS filtering<\/th><th>URL filtering<\/th><th>Secure web gateway<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Sees<\/td><td>The domain only<\/td><td>The full path<\/td><td>Path plus the content of the response<\/td><\/tr>\n    <tr><td>Acts<\/td><td>Before any connection<\/td><td>During the request<\/td><td>Throughout the session<\/td><\/tr>\n    <tr><td>Needs decryption<\/td><td>No<\/td><td>Usually yes<\/td><td>Yes<\/td><\/tr>\n    <tr><td>Covers non-web traffic<\/td><td>Yes, anything resolving a name<\/td><td>No<\/td><td>No<\/td><\/tr>\n    <tr><td>Can block one page on a shared domain<\/td><td>No<\/td><td>Yes<\/td><td>Yes<\/td><\/tr>\n    <tr><td>Cost and complexity<\/td><td>Low<\/td><td>Moderate<\/td><td>High<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Content filtering is the umbrella term covering all three, usually with acceptable-use policy in mind rather than threat blocking. In a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sase\/\">SASE<\/a> architecture the gateway component absorbs the deeper two, but DNS filtering keeps earning its place because it is the only one of the three that catches traffic which never touches a browser.<\/p>\n\n<h2 id=\"osto\">Where Osto fits<\/h2>\n\n<p>Content filtering runs inside the endpoint module rather than as a separate network appliance, which matters for the bypass problem above. Enforcement travelling with the device covers the laptop on a home network or a mobile hotspot, where a resolver configured at the office gateway stops applying the moment someone leaves the building.<\/p>\n\n<p>The controls around it come from the same stack. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/epp\/\">Endpoint protection<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/device-control\/\">device control<\/a> govern what runs and what connects. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/email-security\/\">Inbound email security<\/a> removes most phishing before a user is ever asked to click. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">Private access<\/a> means internal resources are unreachable regardless of what resolves, and blocked lookups land in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">the same SIEM<\/a> as endpoint and identity events, so a repeated attempt to reach a known controller reads as an infected device rather than an isolated log line.<\/p>\n\n<p>For evidence, filtering supports the acceptable-use and malicious-code controls sampled under <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">ISO 27001 Annex A<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/hipaa\/\">HIPAA<\/a>, all from one control set.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Filtering that leaves the office with the laptop<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Content filtering, endpoint protection and private access enforced on the device, with blocked lookups correlated against identity and endpoint events. One owner, one dashboard.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">Evidence from live controls &middot; 200+ frameworks mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is DNS filtering?<\/summary>\n  <p>A control that checks every domain lookup against threat and category lists, refusing to resolve blocked domains. Because it acts before a connection is established, nothing is downloaded or executed.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between DNS filtering and URL filtering?<\/summary>\n  <p>DNS filtering sees the domain only and acts before the connection. URL filtering sees the full path and usually requires decrypting traffic, so it can block a single page on a domain you otherwise allow. DNS filtering covers all protocols; URL filtering covers web traffic.<\/p>\n<\/details>\n\n<details>\n  <summary>Can DNS filtering be bypassed?<\/summary>\n  <p>Yes. Encrypted DNS in the browser, hardcoded IP addresses, personal VPNs and mobile hotspots all route around it. Encrypted DNS is the significant one, because it happens silently and by default in some browsers.<\/p>\n<\/details>\n\n<details>\n  <summary>Does DNS filtering replace antivirus?<\/summary>\n  <p>No. It reduces exposure and can cut an infected machine off from its controller, but it inspects no files and detects nothing running locally. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/epp\/\">Endpoint protection<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/edr\/\">EDR<\/a> cover what happens on the device.<\/p>\n<\/details>\n\n<details>\n  <summary>Does it work for remote staff?<\/summary>\n  <p>Only if enforcement travels with the device. A resolver configured on the office network stops applying the moment a laptop joins a home network or a hotspot, which is why endpoint-level filtering is the durable form for distributed teams.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/epp\/\">EPP<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/edr\/\">EDR<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/device-control\/\">Device Control<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/email-security\/\">Email Security<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">ZTNA<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sase\/\">SASE<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>DNS filtering stops a connection before it is made. It is the cheapest security control you can deploy, and the\u2026<\/p>\n","protected":false},"author":8,"featured_media":1209,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[611,610,607,608,609],"class_list":["post-1208","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-block-malicious-domains","tag-content-filtering","tag-dns-filtering","tag-dns-filtering-vs-url-filtering","tag-dns-security"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1208","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1208"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1208\/revisions"}],"predecessor-version":[{"id":1210,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1208\/revisions\/1210"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1209"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1208"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1208"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1208"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}