Glossary

What is DNS filtering?

What is DNS Filtering?

DNS filtering is a security and policy enforcement technology that controls access to websites and online services by evaluating DNS requests before a connection is established. Also known as protective DNS or a DNS firewall, DNS filtering helps organizations block access to malicious, inappropriate, or unauthorized destinations before users or devices can connect to them.

Because every internet session begins with a DNS query, DNS filtering provides an efficient and scalable way to reduce cyber risk, enforce acceptable use policies, and improve visibility into network activity.

{{anchor:How DNS filtering works}}

How DNS filtering works

When a user attempts to access a website or online service, a DNS request is made to resolve the destination domain. DNS filtering evaluates that request against predefined policies and threat intelligence sources before returning a response.

Based on the organization's policies, domains may be:

This allows organizations to prevent access to harmful destinations before a connection is established, reducing exposure to threats and policy violations.

{{anchor:Why DNS filtering matters}}

Why DNS filtering matters

DNS filtering helps organizations address a wide range of cybersecurity and operational challenges, including:

Because filtering occurs at the DNS layer, organizations can stop many threats before they reach endpoints, applications, or users.

{{anchor:Use cases}}

Common use cases:

{{anchor:Best practices}}

Best practices for DNS filtering

A modern protective DNS solution can help organizations respond more quickly to evolving threats while maintaining consistent security controls across distributed environments.

{{anchor:How DigiCert helps}}

How DigiCert can help

DigiCert UltraDDR provides next-generation protective DNS capabilities that help organizations proactively identify and block malicious domains before users and systems can connect to them. By combining real-time threat intelligence, advanced analytics, and continuous monitoring of adversary infrastructure, UltraDDR helps stop threats at the DNS layer before they impact the business.

UltraDDR supports category-based filtering, customizable policies, domain allowlists and blocklists, and protection for users both on and off the corporate network. Its intelligence-driven approach helps organizations reduce exposure to phishing, malware, command-and-control communications, and other DNS-based threats while improving visibility into network activity.

By strengthening DNS security and enforcing consistent internet usage policies, DigiCert UltraDDR helps organizations improve cyber resilience, support compliance initiatives, and create a safer online experience for users and devices.