Skip to content

Security & DNS

Protective DNS Filtering

Recursive DNS filtering that blocks malware, phishing and command-and-control domains before a connection is ever made, applied to offices and roaming devices.

Protective DNS filtering appliance blocking malicious lookups shown as interrupted light paths
SYSTEM ACTIVE
QUERY FILTERING · Protective DNS Filtering

Capabilities

What we implement

  • Policy design per site, group and device
  • Roaming client rollout on laptops and mobiles
  • Category and threat-feed tuning to cut false positives
  • Reporting on blocked requests and repeat offenders

Security

How it is hardened

  • Blocks known malicious resolution before traffic starts
  • Encrypted DNS transport to the resolver
  • Bypass prevention on local resolvers and hard-coded servers

Editions & pricing

Protective DNS Filtering editions and vendor pricing

Vendor list prices for the editions we deploy. Deployment, migration, hardening and support are quoted separately by Techno Trader PK — they are never bundled into these figures.

Protective DNS Filtering editions, licensing unit and vendor list price
EditionLicensed byVendor list price
Managed protective DNSIndicative market rate; final price depends on the platform selected.per user / month$2

Prices are checked against the vendor's published price list. Last verified 10 Sept 2026. Vendor list prices exclude tax and can change without notice.

Licence cost is only part of the number. Add deployment, migration and ongoing support to see the real figure for your environment.Get a scoped quote

Architecture

Protective DNS resolution path

Every lookup is answered by a filtering resolver, so known malicious destinations fail to resolve before any connection is attempted.

  1. 01 · Clients

    Office devicesRoaming laptopsMobile devicesServers

    Roaming clients keep policy off-network, where most incidents actually start.

  2. 02 · Resolver

    Filtering resolverEncrypted DNS transportSite policy

    Policy can differ by site, group or device class.

  3. 03 · Intelligence

    Malware and phishing feedsCommand-and-control listsCategory policy

    Threat feeds are tuned so blocking does not disrupt legitimate business tools.

  4. 04 · Assurance

    Blocked-request reportingBypass preventionException workflow

    Hard-coded resolvers on devices are blocked so filtering cannot be sidestepped.

FAQ

Protective DNS Filtering questions we are asked

Does DNS filtering replace endpoint protection?
No. It removes a large share of commodity threats early and cheaply, but it does not inspect files or process behaviour — endpoint protection still does that.
What about false positives?
An exception workflow is set up on day one so a blocked business tool is released in minutes rather than becoming a reason to disable filtering.
Can staff bypass it?
Not where devices are managed: hard-coded public resolvers are blocked at the firewall and encrypted DNS is pointed at the filtering service.

Related

Other security & dns platforms

Protective DNS Filtering is referenced to describe engineering capability. All trademarks and product names are the property of their respective owners; no partnership or endorsement is implied.

Ready to scope the work?

Share your environment and objectives. You will get an engineering response covering scope, approach and considerations.