Security & DNS
Protective DNS Filtering
Recursive DNS filtering that blocks malware, phishing and command-and-control domains before a connection is ever made, applied to offices and roaming devices.

Capabilities
What we implement
- Policy design per site, group and device
- Roaming client rollout on laptops and mobiles
- Category and threat-feed tuning to cut false positives
- Reporting on blocked requests and repeat offenders
Security
How it is hardened
- Blocks known malicious resolution before traffic starts
- Encrypted DNS transport to the resolver
- Bypass prevention on local resolvers and hard-coded servers
Editions & pricing
Protective DNS Filtering editions and vendor pricing
Vendor list prices for the editions we deploy. Deployment, migration, hardening and support are quoted separately by Techno Trader PK — they are never bundled into these figures.
| Edition | Licensed by | Vendor list price |
|---|---|---|
| Managed protective DNSIndicative market rate; final price depends on the platform selected. | per user / month | $2 |
Prices are checked against the vendor's published price list. Last verified 10 Sept 2026. Vendor list prices exclude tax and can change without notice.
Architecture
Protective DNS resolution path
Every lookup is answered by a filtering resolver, so known malicious destinations fail to resolve before any connection is attempted.
01 · Clients
Office devicesRoaming laptopsMobile devicesServersRoaming clients keep policy off-network, where most incidents actually start.
02 · Resolver
Filtering resolverEncrypted DNS transportSite policyPolicy can differ by site, group or device class.
03 · Intelligence
Malware and phishing feedsCommand-and-control listsCategory policyThreat feeds are tuned so blocking does not disrupt legitimate business tools.
04 · Assurance
Blocked-request reportingBypass preventionException workflowHard-coded resolvers on devices are blocked so filtering cannot be sidestepped.
FAQ
Protective DNS Filtering questions we are asked
- Does DNS filtering replace endpoint protection?
- No. It removes a large share of commodity threats early and cheaply, but it does not inspect files or process behaviour — endpoint protection still does that.
- What about false positives?
- An exception workflow is set up on day one so a blocked business tool is released in minutes rather than becoming a reason to disable filtering.
- Can staff bypass it?
- Not where devices are managed: hard-coded public resolvers are blocked at the firewall and encrypted DNS is pointed at the filtering service.
Related
Other security & dns platforms
Protective DNS Filtering is referenced to describe engineering capability. All trademarks and product names are the property of their respective owners; no partnership or endorsement is implied.
Ready to scope the work?
Share your environment and objectives. You will get an engineering response covering scope, approach and considerations.