Every time you type a website address into your browser, your computer asks a DNS server to translate that human-readable name into an IP address. It happens billions of times a day across the internet, completely invisibly. And it's also one of the easiest places to insert a security control that blocks threats before they ever reach your network.
DNS filtering is exactly what it sounds like: filtering DNS requests so that known-malicious, suspicious, or policy-violating domains never resolve. The user's device asks to connect to a bad domain, and instead of getting an IP address back, it gets blocked. The malicious page never loads. The malware never downloads. The phishing form never appears. Done.
Why This Matters More Than You'd Think
Most cyberattacks involve DNS at some point. Phishing emails contain links to malicious domains. Malware phones home to command-and-control servers using DNS. Drive-by downloads happen when users land on compromised websites. Ransomware retrieves encryption keys from attacker-controlled domains. If you can block the DNS resolution, you break the attack chain before anything malicious executes.
The numbers back this up. Cisco's annual security report found that DNS-layer security blocks over 85% of command-and-control callbacks before any connection is established. Akamai's threat research showed that 91% of malware uses DNS to communicate. That's not a minor percentage - that's nearly all of it.
How It Works in Practice
The implementation is almost embarrassingly simple. You point your network's DNS to a filtering service instead of a generic public DNS resolver. Instead of using Google's 8.8.8.8 or your ISP's default DNS, your devices use a DNS resolver that checks every request against continuously updated threat intelligence databases.
When we deploy Cisco Umbrella or configure DNS filtering through Cisco Meraki for our managed IT clients, the process typically takes less than 30 minutes per location. For businesses using Meraki networking equipment - which many of our Utah clients do - it's a configuration toggle. The Meraki dashboard lets us enable DNS filtering across all network devices with a few clicks, apply content filtering policies, and immediately start seeing analytics on what's being blocked.
For remote workers, a lightweight agent on their device routes DNS queries through the filtering service regardless of which network they're on. Home network, hotel Wi-Fi, airport - it doesn't matter. The protection follows the user.
What DNS Filtering Actually Blocks
| Threat Category | What It Looks Like | How DNS Filtering Stops It |
|---|---|---|
| Phishing | Employee clicks a link in a spoofed email | Fake domain is flagged and blocked before the page loads |
| Malware downloads | Drive-by download from a compromised website | Known-malicious domains and newly registered suspicious domains are blocked |
| Command and control | Malware on a device tries to phone home for instructions | C2 domain resolution is blocked, malware can't receive commands |
| Cryptomining | Browser-based scripts mining cryptocurrency using your hardware | Mining pool domains are blocked |
| Newly registered domains | Attacker registers a domain 24 hours before a campaign | Domains less than a configurable age threshold are blocked or flagged |
That last category - newly registered domains - is particularly powerful. Attackers frequently register domains hours or days before using them in phishing campaigns, specifically to avoid being in existing blocklists. DNS filtering services that flag or block domains less than 30 days old catch a massive number of these attacks that would bypass traditional email filtering.
Beyond Security: Content Filtering
DNS filtering also gives you content filtering capabilities. Block categories of websites that are inappropriate for the workplace, a productivity drain, or a bandwidth hog. Streaming services eating your office bandwidth? Blockable. Social media during work hours? Configurable by policy. Gambling, adult content, or other categories that create HR or legal risk? Blocked silently at the DNS level without needing to install software on every device.
For businesses with compliance requirements - healthcare offices, financial services, legal firms - content filtering through DNS is one of the simplest ways to demonstrate that you're maintaining appropriate access controls on your network. Auditors like seeing it. It checks a box that's easy to miss otherwise.
The Cost Question
This is where DNS filtering really stands out. Enterprise DNS filtering services typically cost $2-4 per user per month. For a 25-person company, that's $50-100/month for a security layer that blocks the majority of web-based threats. Compare that to the cost of cleaning up a single malware incident - which runs $5,000-25,000 for a small business, not counting downtime - and the ROI is absurd.
If you're already using Cisco Meraki for your network infrastructure, DNS filtering through the Meraki dashboard may already be included in your licensing. We've had clients discover they were paying for this capability and not using it. That's security budget literally sitting on the shelf.
Limitations to Understand
DNS filtering is powerful but it's not a silver bullet. It won't stop threats delivered through IP addresses directly (bypassing DNS), it won't inspect encrypted traffic content, and it won't catch malicious content hosted on legitimate platforms like Google Drive or Dropbox. It's a layer - an important, cost-effective, fast-to-deploy layer - but it works best alongside endpoint detection (like Huntress), email filtering, and user awareness training.
Think of it as the bouncer at the door. The bouncer catches the obvious troublemakers and the known bad actors before they get inside. You still need security cameras, locked doors, and trained staff inside. But without the bouncer, everything that walks up to the door gets in.
If you don't currently have DNS filtering on your network, it's one of the fastest security wins available. We can typically deploy it in a single afternoon. Talk to our team about adding DNS-layer protection to your environment - it's one of those rare cases where the cost is low, the effort is minimal, and the security improvement is immediate.
