Cybersecurity6 min read

DNS Filtering: The Cheapest Security Layer You're Not Using

By Inevat Team·September 30, 2026
DNS Filtering: The Cheapest Security Layer You're Not Using

Image by panumas nikhomkhai

Every time you type a website address into your browser, your computer asks a DNS server to translate that human-readable name into an IP address. It happens billions of times a day across the internet, completely invisibly. And it's also one of the easiest places to insert a security control that blocks threats before they ever reach your network.

DNS filtering is exactly what it sounds like: filtering DNS requests so that known-malicious, suspicious, or policy-violating domains never resolve. The user's device asks to connect to a bad domain, and instead of getting an IP address back, it gets blocked. The malicious page never loads. The malware never downloads. The phishing form never appears. Done.

Why This Matters More Than You'd Think

Most cyberattacks involve DNS at some point. Phishing emails contain links to malicious domains. Malware phones home to command-and-control servers using DNS. Drive-by downloads happen when users land on compromised websites. Ransomware retrieves encryption keys from attacker-controlled domains. If you can block the DNS resolution, you break the attack chain before anything malicious executes.

The numbers back this up. Cisco's annual security report found that DNS-layer security blocks over 85% of command-and-control callbacks before any connection is established. Akamai's threat research showed that 91% of malware uses DNS to communicate. That's not a minor percentage - that's nearly all of it.

How It Works in Practice

The implementation is almost embarrassingly simple. You point your network's DNS to a filtering service instead of a generic public DNS resolver. Instead of using Google's 8.8.8.8 or your ISP's default DNS, your devices use a DNS resolver that checks every request against continuously updated threat intelligence databases.

When we deploy Cisco Umbrella or configure DNS filtering through Cisco Meraki for our managed IT clients, the process typically takes less than 30 minutes per location. For businesses using Meraki networking equipment - which many of our Utah clients do - it's a configuration toggle. The Meraki dashboard lets us enable DNS filtering across all network devices with a few clicks, apply content filtering policies, and immediately start seeing analytics on what's being blocked.

For remote workers, a lightweight agent on their device routes DNS queries through the filtering service regardless of which network they're on. Home network, hotel Wi-Fi, airport - it doesn't matter. The protection follows the user.

What DNS Filtering Actually Blocks

Threat Category What It Looks Like How DNS Filtering Stops It
Phishing Employee clicks a link in a spoofed email Fake domain is flagged and blocked before the page loads
Malware downloads Drive-by download from a compromised website Known-malicious domains and newly registered suspicious domains are blocked
Command and control Malware on a device tries to phone home for instructions C2 domain resolution is blocked, malware can't receive commands
Cryptomining Browser-based scripts mining cryptocurrency using your hardware Mining pool domains are blocked
Newly registered domains Attacker registers a domain 24 hours before a campaign Domains less than a configurable age threshold are blocked or flagged

That last category - newly registered domains - is particularly powerful. Attackers frequently register domains hours or days before using them in phishing campaigns, specifically to avoid being in existing blocklists. DNS filtering services that flag or block domains less than 30 days old catch a massive number of these attacks that would bypass traditional email filtering.

Beyond Security: Content Filtering

DNS filtering also gives you content filtering capabilities. Block categories of websites that are inappropriate for the workplace, a productivity drain, or a bandwidth hog. Streaming services eating your office bandwidth? Blockable. Social media during work hours? Configurable by policy. Gambling, adult content, or other categories that create HR or legal risk? Blocked silently at the DNS level without needing to install software on every device.

For businesses with compliance requirements - healthcare offices, financial services, legal firms - content filtering through DNS is one of the simplest ways to demonstrate that you're maintaining appropriate access controls on your network. Auditors like seeing it. It checks a box that's easy to miss otherwise.

The Cost Question

This is where DNS filtering really stands out. Enterprise DNS filtering services typically cost $2-4 per user per month. For a 25-person company, that's $50-100/month for a security layer that blocks the majority of web-based threats. Compare that to the cost of cleaning up a single malware incident - which runs $5,000-25,000 for a small business, not counting downtime - and the ROI is absurd.

If you're already using Cisco Meraki for your network infrastructure, DNS filtering through the Meraki dashboard may already be included in your licensing. We've had clients discover they were paying for this capability and not using it. That's security budget literally sitting on the shelf.

Limitations to Understand

DNS filtering is powerful but it's not a silver bullet. It won't stop threats delivered through IP addresses directly (bypassing DNS), it won't inspect encrypted traffic content, and it won't catch malicious content hosted on legitimate platforms like Google Drive or Dropbox. It's a layer - an important, cost-effective, fast-to-deploy layer - but it works best alongside endpoint detection (like Huntress), email filtering, and user awareness training.

Think of it as the bouncer at the door. The bouncer catches the obvious troublemakers and the known bad actors before they get inside. You still need security cameras, locked doors, and trained staff inside. But without the bouncer, everything that walks up to the door gets in.

If you don't currently have DNS filtering on your network, it's one of the fastest security wins available. We can typically deploy it in a single afternoon. Talk to our team about adding DNS-layer protection to your environment - it's one of those rare cases where the cost is low, the effort is minimal, and the security improvement is immediate.


Need help with this? We can assist.

Inevat provides managed IT and cybersecurity for businesses nationwide. Schedule a free consultation to talk through your situation.

Schedule a Free Consultation

Related Articles

Cybersecurity

BYOD Is Not a Security Policy - It's a Liability Without One

Your employees are using personal phones and laptops for work whether you've approved it or not. Without a mobile device management strategy, every one of those devices is an unmonitored access point to your business data.

Read Article: BYOD Is Not a Security Policy - It's a Liability Without One
Cybersecurity

The Real Reason Small Businesses Get Breached (It's Not What You Think)

Small businesses don't get breached because hackers specifically target them. They get breached because they have the same vulnerabilities as large enterprises - without the security infrastructure to catch them. Here's what that means for you.

Read Article: The Real Reason Small Businesses Get Breached (It's Not What You Think)
Cybersecurity

Email Forwarding Rules: The Silent Backdoor in Your Inbox

One of the first things attackers do after compromising a business email account is create a hidden forwarding rule. It survives password resets, MFA changes, and most cleanup attempts. Here's how to find and stop them.

Read Article: Email Forwarding Rules: The Silent Backdoor in Your Inbox