Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call
HomeGlossaryDNS Filtering
Glossary

DNS Filtering

DNS filtering is a security control that checks each domain a device tries to reach against threat lists and refuses to resolve dangerous or banned sites.

Definition

What is DNS Filtering?

DNS Filtering is a security control that inspects domain name lookups and refuses to resolve the ones that lead to known malicious or unwanted sites. Every time a computer visits a website, opens a link in an email, or contacts a server in the background, it first asks the Domain Name System to translate a name into an IP address. A filtering resolver answers that question only when the destination passes its checks.

The filtering service maintains lists of domains associated with phishing, malware distribution, command-and-control servers, and newly registered domains that have no reputation yet. It also groups sites into categories, such as gambling or adult content, so a business can enforce an acceptable use policy. When a lookup matches a blocked entry, the resolver returns a block page or no answer at all, and the connection never happens. Because the check occurs before any traffic flows, a malicious page cannot load and malware that is already on a machine cannot reach its operator. Most services install a small agent on laptops so the protection follows the device off the office network.

For a small or mid-sized business DNS filtering is one of the cheapest controls with the broadest effect. It stops many phishing links even when an employee clicks, blocks the fake software download sites that malvertising campaigns push to the top of search results, and gives an administrator a log of which device tried to reach what. It is a complement to endpoint protection rather than a replacement, since it cannot see traffic that bypasses DNS or content served from a legitimate but compromised domain.

NetSys includes DNS filtering in its managed IT and network security services and manages the policy on the client's behalf, adjusting category blocks to match how the business works. Logs feed the same 24/7 monitoring the firm uses for endpoints, so a burst of blocked lookups from one machine is treated as a signal to investigate rather than a statistic to file.

Why it matters for a small business

Most attacks on a small business begin with a click, and most of those clicks lead to a domain that security researchers have already flagged. DNS filtering breaks the chain at that moment without asking anything of the employee. It also covers the devices that traditional firewalls miss, such as laptops on home Wi-Fi and phones on cellular data. Setup takes an afternoon, the policy is easy to explain to staff, and the logs give you a plain answer when someone asks whether a suspicious email did any damage.

Common Questions

DNS Filtering: FAQs

What does DNS filtering do?

DNS filtering stops devices from connecting to dangerous or prohibited websites by refusing to translate their domain names into IP addresses. When an employee clicks a phishing link or a program tries to contact a malware server, the filtering resolver checks the domain against threat lists and category rules, and if it matches, the connection is blocked before any data moves. It works for web browsing and for background traffic from installed software alike.

Is DNS filtering the same as a firewall?

No. A firewall controls traffic based on addresses, ports, and inspected content, usually at the edge of the office network. DNS filtering controls which destinations a device is allowed to look up at all, and with an agent installed it works wherever the device goes. The two overlap on some threats but catch different things, and most businesses run both. DNS filtering is simpler to deploy and is often the first control added when staff work from home.

Does DNS filtering protect remote workers?

It does when the service is deployed with an endpoint agent rather than only at the office router. The agent forces the laptop or desktop to use the filtering resolver no matter which network it joins, so a home connection or a hotel Wi-Fi gets the same protection as the office. Policies can also be set per user group, which lets a business apply stricter rules to shared kiosks than to the finance team.

Reading this because of a questionnaire or a renewal?

Get the controls, not just the definition.

A NetSys engineer can tell you in fifteen minutes whether you have this covered, and what it would take if you do not. Month to month, no long-term contract.