Protective DNS Service

Stop malicious connections before they start.

Protect users from phishing, malware, ransomware and other dangerous destinations by blocking threats at the DNS layer, before a connection is made.  Total Uptime Protective DNS provides always-on protection across corporate networks and roaming users, with real-time threat detection, centralized policy control and visibility into DNS activity.

No endpoint agent required

Protection for on-network and roaming users

Built to meet NSA/CISA Protective DNS guidance

Protective DNS Security Architecture

Stop threats at the first point of connection

Before a user visits a website, opens a cloud application or connects to an online service, their device typically makes a DNS request to find its destination.

 

That creates an opportunity to stop threats before the connection is ever established.

 

Total Uptime Protective DNS evaluates DNS requests and blocks access to known and emerging malicious destinations, helping prevent users and devices from connecting to phishing sites, malware infrastructure, botnets and command-and-control servers.

Safe destination

User → DNS request → Total Uptime Protective DNS → Destination allowed

 

Legitimate requests resolve normally, with policies applied automatically.

Malicious destination

User → DNS request → Total Uptime Protective DNS → Threat blocked

 

Connections to malicious or restricted destinations are stopped before the user reaches them.

Protect users wherever they work

DNS protection shouldn’t disappear when someone leaves the office.

Total Uptime Protective DNS extends security beyond the corporate network, helping protect users whether they are working from an office, home, branch location or on the move.

Block threats earlier

Prevent connections to malicious domains before malware, phishing or command-and-control traffic reaches its destination.

Protect roaming users

Apply Protective DNS policies to users working beyond the corporate network across Windows, Mac, iOS, Android and ChromeOS.

Respond to emerging threats

Use machine-learning analysis to identify suspicious, newly registered and generated domains rather than relying solely on static threat lists.

Gain DNS visibility

See DNS requests, blocked threats, activity patterns and destinations through centralized reporting and query logging.

More than a malicious-domain blocklist

Attackers continually create new domains and infrastructure to evade traditional security controls.

 

Protective DNS therefore needs to identify more than threats that are already known.

 

Total Uptime combines threat intelligence, real-time analysis and DNS-layer policy enforcement to help identify and block both known and emerging threats.

Protection includes:

One Protective DNS service. Protection across your organization.

Protective DNS isn’t only about blocking malicious websites. It also gives IT and security teams centralized control over how DNS is used throughout the organization.

Security filtering

Block malicious domains and suspicious destinations before connections are established.

Content and category filtering

Create policies controlling the types of online content users or networks can access.

SafeSearch enforcement

Apply SafeSearch and restricted-mode policies across supported search and content platforms.

Multi-network policies

Apply different DNS policies to different locations, networks or user groups.

Query logging and reporting

Understand what users and devices are requesting, what has been blocked and where potential threats are occurring.

API and automation

Integrate DNS policies and management into existing operational and security workflows.

Built to the NSA/CISA Protective DNS standard

You shouldn’t have to take our word for what a capable Protective DNS service should provide.

NSA and CISA’s Selecting a Protective DNS Service guidance defines the capabilities organizations should consider when evaluating Protective DNS providers.

 

Total Uptime Protective DNS is built to meet the full set of capabilities outlined in that guidance, including malicious-domain blocking, phishing protection, DNS tunneling detection, protection against newly registered and generated domains, content filtering, roaming protection, query logging, reporting and automation.

Protective DNS for different security requirements

The same DNS security layer can address very different organizational requirements.

Users no longer work from a single office or network.

 

Total Uptime Protective DNS can extend security policies to roaming users, helping protect employees whether they are working from the office, home, another location or while traveling.

 

Roaming protection is available across major desktop and mobile platforms, including:

Windows

macOS

iOS

Android

ChromeOS

Security policies remain centrally managed, giving your organization consistent DNS protection across distributed users and devices.

State & Local Government

Replacing MS-ISAC MDBR?

 

Organizations affected by changes to MS-ISAC’s MDBR service can maintain Protective DNS coverage without simply accepting a new cost or reducing protection.

 

Compare your existing MDBR coverage with Total Uptime Protective DNS, including roaming-user protection, threat detection, filtering and reporting.

Defense Industrial Base

Need to address CMMC DNS filtering requirements?

 

Protective DNS provides a direct way to implement DNS filtering across corporate and roaming users while providing the policy and logging evidence security teams need.

 

Total Uptime Protective DNS supports organizations addressing CMMC DNS filtering requirements, with a FedRAMP-aligned deployment option available for applicable government-facing environments.

Education

Security and content filtering from one DNS layer

 

Protect students, faculty and staff from malicious destinations while applying content filtering, SafeSearch and separate policies across different networks and user groups.

Enterprise

Extend DNS security across distributed users and networks

 

Protect users across offices, branches, remote locations and roaming devices while centralizing DNS security policy and visibility.

Protective DNS without another complex security rollout

Adding another security control shouldn’t create another operational burden.

Total Uptime Protective DNS is cloud-delivered and designed to provide broad protection without disrupting the user experience.

Fast to deploy

Introduce DNS-layer protection without redesigning your application or network architecture.

No endpoint agent required

Protect network DNS traffic without installing another traditional security agent across every endpoint.

Built for distributed environments

Support networks and roaming users across multiple locations and platforms.

Centralized control

Manage policies, filtering, reporting and DNS activity from one service.

Protection is only one part of the application delivery story.

Protective DNS helps stop users and systems from connecting to dangerous destinations, but keeping applications available requires more than one security control.  Total Uptime brings application delivery capabilities together across cloud, on-premises and hybrid environments.

Deliver

Load Balancing | ADC | GSLB | Kubernetes Ingress

Protect

Protective DNS | WAF | WAAP

Connect

Multi-Cloud Networking | BGP over GRE | Hybrid Connectivity

Observe

Monitoring | Reporting | Traffic Visibility

Frequently asked questions

Quick answers to the questions infrastructure teams ask most.

What is Protective DNS?

Protective DNS is a security service that evaluates DNS requests before allowing users or devices to connect to internet destinations. Requests to malicious or restricted domains can be blocked before the connection is established.

Protective DNS can help prevent connections to malware infrastructure, phishing sites, command-and-control servers, botnets, deceptive domains and other known or suspicious destinations.

Yes. Total Uptime supports roaming protection across Windows, Mac, iOS, Android and ChromeOS so policies can continue to protect users outside the corporate network.

No. Protective DNS operates at the DNS layer and prevents connections to dangerous destinations before they are resolved. It complements firewalls, WAF, endpoint security and other security controls rather than replacing them.

Protective DNS is designed to evaluate DNS requests while maintaining fast DNS resolution and is delivered using Total Uptime’s global infrastructure.

Yes. Organizations can apply different filtering and security policies across networks, locations or groups.

Yes. Protective DNS provides activity reporting, security threat reporting and query logging to help teams understand DNS activity and investigate potential threats.

Total Uptime Protective DNS is built to meet the capabilities outlined in NSA and CISA’s Selecting a Protective DNS Service guidance.

Stop threats before they become connections.

See how Total Uptime Protective DNS can protect your users, networks and distributed environments without adding unnecessary complexity.