Protect users from phishing, malware, ransomware and other dangerous destinations by blocking threats at the DNS layer, before a connection is made. Total Uptime Protective DNS provides always-on protection across corporate networks and roaming users, with real-time threat detection, centralized policy control and visibility into DNS activity.
No endpoint agent required
Protection for on-network and roaming users
Built to meet NSA/CISA Protective DNS guidance
Before a user visits a website, opens a cloud application or connects to an online service, their device typically makes a DNS request to find its destination.
That creates an opportunity to stop threats before the connection is ever established.
Total Uptime Protective DNS evaluates DNS requests and blocks access to known and emerging malicious destinations, helping prevent users and devices from connecting to phishing sites, malware infrastructure, botnets and command-and-control servers.
User → DNS request → Total Uptime Protective DNS → Destination allowed
Legitimate requests resolve normally, with policies applied automatically.
User → DNS request → Total Uptime Protective DNS → Threat blocked
Connections to malicious or restricted destinations are stopped before the user reaches them.
DNS protection shouldn’t disappear when someone leaves the office.
Total Uptime Protective DNS extends security beyond the corporate network, helping protect users whether they are working from an office, home, branch location or on the move.
Prevent connections to malicious domains before malware, phishing or command-and-control traffic reaches its destination.
Apply Protective DNS policies to users working beyond the corporate network across Windows, Mac, iOS, Android and ChromeOS.
Use machine-learning analysis to identify suspicious, newly registered and generated domains rather than relying solely on static threat lists.
See DNS requests, blocked threats, activity patterns and destinations through centralized reporting and query logging.
Attackers continually create new domains and infrastructure to evade traditional security controls.
Protective DNS therefore needs to identify more than threats that are already known.
Total Uptime combines threat intelligence, real-time analysis and DNS-layer policy enforcement to help identify and block both known and emerging threats.
Protective DNS isn’t only about blocking malicious websites. It also gives IT and security teams centralized control over how DNS is used throughout the organization.
Block malicious domains and suspicious destinations before connections are established.
Create policies controlling the types of online content users or networks can access.
Apply SafeSearch and restricted-mode policies across supported search and content platforms.
Apply different DNS policies to different locations, networks or user groups.
Understand what users and devices are requesting, what has been blocked and where potential threats are occurring.
Integrate DNS policies and management into existing operational and security workflows.
You shouldn’t have to take our word for what a capable Protective DNS service should provide.
NSA and CISA’s Selecting a Protective DNS Service guidance defines the capabilities organizations should consider when evaluating Protective DNS providers.
Total Uptime Protective DNS is built to meet the full set of capabilities outlined in that guidance, including malicious-domain blocking, phishing protection, DNS tunneling detection, protection against newly registered and generated domains, content filtering, roaming protection, query logging, reporting and automation.
Users no longer work from a single office or network.
Total Uptime Protective DNS can extend security policies to roaming users, helping protect employees whether they are working from the office, home, another location or while traveling.
Roaming protection is available across major desktop and mobile platforms, including:
Windows
macOS
iOS
Android
ChromeOS
Security policies remain centrally managed, giving your organization consistent DNS protection across distributed users and devices.
Organizations affected by changes to MS-ISAC’s MDBR service can maintain Protective DNS coverage without simply accepting a new cost or reducing protection.
Compare your existing MDBR coverage with Total Uptime Protective DNS, including roaming-user protection, threat detection, filtering and reporting.
Protective DNS provides a direct way to implement DNS filtering across corporate and roaming users while providing the policy and logging evidence security teams need.
Total Uptime Protective DNS supports organizations addressing CMMC DNS filtering requirements, with a FedRAMP-aligned deployment option available for applicable government-facing environments.
Protect students, faculty and staff from malicious destinations while applying content filtering, SafeSearch and separate policies across different networks and user groups.
Protect users across offices, branches, remote locations and roaming devices while centralizing DNS security policy and visibility.
Adding another security control shouldn’t create another operational burden.
Total Uptime Protective DNS is cloud-delivered and designed to provide broad protection without disrupting the user experience.
Introduce DNS-layer protection without redesigning your application or network architecture.
Protect network DNS traffic without installing another traditional security agent across every endpoint.
Support networks and roaming users across multiple locations and platforms.
Manage policies, filtering, reporting and DNS activity from one service.
Protective DNS helps stop users and systems from connecting to dangerous destinations, but keeping applications available requires more than one security control. Total Uptime brings application delivery capabilities together across cloud, on-premises and hybrid environments.
Load Balancing | ADC | GSLB | Kubernetes Ingress
Protective DNS | WAF | WAAP
Multi-Cloud Networking | BGP over GRE | Hybrid Connectivity
Monitoring | Reporting | Traffic Visibility
Quick answers to the questions infrastructure teams ask most.
Protective DNS is a security service that evaluates DNS requests before allowing users or devices to connect to internet destinations. Requests to malicious or restricted domains can be blocked before the connection is established.
Protective DNS can help prevent connections to malware infrastructure, phishing sites, command-and-control servers, botnets, deceptive domains and other known or suspicious destinations.
Yes. Total Uptime supports roaming protection across Windows, Mac, iOS, Android and ChromeOS so policies can continue to protect users outside the corporate network.
No. Protective DNS operates at the DNS layer and prevents connections to dangerous destinations before they are resolved. It complements firewalls, WAF, endpoint security and other security controls rather than replacing them.
Protective DNS is designed to evaluate DNS requests while maintaining fast DNS resolution and is delivered using Total Uptime’s global infrastructure.
Yes. Organizations can apply different filtering and security policies across networks, locations or groups.
Yes. Protective DNS provides activity reporting, security threat reporting and query logging to help teams understand DNS activity and investigate potential threats.
Total Uptime Protective DNS is built to meet the capabilities outlined in NSA and CISA’s Selecting a Protective DNS Service guidance.
See how Total Uptime Protective DNS can protect your users, networks and distributed environments without adding unnecessary complexity.