For State, Local, Tribal & Territorial Government

Lost your free MDBR Protective DNS? Replace it with something better.

When MS-ISAC moved to a paid model, thousands of SLTT teams were left exposed or facing a surprise bill. Total Uptime Protective DNS meets all 11 NSA/CISA capabilities, protects your roaming staff, and our team sets it up with you.

Three choices after the MS-ISAC change. Only one is actually safe

CISA’s cooperative agreement with the Center for Internet Security ended on 30 September 2025. MDBR, the free Protective DNS that supported 7,000+ SLTT entities, moved to fee-based membership, and federal grant dollars generally can’t be used to pay for it.

Risky

Go without Protective DNS

Removes your cheapest, broadest layer of defense. Nearly every attack, ransomware, phishing, data theft, relies on a domain lookup. Drop DNS protection and you re-open all of it.

Costly

Pay for the same thing you had

Absorb a new, unbudgeted cost for a like-for-like service, without re-evaluating whether it still covers roaming users, new domains, and the full NSA/CISA standard.

Recommended

Upgrade to better-value PDNS

If you’re funding Protective DNS for the first time, fund one that meets all 11 NSA/CISA capabilities, follows users off-network, and comes with hands-on setup. That’s Total Uptime.

0 %

of malware command-and-control can be disrupted by secure DNS (NSA estimate)

0 M+

deceptive sites blocked across our network every single day

0 / 11

NSA/CISA Protective DNS capabilities met — the full standard

The federal government already wrote your evaluation criteria

NSA and CISA’s “Selecting a Protective DNS Service” (v1.3, March 2025) defines 11 capabilities a credible provider should deliver. Use it to compare any vendor. Total Uptime meets all of them.

Block malware & C2 domains

Stops connections to known-malicious and command-and-control infrastructure.

Block phishing domains

Prevents users reaching credential-harvesting and spear-phishing sites.

Detect DNS tunneling & exfiltration

Identifies data being smuggled out over DNS.

Catch newly-registered & DGA domains

Machine-learning analysis of unknown domains in real time.

Block malvertising & drive-by sites

Filters domains serving malicious ads and payloads.

Content & category filtering

Per-network policy control across dozens of categories.

Enforce SafeSearch

Google, Bing, DuckDuckGo and YouTube restricted modes.

Roaming / off-network protection

Windows, Mac, iOS, Android and ChromeOS clients.

Comprehensive query logging

Real-time logs for investigation and reporting.

Scale without slowing users down

From 10 to 100,000+ users with anycast performance.

Actionable reporting & visibility

Threat, activity and top-destination dashboards.

API & automation

Manage policies programmatically and integrate with your stack.

The reason MDBR worked was that it was simple.So is this.

Most county, city, district and tribal IT teams are stretched thin. Any replacement has to be effortless to run,  and get you covered fast.

Get your MDBR replacement plan

A 20-minute walkthrough plus a like-for-like comparison against your current MS-ISAC/MDBR costs at no obligation.

$

/mo · scaled to your entity size

Transparent, entity-sized pricing. We’ll show you exactly how it compares.

Customer success

Trusted by IT Teams Worldwide

Real organisations. Real resilience. Real results.

Rated by the people who use us.

MDBR replacement, answered

Can we use federal grant dollars to pay for this?

Agencies are generally prohibited from using federal cyber-grant dollars to pay for MS-ISAC membership specifically. Rules vary by grant program and for commercial services, we’ll help you understand the options, but always confirm eligibility with your grant administrator.

Some states (for example, Texas, covering 6,000+ entities) have centralized membership. If yours has, you may already be covered for MDBR, though many teams still evaluate Total Uptime for broader capabilities like roaming coverage and real-time detection. If your state hasn’t, the gap is on you today.

Because there’s no endpoint agent and no change to the user experience, most organizations are live within days. Our team runs the configuration with you.

MDBR delivered core malicious-domain blocking. Total Uptime meets all 11 NSA/CISA capabilities, adds machine-learning detection of brand-new domains (rather than waiting on static lists), roaming protection across every major platform, content filtering and full reporting, from a single service.

Don't let the funding change become a coverage gap

Get a straight, itemized comparison against your MS-ISAC/MDBR costs and see the full 11-capability match, in 20 minutes.