Call if something looks wrong now. Or book a free IT review. No pressure, no jargon.
DNS filtering: stop a bad click before the page even loads
Someone will click the wrong link. The question is what happens next.
Most attacks need your computer to reach a bad website: a fake sign-in page, a booby-trapped download, a server that hands out instructions to malware. DNS filtering blocks known bad sites at the moment a computer looks them up. It’s quiet, fast and one of the cheapest layers you can add.
What is DNS filtering?
DNS is the internet’s phone book. Before a computer opens a website, it asks a DNS server for that site’s address. DNS filtering checks each request against lists of known malicious, phishing and unwanted domains. If the domain is known bad, the lookup is refused or sent to a block page, so the connection never starts.
Why it matters
If you own the business
- One click shouldn’t cost a week. If the fake invoice link goes to a known bad site, the page doesn’t open.
- It costs little and works everywhere. It protects every device that uses it, without slowing anyone down.
- It’s one layer of several. Insurers commonly ask what protection is in place, and filtering is part of a good answer.
If you run the office
- Fewer “I clicked something” calls. Many bad links just show a block page.
- Less blame on the team. Staff are people, and people click. A filter catches some of what training misses.
- Simple rules, no surprises. We agree what gets blocked, and staff can ask us to review a site that was blocked by mistake.
How DNS filtering works
It happens in a fraction of a second, before the page loads.
- Someone clicks a link or an app tries to reach a domain.
- The computer asks the DNS filtering service for the address.
- The service checks the domain against threat intelligence: malware, phishing, command-and-control servers, and newly registered domains if we choose to block them.
- Safe domains resolve normally. Known bad ones are blocked, and the attempt is logged.
What DNS filtering doesn’t do
It’s a strong first layer, not the whole wall.
- It doesn’t replace protection on each computer. Malware that arrives on a USB stick, or on a site not yet known to be bad, needs endpoint protection and monitoring. We provide 24/7 monitoring, with Huntress, a separate security team, alongside us.
- It doesn’t read the page. It decides by domain name. A bad page on a trusted, shared site can get through.
- It can be bypassed if a device uses a different DNS server or encrypted DNS in the browser. We set the firewall and devices so lookups go through the filter.
- It doesn’t stop a stolen password. That’s the job of multi-factor sign in.
How we set it up
- DNS security from Cisco, or an equivalent service if price is a concern. We’re technology agnostic.
- Applied at the office network through the firewall, and on every laptop that leaves the office, through a small roaming agent.
- Security categories blocked by default: malware, phishing and command-and-control.
- Content categories only if you want them, such as gambling or adult sites. Your office, your rules.
- Other DNS routes closed at the firewall, so devices can’t quietly skip the filter.
- Reviewed with the rest of your security, alongside your business firewall and monitoring.
Common mistakes we see
- Filtering only in the office, so laptops at home or on hotel Wi-Fi go unprotected.
- Leaving other DNS servers reachable, so the filter is easy to skip.
- Treating it as antivirus. It isn’t.
- Blocking so much that staff work around it. Keep the security categories strict and the rest sensible.
- Nobody looking at the logs. Repeated blocks from one computer can be an early warning.
DNS filtering questions
Is DNS filtering the same as antivirus?
No. DNS filtering blocks known bad domains at lookup time. Antivirus and endpoint protection look at what is running on the computer. You want both.
Will it slow down our internet?
Not noticeably. It’s a lookup that happens anyway. It just goes to a smarter phone book.
What if it blocks a site we need?
Call or message us. We check the site and allow it if it’s safe.
Does it work on laptops away from the office?
Yes. A small roaming agent on each laptop keeps the filter on at home, on hotel Wi-Fi and anywhere else. Back at the office, the firewall blocks other DNS routes, so devices can’t skip it.
Can you see what websites my staff visit?
DNS filtering logs the domains looked up, not the content of pages. We use the logs for security. How you use them for staff policy is your decision, and it’s worth checking privacy rules first. This isn’t legal advice.
