Phishing and malware nearly always need a DNS lookup first. A blocked domain should never resolve — DNSFilter checks every DNS lookup from your offices and roaming devices against threat and content policy, and blocked domains never resolve — from $1.00 a licence a month, with laptops covered on Plus.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers DNSFilter — the protective-DNS service in its Core, Plus and Enterprise plans, with DNS PreCheck, CyberSight, Data Export and SecureTransit folded in.
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Every connection starts with a DNS lookup; a protective resolver refuses to answer for malicious or banned domains.
What consolidation actually replaces, dimension by dimension.
| Dimension | The ISP’s resolver and unfiltered laptops | DNSFilter |
|---|---|---|
| Where a bad domain is stopped | After the connection, if the endpoint agent notices | At the lookup, before any connection opens |
| Laptops outside the office | Unfiltered at home and on public Wi-Fi | Roaming Client on Plus, across five platforms |
| Rules for one subnet | Separate firewall lists per VLAN | A DNS Relay applying a policy per subnet |
| Budgeting the service | A quote after a sales cycle | $1.00 or $2.25 a licence, printed online |
| A log for the auditor | Firewall logs nobody kept | 9 days in the dashboard; 180 via Data Export |
| What it is NOT | — | A web proxy, TLS inspection, a CASB or an Indian resolver |
The cheapest test is the 14-day trial: point one office at the resolvers, add Plus clients to a few laptops, and read what got blocked.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Networks send lookups to anycast addresses such as 103.247.36.36 and 103.247.37.37; DNSFilter documents 200+ anycast servers in 80+ data centres and routes to the nearest.
A local forwarding resolver, shipped as a Docker image, a binary or a VM, applies a separate policy per LAN subnet and still resolves your internal domain names.
Agents for Windows, macOS, iOS, Android and Chrome keep policy on laptops and phones on any network, sending lookups to DNSFilter over DNS over TLS.
Windows Roaming Client 3.0 or later can filter locally through a transparent proxy, leaving DNS settings alone; it fails open by default, while Classic mode fails closed.
Sites and relays forward to anycast resolvers — roaming clients and Windows PreCheck carry the same policy off-network.
DNSFilter refuses to resolve malicious and banned domains, so the connection never starts.
Malicious Domain Protection, a policy setting, flags zero-day domains an average of 10 days ahead of traditional feeds, DNSFilter says.
Block gambling, adult or any other class of site by policy; DNSFilter cites about 40 categories, sorted by its Webshrinker engine.
AppAware blocks more than 400 SaaS applications by the domains they use, so a file-sharing or chat app can be refused at the lookup.
Point a router, DHCP scope or firewall at the anycast resolvers and every device on that network is filtered, on Core and above.
From Plus upwards, agents for Windows, macOS, iOS, Android and Chrome carry the same policy to devices at home or on mobile data.
On Plus and Enterprise, Microsoft Entra or Active Directory lets policies and reports attach to a named user, not only a site.
Insights reports cover 90 days of allowed and blocked traffic, while the raw query log behind them is kept for 9 days on every plan.
On Windows clients, CyberSight records URLs, app use, device state and logins, with an AI usage report, kept for up to one year.
For $0.25 a licence a month, logs stream to Splunk, Microsoft Sentinel, IBM QRadar or Amazon S3, where you set the retention.
A first setup walkthrough, the Roaming Client, a 90-second demo recorded in 2022 on the old interface, and AppAware. All from DNSFilter’s official channel, 2022–2025.
A first setup from sign-up to a working policy, on the current dashboard.
How the Roaming Client keeps a laptop filtered once it leaves the office network; a Plus-plan feature.
A quick tour, recorded in 2022 on the old interface and before the plans were renamed Core, Plus and Enterprise.
Blocking whole SaaS applications by their domains rather than one site at a time; from 2022.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Core is $1.00 a licence a month billed yearly and Plus is $2.25, both bought online after a 14-day trial with every generally available feature on. That is the lowest published entry price in TechBag’s Secure Web & DNS guide, where most rivals either quote or charge per user.
On Plus, roaming clients cover Windows, macOS, iOS, Android and Chrome, so a laptop on hotel Wi-Fi keeps the office’s rules. Windows can also run DNS PreCheck, filtering on the device itself, and the $2.00 SecureTransit add-on tunnels Windows traffic, though it is not a full VPN.
CyberSight, which came with the Zorus acquisition in April 2025, records URLs, application use and logins from Windows clients and adds an AI usage report, held for up to a year. Insights reports span 90 days, and the Data Export add-on hands everything to Splunk, Sentinel, QRadar or S3.
It judges domains only: no proxy, TLS inspection or CASB. Core has no roaming client. Raw query logs last 9 days, so CERT-In’s 180 days means paying for Data Export. Only Firefox’s DoH is switched off automatically. No Indian resolver city is named, and GigaOm rated it a Challenger, not a Leader.
List roaming devices, then estimate each office’s daily queries in 10,000s; that sum, not headcount, is the licence total.
Start the 14-day trial, point one office’s DNS at the resolvers, and put Plus roaming clients on a handful of laptops.
Block known DoH providers at the firewall, force port 53 to the resolvers, and check Chrome and Edge are now filtered.
Choose Core for sites only or Plus for roaming, sync Entra ID for per-user policy, and push agents to every device.
Turn on Data Export to your SIEM or S3 for 180 days of history, then review Insights and CyberSight with each team.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We pointed the office firewall at DNSFilter before lunch, and by evening the phishing domains on our test list would not resolve.”
“Core looked cheap until we saw it has no roaming client. Our field laptops needed Plus, so budget at $2.25, not $1.”
“The relay gave our lab subnet a stricter policy than staff Wi-Fi, and internal hostnames still resolved without any tricks.”
“Nine days of query history did not satisfy our auditors. We bought Data Export and now keep 180 days in Sentinel.”
“Chrome kept using its own encrypted DNS until we blocked DoH providers on the firewall; Firefox fell in line by itself.”
“CyberSight’s AI usage report showed us which teams were pasting work into chatbots, at least on our Windows machines.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the protective DNS market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Core $1.00 and Plus $2.25 a licence a month, billed yearly.
The grid nobody publishes — how openly a product prints its price and lets you start vs how many places and devices it can enforce DNS policy.
Printed rates; networks, relays, five client platforms, PreCheck.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Cisco Umbrella, Cloudflare One Gateway, Infoblox Threat Defense, OpenText Core DNS Protection and N-able DNS Filtering (the same engine under N-able’s contract) — on licence unit, price, roaming, inspection depth, encrypted-DNS bypass, logs and India.
| Dimension | DNSFilter | Cisco Umbrella | Cloudflare One Gateway | Infoblox Threat Defense | OpenText Core DNS Protection | N-able DNS Filtering |
|---|---|---|---|---|---|---|
| What it is | Protective DNS, 3 plans | DNS layer, SIG on top | Filter of a SASE suite | DDI vendor’s DNS shield | Ex-Webroot DNS filter | DNSFilter engine, resold |
| Deployment and roaming | Network, relay, 5 agents | DNS change + client | Locations and WARP | Proxy, NIOS or agent | Windows agent + sites | Sites, relay, Win + Mac |
| Pricing model | Per licence, monthly | Per user, four tiers | Per user, published | Security Tokens | Keycode, unit unstated | Quote, unit unstated |
| Published entry price | $1.00/licence/month | ~$30–40/user/year | Free to 50, then $7 | Quote only | Not published | Not published |
| Included vs add-on | Roaming starts at Plus | Proxy needs SIG tier | Three filters in plan | Extras spend tokens | Every feature in policy | Former Pro feature set |
| Scale and network | 80+ data centres | Verified past 5,000 | Verified past 5,000 | 17,000-staff customer | Not verified at scale | 500k-user sync claim |
| Inspection depth | Domains only | Selective proxy at SIG | Full TLS, inline CASB | DNS only, deep intel | DNS only, 78 categories | Same domain-only engine |
| Encrypted DNS bypass | Firefox only, by itself | DoH/DoT category | DoH/DoT per location | Public DoH feeds | Agent blocks 53/443/853 | As DNSFilter: firewall |
| Integrations | API, PSA, SIEM, MCP | Cisco and Meraki gear | Cloudflare One stack | NIOS DDI, S3 or SIEM | RMM, PSA, Unity API | N-central and N-sight |
| Governance and logs | SSO, MFA; 9-day log | S3 export, default n/a | 24 h free, 30 days paid | 60 days in the viewer | 13-month category data | Same 9-day log |
| India resolver | No Indian city named | Mumbai and Chennai | Six Indian cities | Resolvers in, portal out | Not documented | Not documented |
| Support and trial | 14-day full trial | Free trial, partners | Free plan, no limit | Detection Mode pilot | 30-day console trial | Trial, length unstated |
| Lock-in and exit | Repoint, then uninstall | Easy on DNS tiers | Harder once HTTP is on | Cloud easy, NIOS sticky | Agent stop restores DNS | Bound to N-able tools |
| Best fit | Price-led SMBs, schools | DNS first, proxy later | Inspection at list price | Infoblox DDI shops | MSP Windows fleets | N-able RMM customers |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
DNSFilter is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (devices protected; IT staff-hour cost). Estimates model IT time lost to cleaning up after malware infections and phishing clicks, plus handling site-blocking requests, at an assumed 1.5 hours per device a year, with 70% of it saved once bad domains stop resolving. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Published: Core is $1.00 a licence a month billed yearly ($1.15 monthly) with a $240 yearly minimum, for network and relay deployments only; Plus is $2.25 ($2.50 monthly) with a $750 minimum and adds roaming clients, DNS PreCheck, CyberSight and per-user policy. A licence is one roaming device or 10,000 network DNS queries a day, never a user. Enterprise and Education are quoted, MSP pricing starts at $150 a month, Data Export is $0.25 and SecureTransit $2.00 a licence a month. No INR price is published. TechBag counts your devices and daily queries first, then quotes in INR with GST.
Best for offices filtered at the network
Best for a broader rollout
Best for laptops and phones that roam
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
How many roaming devices, and how many 10,000-query blocks a day per office? Licences are not counted per user.
Do any devices leave the office? Core has no roaming client, so laptops and phones push you to Plus at $2.25.
Are clients at supported versions: Windows 10+ with .NET 4.8, macOS 13+, iOS 18+, Android 13+, ChromeOS extension 3.0+?
Can your firewall block DoH providers and force port 53? Without it, browsers other than Firefox can bypass the filter.
Where will 180 days of logs live for CERT-In? The 9-day query log needs Data Export to a SIEM or S3.
On Windows, should a PreCheck failure fail open, its default, or would you rather use Classic mode, which fails closed?
Have you timed lookups from each Indian office? DNSFilter names no Indian resolver city, so measure before rollout.
Does the quote state the licence count, plan, add-ons and term? Ask TechBag for INR with GST and agent EOL terms.
Count your roaming devices and daily network queries first, or let a TechBag advisor run the 14-day trial on one office, close the DoH gap and plan 180-day log retention.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.