Your laptops spend more time on home and hotel Wi-Fi than on the office LAN. The DNS filter should go with them — Heimdal DNS Security – Endpoint runs a DNS server on every Windows and Mac device, so each lookup is checked before a site loads, in the office or on hotel Wi-Fi — by domain only, and only for DNS the operating system generates.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Heimdal DNS Security – Endpoint — the agent-side DNS filter, formerly Threat Prevention – Endpoint. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A resolver on the device checks each domain before a connection opens, so a malicious site never resolves, on any network.
What consolidation actually replaces, dimension by dimension.
| Dimension | An office resolver and a firewall blocklist | Heimdal DNS Security – Endpoint |
|---|---|---|
| Coverage away from the office | Ends when the laptop leaves the LAN | The agent filters on any network it joins |
| Who made the bad lookup | A device IP in a resolver log | The executable, named by TTPC |
| Browsers using their own DoH | Invisible to the office resolver | Chrome and Firefox held on the filter |
| Block-list freshness | Whenever someone edits the firewall rule | Updates every two hours, ~800,000 entries a week |
| Which apps staff use | Guesswork from firewall logs | Apps seen in DNS, blockable by domain |
| What it is NOT | — | A web proxy, TLS inspection, a CASB or a Linux agent |
The cheapest test is the free trial on ten laptops that travel: turn on DoH Compatibility Mode and read a week of blocks.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
The agent runs a DNS server on the device and points the network adapter at 127.7.7.x for IPv4 or fe80:: for IPv6, keeping the original resolvers for internal names.
A local database of about 15 MB answers first, and Heimdal says 95% of the sites it blocks are found there; anything it misses is checked against a cloud set of roughly 6 GB.
VectorN Detection reads traffic patterns for signs of attack, and Threat to Process Correlation names the executable behind a lookup, drawing on Sysmon event 22 on Windows.
Block lists, categories, allow entries and the list of apps seen in DNS are managed in the cloud dashboard, and each customer picks an EU, US or UK region for its data.
A resolver inside each Windows or Mac endpoint — local list first, Heimdal’s cloud second, data in Europe, the US or the UK.
Heimdal DNS Security – Endpoint filters every lookup on the device itself, so the policy travels with the laptop.
DarkLayer Guard answers lookups on the endpoint itself, so the same policy follows a laptop onto home, hotel or mobile networks.
The threat database absorbs around 800,000 new entries a week, delivered to agents in updates that land every two hours.
Heimdal credits Predictive DNS with 96% accuracy in forecasting malicious domains; that is the vendor’s number, not a lab result.
Threat to Process Correlation links a blocked domain to the executable that requested it, using Sysmon event 22 on Windows.
VectorN Detection adds host-intrusion signals by spotting indicators of attack in a device’s traffic, on Windows and on macOS.
An optional HEIMDAL Block Page Certificate lets the block notice render on HTTPS sites; it exists for display and decrypts nothing.
DoH Compatibility Mode stops Chrome and Firefox sending lookups to their own encrypted resolvers, so both still pass the agent.
A DNS-over-HTTPS server setting encrypts the agent’s upstream queries, applying only while a device is outside the corporate network.
Apps spotted in lookups appear in a view Heimdal names CASB and can be blocked by domain; there is no proxy and no SaaS API behind it.
A console demo of DNS Security, a five-minute primer on DNS filtering, and Heimdal’s explainer on DNS as an attack path. All from Heimdal’s official channel, 2024–2025.
A walk through the DNS Security console: policies, categories and what an administrator sees when a lookup is blocked.
Heimdal’s short primer on how filtering at name resolution stops a connection before it starts.
Background on why DNS is an attack path and what a protective DNS layer is expected to catch.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
With the resolver on the device, one block list applies on office Wi-Fi, at home and on a phone hotspot, with no VPN back to head office. Off the network, a DNS-over-HTTPS setting encrypts the upstream query, and macOS agent 3.5.9 (a release candidate) filters before sign-in.
A resolver log tells you a laptop asked for a bad domain. Threat to Process Correlation adds which executable asked, from Sysmon event 22 on Windows, and VectorN Detection flags odd traffic patterns, shortening the path from alert to the file someone must remove.
It is its own line item and can be bought alone, yet it shares one agent and dashboard with Heimdal’s antivirus, patching and privilege modules. Its integration list names ConnectWise RMM, HaloPSA, Autotask PSA, Meraki and Palo Alto, and a REST API exists too.
By Heimdal’s own account it intercepts system-generated DNS only, so apps with a built-in resolver and VPNs without split tunnelling go round it. No Linux agent, no TLS inspection, no co-existence with Umbrella-style tools, no Indian resolver or region, no stated log retention.
List VPN clients, browsers and apps with their own resolvers, plus any Umbrella-style agent that must come off before install.
Install the agent on a dozen Windows and Mac machines that roam, with DoH Compatibility Mode switched on from the start.
Review blocks on business sites, add allow entries, and confirm the block page renders on HTTPS once its certificate is out.
Follow a blocked lookup back to the executable with TTPC, and agree who removes the file and within what time.
Push the agent across the estate, then schedule CSV or API exports so 180 days of DNS records sit in your SIEM.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our field sales team works off client and hotel Wi-Fi all week. The agent blocks the same domains there as in the office.”
“TTPC showed the blocked callback came from a PDF tool nobody had approved, which spared us a full reimage of the laptop.”
“Switch on DoH compatibility mode on day one. Until we did, Chrome was quietly resolving around the filter on half our machines.”
“Our always-on VPN had no split tunnel, so lookups skipped the agent until the network team rebuilt the client profile.”
“Mac support decided it. Our design studio runs on MacBooks and the other agent we trialled only covered Windows.”
“We had to pull Umbrella off every laptop first, because the two DNS agents refuse to share a machine. Budget for that cutover.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint DNS filtering market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quoted per device per year; Windows and macOS agent.
The grid nobody publishes — how many device platforms keep filtering away from the office vs how hard the filter is to route around with encrypted DNS or a private resolver.
Windows and macOS; browser DoH held, system DNS only.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Cisco Umbrella, Infoblox Threat Defense, OpenText Core DNS Protection, N-able DNS Filtering and Cloudflare One Gateway — on agents, inspection depth, encrypted-DNS bypass, price, logs, India and exit.
| Dimension | Heimdal DNS Security – Endpoint | Cisco Umbrella | Infoblox Threat Defense | OpenText Core DNS Protection | N-able DNS Filtering | Cloudflare One Gateway |
|---|---|---|---|---|---|---|
| What it is | On-device DNS filter | DNS tiers, SIG above | Protective DNS, 4 tiers | Webroot lineage | DNSFilter inside | Policy engine of a SASE |
| Deployment and agents | Windows + macOS agent | Resolvers + roaming app | Seven-OS endpoint agent | Windows agent + forwards | Relays + Win/Mac agents | Locations or WARP |
| Layer, TLS and CASB | Domains; CASB in name | Selective proxy at SIG | DNS layer only | Domains, no decryption | Lookup verdicts only | TLS decryption, CASB |
| Encrypted DNS bypass | Chrome/Firefox DoH held | DoH category, gaps | Public_DoH feeds | Closes 53, 443, 853 | DoT; browser DoH partly | DoH, DoT per location |
| Scale and blind spots | System DNS only | Large estates verified | 17,000-staff customer | SMB and MSP focus | 500k sync, as claimed | 330+ cities, no user cap |
| Pricing model | Per device, per year | Per user, four tiers | 3 tokens per asset | Per site, keycode | Quoted, unit unstated | Per user, monthly |
| Published entry price | Not published | ~$2.25/user/month | Quote only | Not published | Not published | Free to 50, then $7 |
| Included vs add-on | One module of a suite | Proxy costs a tier up | Extras draw tokens | Every feature included | Pro features only | DNS free, depth extra |
| Logs and retention | Retention unpublished | Export to S3 | 60 days in the viewer | 13-month categories | 9-day query logs | 24 h free, 30 d paid |
| Integrations and admin | RMM, PSA, REST API | Meraki and SD-WAN | NIOS and forwarders | MSP console, Unity API | N-central, SSO, sync | Shared Zero Trust panel |
| India resolver and data | No India region | Mumbai and Chennai | Indian resolvers only | Not documented | No Indian city | Six Indian cities |
| Support and trial | Free trial, Mumbai desk | Free trial | Detection Mode pilot | 30-day trial | Trial, length unstated | Free tier, SLA on paid |
| Lock-in and exit | Agent tied to platform | Change the resolvers | Easy unless on NIOS | Agent hands DNS back | Linked to N-able RMM | No annual term |
| Best fit | Roaming Win/Mac fleets | DNS first, proxy later | Infoblox DDI shops | Windows MSP clients | N-able MSP customers | Price-led, Indian PoPs |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Heimdal DNS Security – Endpoint is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (devices protected; IT-hour cost). Estimates model IT time lost to cleaning up malware infections and phishing clicks that started with a bad domain, at an assumed 1.5 hours per device a year, with 70% of it avoided when those domains never resolve. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Heimdal publishes no prices: its pricing calculator lists DNS Security – Endpoint as a separate line item, counted per device per year, and shows no figures. A free trial is offered. The agent it installs can also carry Heimdal’s antivirus, patching and privilege modules, each priced as its own line, and DNS Security – Network for agentless office coverage is another. TechBag counts your devices and the modules you actually need, then quotes in INR with GST.
Best for laptops that roam off the network
Best for a broader rollout
Best for printers, IoT and guests in the office
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Do all machines run a supported Windows desktop or server release, or a Mac on 10.15 or newer? Linux and phones need another control.
Does your VPN client support split tunnelling or split exclusion? Without it, lookups travel round the agent.
Is Cisco Umbrella or a similar DNS agent installed? Heimdal says DarkLayer Guard cannot work beside one.
Which apps carry their own resolver or DoH? Only system-generated DNS is filtered, so list them before the pilot.
Will DoH Compatibility Mode be enforced for Chrome and Firefox, and how will any other browser in use be handled?
Can your DPDP and sector rules live with an EU, US or UK data region? Heimdal offers no Indian one.
How will DNS records reach CERT-In’s 180 days? Heimdal states no retention, so plan CSV or API exports.
Is the quote per device per year, and which other Heimdal modules share the agent? Ask for INR with GST.
Count the laptops and servers that need filtering first, or let a TechBag advisor map your VPN and browser bypass routes and run a roaming-laptop pilot.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.