Talk to us
by HeimdalTechBag Intel Page

Heimdal DNS Security – Endpoint

Your laptops spend more time on home and hotel Wi-Fi than on the office LAN. The DNS filter should go with them — Heimdal DNS Security – Endpoint runs a DNS server on every Windows and Mac device, so each lookup is checked before a site loads, in the office or on hotel Wi-Fi — by domain only, and only for DNS the operating system generates.

A DNS filter that lives on the deviceWindows and macOS, on any networkQuote, per device per year

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Heimdal’s calculator lists the module per device per year but shows no figures
Quote
Agents
Workstations and servers on Windows, Macs from 10.15; Linux and phones are not covered
Windows + macOS
Analysts
No Gartner Magic Quadrant includes Heimdal; the 4.8/5 it cites is a user rating on Gartner Peer Insights
No MQ
India
Customer data goes to an EU, US or UK region, and Heimdal’s documents name no Indian resolver city
No local region

Quick answer

Heimdal DNS Security – Endpoint puts a small DNS server on each Windows or macOS device, so each lookup the operating system makes is checked against Heimdal’s threat lists before a site loads, at the office or on hotel Wi-Fi. It judges domains only: no TLS inspection, no proxy, and apps with their own resolver slip past. Pricing is a per-device annual quote; customer records go to a European, American or British region, with no Indian option. Read more ↓ Show less ↑
Part 01 · Orient

The Heimdal platform family

This page covers Heimdal DNS Security – Endpoint — the agent-side DNS filter, formerly Threat Prevention – Endpoint. The rest:

Quick facts

30-second orientation
Product
An agent-side DNS filter that runs a resolver on each laptop or server and vets every system lookup
Maker
A Danish company founded in Copenhagen in 2014, which Marlin Equity Partners acquired in March 2020; CEO Jesper Frederiksen
Formerly
Sold as Threat Prevention – Endpoint; the filtering engine inside is called DarkLayer Guard
Price
Not published; quoted per device per year as its own line item, with a free trial
Platforms
Windows desktops (10, 11), Windows Server editions 2016–2025 and Macs on 10.15+; nothing for Linux
Layer
DNS only: the verdict rests on the domain name, with no proxy, URL-path check or TLS decryption
Encrypted DNS
DoH Compatibility Mode keeps Chrome and Firefox from switching to their own DoH resolvers
Blind spot
Only system-generated DNS is filtered; apps with a built-in resolver and full-tunnel VPNs go round it
India
Sales and support from Mumbai since 2023; customer data kept in an EU, US or UK region; no Indian resolver named
In India via
TechBag — roaming-laptop pilot, bypass review, quote in INR with GST, log-export plan
Part 02 · Learn

Understand endpoint DNS filtering before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is endpoint DNS filtering?

A resolver on the device checks each domain before a connection opens, so a malicious site never resolves, on any network.

An office resolver and a firewall blocklist vs Heimdal DNS Security – Endpoint — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionAn office resolver and a firewall blocklistHeimdal DNS Security – Endpoint
Coverage away from the officeEnds when the laptop leaves the LANThe agent filters on any network it joins
Who made the bad lookupA device IP in a resolver logThe executable, named by TTPC
Browsers using their own DoHInvisible to the office resolverChrome and Firefox held on the filter
Block-list freshnessWhenever someone edits the firewall ruleUpdates every two hours, ~800,000 entries a week
Which apps staff useGuesswork from firewall logsApps seen in DNS, blockable by domain
What it is NOT—A web proxy, TLS inspection, a CASB or a Linux agent

The cheapest test is the free trial on ten laptops that travel: turn on DoH Compatibility Mode and read a week of blocks.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where each lookup is caught

Agent

DarkLayer Guard local resolver

The agent runs a DNS server on the device and points the network adapter at 127.7.7.x for IPv4 or fe80:: for IPv6, keeping the original resolvers for internal names.

02
How a verdict is reached

Lookup

Local database, then the cloud

A local database of about 15 MB answers first, and Heimdal says 95% of the sites it blocks are found there; anything it misses is checked against a cloud set of roughly 6 GB.

03
Which program asked

Process

VectorN and Threat to Process Correlation

VectorN Detection reads traffic patterns for signs of attack, and Threat to Process Correlation names the executable behind a lookup, drawing on Sysmon event 22 on Windows.

04
Where policy and records live

Console

Heimdal Dashboard

Block lists, categories, allow entries and the list of apps seen in DNS are managed in the cloud dashboard, and each customer picks an EU, US or UK region for its data.

A resolver inside each Windows or Mac endpoint — local list first, Heimdal’s cloud second, data in Europe, the US or the UK.

Part 03 · Evaluate

Nine capabilities. Filter, trace, control.

Heimdal DNS Security – Endpoint filters every lookup on the device itself, so the policy travels with the laptop.

Filter
Local resolver

A DNS server on every device

DarkLayer Guard answers lookups on the endpoint itself, so the same policy follows a laptop onto home, hotel or mobile networks.

Filter
Updates

Fresh lists every two hours

The threat database absorbs around 800,000 new entries a week, delivered to agents in updates that land every two hours.

Filter
Predictive DNS

Verdicts on unseen domains

Heimdal credits Predictive DNS with 96% accuracy in forecasting malicious domains; that is the vendor’s number, not a lab result.

Trace
TTPC

The process behind the lookup

Threat to Process Correlation links a blocked domain to the executable that requested it, using Sysmon event 22 on Windows.

Trace
VectorN

Traffic patterns, not just names

VectorN Detection adds host-intrusion signals by spotting indicators of attack in a device’s traffic, on Windows and on macOS.

Trace
Block page

Users see why it stopped

An optional HEIMDAL Block Page Certificate lets the block notice render on HTTPS sites; it exists for display and decrypts nothing.

Control
DoH mode

Browsers held on the filter

DoH Compatibility Mode stops Chrome and Firefox sending lookups to their own encrypted resolvers, so both still pass the agent.

Control
Off-network DoH

Encrypted upstream when away

A DNS-over-HTTPS server setting encrypts the agent’s upstream queries, applying only while a device is outside the corporate network.

Control
App list

DNS-seen apps, labelled CASB

Apps spotted in lookups appear in a view Heimdal names CASB and can be blocked by domain; there is no proxy and no SaaS API behind it.

See it, don’t just read it

Watch Heimdal DNS Security – Endpoint in action

A console demo of DNS Security, a five-minute primer on DNS filtering, and Heimdal’s explainer on DNS as an attack path. All from Heimdal’s official channel, 2024–2025.

Heimdal (official)·Demo, March 2025

Heimdal DNS Security - Product Demo

A walk through the DNS Security console: policies, categories and what an administrator sees when a lookup is blocked.

Heimdal (official)·Explainer, September 2024

DNS Filtering Explained in Less than 5 Minutes

Heimdal’s short primer on how filtering at name resolution stops a connection before it starts.

Heimdal (official)·Explainer, January 2024

What Is DNS Security?

Background on why DNS is an attack path and what a protective DNS layer is expected to catch.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Heimdal DNS Security – Endpoint

Laptops leave the office every evening. Heimdal puts the DNS filter on the laptop.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Protection that leaves the building with the laptop

With the resolver on the device, one block list applies on office Wi-Fi, at home and on a phone hotspot, with no VPN back to head office. Off the network, a DNS-over-HTTPS setting encrypts the upstream query, and macOS agent 3.5.9 (a release candidate) filters before sign-in.

02

A block names the program, not only the machine

A resolver log tells you a laptop asked for a bad domain. Threat to Process Correlation adds which executable asked, from Sysmon event 22 on Windows, and VectorN Detection flags odd traffic patterns, shortening the path from alert to the file someone must remove.

03

One more module on an agent you may already run

It is its own line item and can be bought alone, yet it shares one agent and dashboard with Heimdal’s antivirus, patching and privilege modules. Its integration list names ConnectWise RMM, HaloPSA, Autotask PSA, Meraki and Palo Alto, and a REST API exists too.

04

Where it stops

By Heimdal’s own account it intercepts system-generated DNS only, so apps with a built-in resolver and VPNs without split tunnelling go round it. No Linux agent, no TLS inspection, no co-existence with Umbrella-style tools, no Indian resolver or region, no stated log retention.

The idea
A DNS filter that lives on the device
The reach
Windows and macOS, on any network
The price
Quote, per device per year
Proof, not promises

The numbers behind the platform

~15 MB
size of the on-device threat database that answers most lookups before the cloud is asked
— Vendor
95%
share of blocked sites Heimdal says are caught by that local copy alone
— Vendor
800K a week
new threat entries the filter takes in, shipped to agents in two-hourly updates
— Vendor
~6 GB
approximate size of the cloud database consulted when the local copy has no answer
— Vendor
96%
Heimdal’s claimed Predictive DNS accuracy; a vendor figure without an independent test
— Vendor claim
180 days
CERT-In’s log-keeping rule; with no stated DNS retention, plan an export to meet it
— CERT-In

What your Heimdal DNS Security – Endpoint rollout looks like

Week 1Plan

Map the bypass routes first

List VPN clients, browsers and apps with their own resolvers, plus any Umbrella-style agent that must come off before install.

Week 2Pilot

Pilot on travelling laptops

Install the agent on a dozen Windows and Mac machines that roam, with DoH Compatibility Mode switched on from the start.

Week 3Tune

Tune categories and exceptions

Review blocks on business sites, add allow entries, and confirm the block page renders on HTTPS once its certificate is out.

Month 2Prove

Trace a real block to its process

Follow a blocked lookup back to the executable with TTPC, and agree who removes the file and within what time.

Month 3Scale

Roll out and schedule exports

Push the agent across the estate, then schedule CSV or API exports so 180 days of DNS records sit in your SIEM.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.2
38+ reviews*
83% would recommend
Roaming protection4.4
Ease of rollout4.3
Threat blocking4.2
Reporting depth3.8
Value for money4.0
5★
46%
4★
34%
3★
13%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Pharmaceuticals
“Our field sales team works off client and hotel Wi-Fi all week. The agent blocks the same domains there as in the office.”
IT Manager
Pharmaceuticals
IT Services
“TTPC showed the blocked callback came from a PDF tool nobody had approved, which spared us a full reimage of the laptop.”
Security Analyst
IT Services
Education
“Switch on DoH compatibility mode on day one. Until we did, Chrome was quietly resolving around the filter on half our machines.”
Systems Administrator
Education
BFSI
“Our always-on VPN had no split tunnel, so lookups skipped the agent until the network team rebuilt the client profile.”
Network Engineer
BFSI
Media
“Mac support decided it. Our design studio runs on MacBooks and the other agent we trialled only covered Windows.”
Head of IT
Media
Manufacturing
“We had to pull Umbrella off every laptop first, because the two DNS agents refuse to share a machine. Budget for that cutover.”
Infrastructure Lead
Manufacturing
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint DNS filtering market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Endpoint DNS Filtering Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Heimdal DNS Security – EndpointThis page

Quoted per device per year; Windows and macOS agent.

Grid 02 · The architecture

Off-Network Reach × Bypass Resistance

The grid nobody publishes — how many device platforms keep filtering away from the office vs how hard the filter is to route around with encrypted DNS or a private resolver.

Locked down, few platformsBroad and hard to dodgeOffice-bound basicsWide but leaky
Heimdal DNS Security – EndpointThis page

Windows and macOS; browser DoH held, system DNS only.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Heimdal DNS Security – Endpoint vs the DNS filtering field

Against Cisco Umbrella, Infoblox Threat Defense, OpenText Core DNS Protection, N-able DNS Filtering and Cloudflare One Gateway — on agents, inspection depth, encrypted-DNS bypass, price, logs, India and exit.

DimensionHeimdal DNS Security – EndpointCisco UmbrellaInfoblox Threat DefenseOpenText Core DNS ProtectionN-able DNS FilteringCloudflare One Gateway
What it isOn-device DNS filterDNS tiers, SIG aboveProtective DNS, 4 tiersWebroot lineageDNSFilter insidePolicy engine of a SASE
Deployment and agentsWindows + macOS agentResolvers + roaming appSeven-OS endpoint agentWindows agent + forwardsRelays + Win/Mac agentsLocations or WARP
Layer, TLS and CASBDomains; CASB in nameSelective proxy at SIGDNS layer onlyDomains, no decryptionLookup verdicts onlyTLS decryption, CASB
Encrypted DNS bypassChrome/Firefox DoH heldDoH category, gapsPublic_DoH feedsCloses 53, 443, 853DoT; browser DoH partlyDoH, DoT per location
Scale and blind spotsSystem DNS onlyLarge estates verified17,000-staff customerSMB and MSP focus500k sync, as claimed330+ cities, no user cap
Pricing modelPer device, per yearPer user, four tiers3 tokens per assetPer site, keycodeQuoted, unit unstatedPer user, monthly
Published entry priceNot published~$2.25/user/monthQuote onlyNot publishedNot publishedFree to 50, then $7
Included vs add-onOne module of a suiteProxy costs a tier upExtras draw tokensEvery feature includedPro features onlyDNS free, depth extra
Logs and retentionRetention unpublishedExport to S360 days in the viewer13-month categories9-day query logs24 h free, 30 d paid
Integrations and adminRMM, PSA, REST APIMeraki and SD-WANNIOS and forwardersMSP console, Unity APIN-central, SSO, syncShared Zero Trust panel
India resolver and dataNo India regionMumbai and ChennaiIndian resolvers onlyNot documentedNo Indian citySix Indian cities
Support and trialFree trial, Mumbai deskFree trialDetection Mode pilot30-day trialTrial, length unstatedFree tier, SLA on paid
Lock-in and exitAgent tied to platformChange the resolversEasy unless on NIOSAgent hands DNS backLinked to N-able RMMNo annual term
Best fitRoaming Win/Mac fleetsDNS first, proxy laterInfoblox DDI shopsWindows MSP clientsN-able MSP customersPrice-led, Indian PoPs
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Heimdal DNS Security – Endpoint if…

  • ✓Your laptops spend most of their week off the office network and need the same domain blocks wherever they connect
  • ✓You want each blocked lookup tied to the program that made it, not just to a device address
  • ✓You run, or plan to run, other Heimdal modules and want one agent and one dashboard for all of them

Compare alternatives if…

  • ✓Indian resolvers must be documented — Cisco Umbrella, Infoblox Threat Defense and Cloudflare all name Indian cities
  • ✓Linux servers, iOS or Android phones need the agent too — Infoblox Endpoint covers all three
  • ✓You need content inspection or a working CASB — Cloudflare One Gateway decrypts and inspects HTTP on paid plans

Do not expect…

  • ✓TLS inspection, URL-path filtering, or a real CASB behind the dashboard label
  • ✓Cover for apps that bring their own resolver, or co-existence with an Umbrella-style DNS agent
  • ✓A published price, a stated DNS log retention, or an India data region

Heimdal DNS Security – Endpoint is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does cleaning up after bad domains cost you?

Drag the sliders (devices protected; IT-hour cost). Estimates model IT time lost to cleaning up malware infections and phishing clicks that started with a bad domain, at an assumed 1.5 hours per device a year, with 70% of it avoided when those domains never resolve. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual malware clean-up cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. Heimdal publishes no prices: its pricing calculator lists DNS Security – Endpoint as a separate line item, counted per device per year, and shows no figures. A free trial is offered. The agent it installs can also carry Heimdal’s antivirus, patching and privilege modules, each priced as its own line, and DNS Security – Network for agentless office coverage is another. TechBag counts your devices and the modules you actually need, then quotes in INR with GST.

DNS Security – Endpoint

Best for laptops that roam off the network

  • Quoted per device per year
  • Windows and macOS agent; no Linux
  • Free trial before purchase

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Add DNS Security – Network

Best for printers, IoT and guests in the office

  • A separate per-device line item
  • Office DNS forwards to Heimdal resolvers
  • No cover once a device leaves the site

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Operating systems

Do all machines run a supported Windows desktop or server release, or a Mac on 10.15 or newer? Linux and phones need another control.

2
VPN

Does your VPN client support split tunnelling or split exclusion? Without it, lookups travel round the agent.

3
Other DNS agents

Is Cisco Umbrella or a similar DNS agent installed? Heimdal says DarkLayer Guard cannot work beside one.

4
Built-in resolvers

Which apps carry their own resolver or DoH? Only system-generated DNS is filtered, so list them before the pilot.

5
Browsers

Will DoH Compatibility Mode be enforced for Chrome and Firefox, and how will any other browser in use be handled?

6
Data location

Can your DPDP and sector rules live with an EU, US or UK data region? Heimdal offers no Indian one.

7
Log retention

How will DNS records reach CERT-In’s 180 days? Heimdal states no retention, so plan CSV or API exports.

8
Licence

Is the quote per device per year, and which other Heimdal modules share the agent? Ask for INR with GST.

FAQ

Questions buyers ask

It is Heimdal’s agent-based DNS filter, formerly sold as Threat Prevention – Endpoint. Its DarkLayer Guard engine runs a DNS server on each Windows or macOS device, checks every system lookup against a local and then a cloud threat database, and refuses to resolve malicious domains wherever the device is.

Ready to evaluate Heimdal DNS Security – Endpoint?

Count the laptops and servers that need filtering first, or let a TechBag advisor map your VPN and browser bypass routes and run a roaming-laptop pilot.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.