Your offices are full of devices that will never run an agent. They still look up every domain through your DNS servers — Heimdal DNS Security – Network filters every device that uses your office DNS servers — PCs, guest phones, printers and IoT — by forwarding lookups to Heimdal’s resolvers, or by filtering on your own DNS server with Hybrid DNS.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Heimdal DNS Security – Network — the agentless network filter, including Hybrid DNS. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Your DNS servers ask a filtering resolver first, so a bad domain never resolves for any device behind them.
What consolidation actually replaces, dimension by dimension.
| Dimension | An ISP resolver and firewall blocklists | Heimdal DNS Security – Network |
|---|---|---|
| Who gets filtered | Nobody; the ISP resolver answers everything | Every device that uses your DNS servers |
| IoT and guest devices | Unfiltered; nothing can be installed | Covered by forwarding, with no software |
| Dynamic-IP branches | Static IP or no service | Hybrid DNS filters on the local server |
| Finding the device | A NAT address in the firewall log | Internal hostname and IP from the LogAgent |
| Policy across sites | A blocklist per firewall, edited by hand | One dashboard of categories and lists |
| What it is NOT | — | A proxy, TLS inspection, roaming cover or an India region |
The cheapest test is the free trial: forward one office’s DNS to Heimdal for a few weeks and read which devices it blocks.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Your internal DNS servers forward outside queries to 193.243.129.53 and 76.223.127.10. Heimdal says these run on AWS but names no city; blocked domains get no usable answer.
Each office’s public address is registered as a /32, /31 or /30 Access Rule; wider ranges go through support, and an edit reaches the resolvers within about 30 minutes.
Optional: the LogAgent runs a filtering DNS server on loopback 127.8.8.1 inside a Windows Server 2012+ or Ubuntu 18.04+ DNS box, so dynamic IPs and any forwarder work.
Category blocks, allow and deny lists, the DNS-based app view Heimdal labels CASB, and query logs share one console with Heimdal’s other modules, plus a REST API.
Your DNS servers forward to Heimdal’s resolvers — or Hybrid DNS filters on the server itself and names each internal device.
Heimdal DNS Security – Network blocks bad domains for a whole office, with nothing installed on the devices.
Phones, printers, cameras, guest laptops and IoT kit are filtered just by using a DNS server that forwards to Heimdal.
The LogAgent filters on the DNS server itself, which drops the static-IP requirement and lets you keep the forwarder you prefer.
A DoH setting sends the server’s own lookups to a chosen DNS-over-HTTPS resolver, so the upstream leg is not plain text.
Entire categories of domains can be refused in one rule, with per-domain allow and deny lists for the exceptions you need.
Heimdal claims 96% accuracy for Predictive DNS in spotting malicious domains; that is the vendor’s figure, not an independent test.
Apps seen in DNS lookups are listed and can be blocked through the domain blocklist; no inline proxy or SaaS API sits behind it.
With Hybrid DNS the LogAgent ties each lookup to an internal hostname and IP, so a blocked query points at a device, not a NAT address.
Connectors for Cisco Meraki, Palo Alto, HaloPSA, Autotask PSA and ConnectWise RMM are listed, with a REST API for exports.
The same dashboard runs DNS Security – Endpoint, so laptops that leave the office keep a matching policy if you buy both.
Network and endpoint DNS filtering under the product’s former name, Threat Prevention (2021), plus two DNS security explainers from 2024. All from Heimdal’s official channel.
Network and endpoint DNS filtering side by side (under its former name, Threat Prevention).
Heimdal’s practical list for protecting an organisation’s DNS; a topic guide rather than a product demo.
A half-minute primer on why stopping a bad lookup stops the connection that would have followed it.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Point your internal DNS servers at two Heimdal addresses and every device that relies on them is filtered: PCs, guest phones, printers, CCTV and IoT kit no agent will ever run on. Heimdal knows the office by its registered public IP, so nothing is installed on clients.
Branches on broadband rarely keep one public address. Hybrid DNS moves the filter onto your own Windows Server or Ubuntu DNS server via the LogAgent, which needs no static IP, keeps your forwarder, and logs the internal hostname behind each lookup.
DNS – Network lives in the dashboard that also runs Heimdal’s endpoint DNS agent, patching, antivirus and XDR. Buy it alone for the office, or add DNS Security – Endpoint for laptops; it also plugs into Meraki, Palo Alto and the main MSP tools.
It decides on the domain name only: no proxy, no TLS inspection, and the “CASB” view is a list of apps seen in DNS. It cannot follow a laptop home. The resolvers run on AWS with no city named, customer data is held in an EU, US or UK region, and query-log retention is never stated.
List each office’s DNS servers and public IPs, and note which IPs are static; dynamic-IP branches are Hybrid DNS candidates.
Add each static IP as a /32, /31 or /30 Access Rule, allow 30 minutes to propagate, then forward one site’s DNS to Heimdal.
Put the LogAgent on a Windows Server 2012+ or Ubuntu 18.04+ DNS server; check Npcap OEM against any Azure ATP sensor first.
Block outbound port 53 and known DoH services at the firewall so devices cannot skip your forwarders, then tune the blocks.
Set up CSV or API log export for 180 days, decide whether laptops need the Endpoint module, and get the device count in writing.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We forwarded the head-office DNS servers on a Friday afternoon; by Monday the CCTV recorders were turning up in blocked-query logs.”
“Our branches sit on broadband with changing IPs. Hybrid DNS on each local Windows DNS server fixed that without a support ticket.”
“The LogAgent named the actual laptop behind a blocked lookup instead of the firewall’s NAT address. That alone saved hours.”
“Npcap clashed with the Azure ATP sensor on one domain controller, so we moved the LogAgent to a separate DNS server.”
“Guest Wi-Fi phones are filtered without any app, which was the whole point for our campus. Roaming laptops needed the endpoint module.”
“Blocking works well, but we export logs ourselves to keep 180 days for CERT-In; the retention period is not spelled out anywhere.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the protective DNS market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote per device a year; part of a 12+ product platform.
The grid nobody publishes — how many devices a product filters without an agent vs how far past the domain name it can look.
Forwarding or on-server Hybrid DNS; domain verdicts only.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Set beside Akamai SIA, Cloudflare One Gateway, OpenText Core DNS Protection, Infoblox Threat Defense and Cisco Umbrella — on deployment, devices covered, inspection depth, encrypted DNS, price, logs and India.
| Dimension | Heimdal DNS Security – Network | Cisco Umbrella | Infoblox Threat Defense | OpenText Core DNS Protection | Cloudflare One Gateway | Akamai Secure Internet Access Enterprise |
|---|---|---|---|---|---|---|
| What it is | Network DNS filter | DNS tiers under SIG | Protective DNS family | Ex-Webroot DNS filter | SSE gateway, DNS too | Recursive DNS firewall |
| Deployment | Forwarders or LogAgent | Repoint DNS, Meraki | Cloud, NIOS, Endpoint | Forwarding + Win agent | Locations or WARP | Forwarders, then proxy |
| Devices covered | Site only, no roaming | Sites + roaming module | Seven-OS agent | Windows agent only | WARP on any device | Clients on five OSes |
| Inspection depth | Domain verdicts only | Proxy from SIG up | DNS layer only | Lookups only | Full TLS, CASB | Selective TLS proxy |
| Encrypted DNS | DoH upstream only | DoH/DoT category | Public DoH feeds | Agent blocks DoH, DoT | DoH per location | DoT in the client |
| Pricing model | Per device, per year | Per user by tier | Three tokens a device | Per-site keycodes | Per user, monthly | Quote by licence |
| Published entry price | No price | ~$30–40/user/yr | Not published | Not published | $0 to 50, then $7 | Quote only |
| Included vs add-on | Endpoint sold apart | Proxy costs a tier | Extras on tokens | One policy, all in | Three filter types | Licences stack |
| Scale and limits | /30 rules, AWS-hosted | Verified past 5,000 | 17,000-staff customer | Scale not verified | 330+ cities, verified | Carrier-scale DNS |
| Integrations | RMM, PSA, Meraki, API | Cisco and Meraki | Infoblox DDI | MSP console, Unity API | Cloudflare One stack | Connector, SD-WAN, IPsec |
| Logs and retention | Retention not stated | S3 export | 60-day viewer | 13-month reports | 24 h free, 30 days paid | Not documented |
| India presence | No Indian region | Mumbai and Chennai | Indian resolvers | No Indian city listed | Six Indian cities | No Indian city named |
| Lock-in and exit | Change two forwarders | Repoint and remove | Cloud easy, NIOS sticky | Agent stop reverts DNS | Harder once HTTP is on | Proxy adds exit work |
| Best fit | Offices full of IoT | Fast DNS, proxy later | Infoblox DDI shops | MSP Windows clients | Free start, Indian PoPs | DNS + risky-site proxy |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Heimdal DNS Security – Network is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (devices on your office networks; IT-security hour cost). Estimates model staff time spent cleaning up after malware callbacks and phishing clicks from office devices at an assumed 1.5 hours per device a year, with 70% of it removed by blocking malicious domains at the network’s DNS. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
No public figure exists. Heimdal’s quote builder shows DNS Security – Network on its own line, counted by device for each year of the term, and a free trial comes first. How a forwarding DNS server’s clients become a device count is not written down anywhere, so have Heimdal state the method. Roaming laptops need DNS Security – Endpoint, which is a second line. TechBag maps your sites and devices first, then quotes in INR with GST.
Best for offices full of devices no agent reaches
Best for a broader rollout
Best when laptops also leave the office
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
How will Heimdal count devices behind a forwarder for a per-device licence? Get the counting method in writing.
Is every site’s public IP static and no wider than a /30? Larger ranges go through support; dynamic ones need Hybrid DNS.
Do your DNS servers run Windows Server 2012+ or Ubuntu 18.04+, and is Npcap OEM safe beside your other agents?
Will the firewall stop clients using their own resolvers or DoH? No client-side DoH control is documented for this product.
Do laptops spend time off-site? This product covers only the network, so budget DNS Security – Endpoint for them.
Where will DNS logs live for CERT-In’s 180 days? Retention is not documented, so plan a CSV or REST API export.
Can your compliance team accept an EU, US or UK tenant? Heimdal has no Indian region and names no resolver city.
Do you need content inspection or a CASB? This product decides on domains only; a proxy gateway is a different buy.
Map your offices’ DNS servers and public IPs first, or let a TechBag advisor run a trial on one site and plan the bypass rules and log export.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.