Talk to us
by HeimdalTechBag Intel Page

Heimdal DNS Security – Network

Your offices are full of devices that will never run an agent. They still look up every domain through your DNS servers — Heimdal DNS Security – Network filters every device that uses your office DNS servers — PCs, guest phones, printers and IoT — by forwarding lookups to Heimdal’s resolvers, or by filtering on your own DNS server with Hybrid DNS.

Filter the network, not each deviceBYOD, IoT and guests coveredQuote; per device per year

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Licensed per device per year on Heimdal’s calculator; no figure is published
Quote
Layer
Refuses bad domains at lookup; no proxy, no TLS decryption and no true CASB
DNS only
Analysts
Absent from analyst quadrants; its 4.8/5 badge is a Gartner Peer Insights review average
None
India
Tenants are hosted in EU, US or UK regions; the AWS resolvers have no stated city
No region

Quick answer

Heimdal DNS Security – Network filters a whole office’s DNS with nothing on the clients: your DNS servers forward to two AWS-hosted Heimdal resolvers, which know your site by its public IP. Optional Hybrid DNS runs a filtering LogAgent on your own Windows or Ubuntu DNS server. It blocks by domain only, with no TLS inspection, is quoted per device a year, and keeps tenant data in Europe, the US or the UK, not India. Read more ↓ Show less ↑
Part 01 · Orient

The Heimdal platform family

This page covers Heimdal DNS Security – Network — the agentless network filter, including Hybrid DNS. The rest:

Quick facts

30-second orientation
Product
Agentless DNS filtering for networks: your DNS servers forward lookups to Heimdal’s resolvers
Maker
A Danish firm founded 2014 with HQ in Copenhagen; owned by Marlin Equity Partners since 2020; CEO Jesper Frederiksen
Former name
Threat Prevention Network, now sold as DNS Security – Network
Price
Not published; per device per year on Heimdal’s calculator, quote only, with a free trial
Deployment
Forward to 193.243.129.53 and 76.223.127.10, or run the Hybrid DNS LogAgent on your DNS server
Coverage
Any device using a forwarding DNS server, BYOD and IoT included; nothing follows laptops off-site
Layer
DNS only: no proxy and no TLS inspection; its “CASB” view is DNS-based app discovery
Recognition
No MQ or Wave; Heimdal’s awards page quotes 4.8/5 from Gartner Peer Insights reviewers
India
No Indian hosting: tenants live in EU, US or UK regions; the Mumbai team sells and supports
In India via
TechBag — resolver mapping, quote in INR with GST, bypass rules and a log-export plan
Part 02 · Learn

Understand network DNS filtering before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is network DNS filtering?

Your DNS servers ask a filtering resolver first, so a bad domain never resolves for any device behind them.

An ISP resolver and firewall blocklists vs Heimdal DNS Security – Network — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionAn ISP resolver and firewall blocklistsHeimdal DNS Security – Network
Who gets filteredNobody; the ISP resolver answers everythingEvery device that uses your DNS servers
IoT and guest devicesUnfiltered; nothing can be installedCovered by forwarding, with no software
Dynamic-IP branchesStatic IP or no serviceHybrid DNS filters on the local server
Finding the deviceA NAT address in the firewall logInternal hostname and IP from the LogAgent
Policy across sitesA blocklist per firewall, edited by handOne dashboard of categories and lists
What it is NOT—A proxy, TLS inspection, roaming cover or an India region

The cheapest test is the free trial: forward one office’s DNS to Heimdal for a few weeks and read which devices it blocks.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where every forwarded lookup is judged

Resolvers

Heimdal’s two cloud resolvers

Your internal DNS servers forward outside queries to 193.243.129.53 and 76.223.127.10. Heimdal says these run on AWS but names no city; blocked domains get no usable answer.

02
How Heimdal knows the query is yours

Access Rules

Public-IP Access Rules

Each office’s public address is registered as a /32, /31 or /30 Access Rule; wider ranges go through support, and an edit reaches the resolvers within about 30 minutes.

03
Filtering on your own DNS server

LogAgent

Hybrid DNS LogAgent

Optional: the LogAgent runs a filtering DNS server on loopback 127.8.8.1 inside a Windows Server 2012+ or Ubuntu 18.04+ DNS box, so dynamic IPs and any forwarder work.

04
Where policy and query logs live

Dashboard

Heimdal unified dashboard

Category blocks, allow and deny lists, the DNS-based app view Heimdal labels CASB, and query logs share one console with Heimdal’s other modules, plus a REST API.

Your DNS servers forward to Heimdal’s resolvers — or Hybrid DNS filters on the server itself and names each internal device.

Part 03 · Evaluate

Nine capabilities. Forward, filter, report.

Heimdal DNS Security – Network blocks bad domains for a whole office, with nothing installed on the devices.

Forward
Agentless

Covers what cannot run an agent

Phones, printers, cameras, guest laptops and IoT kit are filtered just by using a DNS server that forwards to Heimdal.

Forward
Hybrid DNS

Filtering on your own DNS server

The LogAgent filters on the DNS server itself, which drops the static-IP requirement and lets you keep the forwarder you prefer.

Forward
Encrypted upstream

DoH from the server outward

A DoH setting sends the server’s own lookups to a chosen DNS-over-HTTPS resolver, so the upstream leg is not plain text.

Filter
Categories

Block whole categories at once

Entire categories of domains can be refused in one rule, with per-domain allow and deny lists for the exceptions you need.

Filter
Predictive DNS

Heimdal’s predictive engine

Heimdal claims 96% accuracy for Predictive DNS in spotting malicious domains; that is the vendor’s figure, not an independent test.

Filter
App discovery

The list Heimdal calls CASB

Apps seen in DNS lookups are listed and can be blocked through the domain blocklist; no inline proxy or SaaS API sits behind it.

Report
Internal names

Which machine asked

With Hybrid DNS the LogAgent ties each lookup to an internal hostname and IP, so a blocked query points at a device, not a NAT address.

Report
Integrations

Hooks for MSP and network tools

Connectors for Cisco Meraki, Palo Alto, HaloPSA, Autotask PSA and ConnectWise RMM are listed, with a REST API for exports.

Report
One platform

Pairs with the endpoint DNS agent

The same dashboard runs DNS Security – Endpoint, so laptops that leave the office keep a matching policy if you buy both.

See it, don’t just read it

Watch Heimdal DNS Security – Network in action

Network and endpoint DNS filtering under the product’s former name, Threat Prevention (2021), plus two DNS security explainers from 2024. All from Heimdal’s official channel.

Heimdal (official)·Overview, May 2021

Heimdal Threat Prevention Endpoint & Network - DNS Filtering

Network and endpoint DNS filtering side by side (under its former name, Threat Prevention).

Heimdal (official)·Explainer, Sept 2024

DNS Security Best Practices – A Quick Guide for Organizations

Heimdal’s practical list for protecting an organisation’s DNS; a topic guide rather than a product demo.

Heimdal (official)·Short, Jan 2024

DNS Security Explained in 30 Seconds

A half-minute primer on why stopping a bad lookup stops the connection that would have followed it.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Heimdal DNS Security – Network

Every device asks DNS before it connects. DNS Security – Network answers for the whole office.

Here’s what genuinely sets it apart — and exactly where it stops.

01

A whole site filtered with no rollout

Point your internal DNS servers at two Heimdal addresses and every device that relies on them is filtered: PCs, guest phones, printers, CCTV and IoT kit no agent will ever run on. Heimdal knows the office by its registered public IP, so nothing is installed on clients.

02

Hybrid DNS answers the dynamic-IP problem

Branches on broadband rarely keep one public address. Hybrid DNS moves the filter onto your own Windows Server or Ubuntu DNS server via the LogAgent, which needs no static IP, keeps your forwarder, and logs the internal hostname behind each lookup.

03

The same console as the endpoint stack

DNS – Network lives in the dashboard that also runs Heimdal’s endpoint DNS agent, patching, antivirus and XDR. Buy it alone for the office, or add DNS Security – Endpoint for laptops; it also plugs into Meraki, Palo Alto and the main MSP tools.

04

Where it stops

It decides on the domain name only: no proxy, no TLS inspection, and the “CASB” view is a list of apps seen in DNS. It cannot follow a laptop home. The resolvers run on AWS with no city named, customer data is held in an EU, US or UK region, and query-log retention is never stated.

The idea
Filter the network, not each device
The reach
BYOD, IoT and guests via forwarding
The price
Quote; per device per year
Proof, not promises

The numbers behind the platform

2 resolvers
Heimdal addresses your DNS servers forward to: 193.243.129.53 and 76.223.127.10
— Vendor
30 minutes
how often Access Rule changes propagate out to Heimdal’s resolvers
— Vendor
4 addresses
the widest Access Rule you can add yourself, a /30; larger ranges go via support
— Vendor
Server 2012
the oldest Windows Server the Hybrid DNS LogAgent supports; Ubuntu needs 18.04 or later
— Vendor
96%
Heimdal’s own accuracy claim for Predictive DNS; no independent test was found
— Vendor
3 tenant regions
where a customer’s Heimdal data can be kept — EU, US or UK; India is not among them
— Vendor

What your Heimdal DNS Security – Network rollout looks like

Week 1Model

Map every resolver in the estate

List each office’s DNS servers and public IPs, and note which IPs are static; dynamic-IP branches are Hybrid DNS candidates.

Week 2Pilot

Register rules and forward one site

Add each static IP as a /32, /31 or /30 Access Rule, allow 30 minutes to propagate, then forward one site’s DNS to Heimdal.

Week 3Extend

Install Hybrid DNS where IPs move

Put the LogAgent on a Windows Server 2012+ or Ubuntu 18.04+ DNS server; check Npcap OEM against any Azure ATP sensor first.

Month 2Prove

Close the bypass routes

Block outbound port 53 and known DoH services at the firewall so devices cannot skip your forwarders, then tune the blocks.

Month 3Commit

Settle logs and the licence

Set up CSV or API log export for 180 days, decide whether laptops need the Endpoint module, and get the device count in writing.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.1
38+ reviews*
80% would recommend
Ease of rollout4.5
Agentless coverage4.4
Threat blocking4.0
Reporting3.8
Value for money3.9
5★
42%
4★
38%
3★
13%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Manufacturing
“We forwarded the head-office DNS servers on a Friday afternoon; by Monday the CCTV recorders were turning up in blocked-query logs.”
Network Administrator
Manufacturing
Retail
“Our branches sit on broadband with changing IPs. Hybrid DNS on each local Windows DNS server fixed that without a support ticket.”
IT Manager
Retail
BFSI
“The LogAgent named the actual laptop behind a blocked lookup instead of the firewall’s NAT address. That alone saved hours.”
Security Analyst
BFSI
IT Services
“Npcap clashed with the Azure ATP sensor on one domain controller, so we moved the LogAgent to a separate DNS server.”
Systems Engineer
IT Services
Education
“Guest Wi-Fi phones are filtered without any app, which was the whole point for our campus. Roaming laptops needed the endpoint module.”
IT Head
Education
Healthcare
“Blocking works well, but we export logs ourselves to keep 180 days for CERT-In; the retention period is not spelled out anywhere.”
Head of IT
Healthcare
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the protective DNS market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Network DNS Filtering Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Heimdal DNS Security – NetworkThis page

Quote per device a year; part of a 12+ product platform.

Grid 02 · The architecture

Agentless Reach × Inspection Depth

The grid nobody publishes — how many devices a product filters without an agent vs how far past the domain name it can look.

Proxy-first platformsBroad and deepNarrow DNS filtersAgentless DNS specialists
Heimdal DNS Security – NetworkThis page

Forwarding or on-server Hybrid DNS; domain verdicts only.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Heimdal DNS Security – Network vs the protective DNS field

Set beside Akamai SIA, Cloudflare One Gateway, OpenText Core DNS Protection, Infoblox Threat Defense and Cisco Umbrella — on deployment, devices covered, inspection depth, encrypted DNS, price, logs and India.

DimensionHeimdal DNS Security – NetworkCisco UmbrellaInfoblox Threat DefenseOpenText Core DNS ProtectionCloudflare One GatewayAkamai Secure Internet Access Enterprise
What it isNetwork DNS filterDNS tiers under SIGProtective DNS familyEx-Webroot DNS filterSSE gateway, DNS tooRecursive DNS firewall
DeploymentForwarders or LogAgentRepoint DNS, MerakiCloud, NIOS, EndpointForwarding + Win agentLocations or WARPForwarders, then proxy
Devices coveredSite only, no roamingSites + roaming moduleSeven-OS agentWindows agent onlyWARP on any deviceClients on five OSes
Inspection depthDomain verdicts onlyProxy from SIG upDNS layer onlyLookups onlyFull TLS, CASBSelective TLS proxy
Encrypted DNSDoH upstream onlyDoH/DoT categoryPublic DoH feedsAgent blocks DoH, DoTDoH per locationDoT in the client
Pricing modelPer device, per yearPer user by tierThree tokens a devicePer-site keycodesPer user, monthlyQuote by licence
Published entry priceNo price~$30–40/user/yrNot publishedNot published$0 to 50, then $7Quote only
Included vs add-onEndpoint sold apartProxy costs a tierExtras on tokensOne policy, all inThree filter typesLicences stack
Scale and limits/30 rules, AWS-hostedVerified past 5,00017,000-staff customerScale not verified330+ cities, verifiedCarrier-scale DNS
IntegrationsRMM, PSA, Meraki, APICisco and MerakiInfoblox DDIMSP console, Unity APICloudflare One stackConnector, SD-WAN, IPsec
Logs and retentionRetention not statedS3 export60-day viewer13-month reports24 h free, 30 days paidNot documented
India presenceNo Indian regionMumbai and ChennaiIndian resolversNo Indian city listedSix Indian citiesNo Indian city named
Lock-in and exitChange two forwardersRepoint and removeCloud easy, NIOS stickyAgent stop reverts DNSHarder once HTTP is onProxy adds exit work
Best fitOffices full of IoTFast DNS, proxy laterInfoblox DDI shopsMSP Windows clientsFree start, Indian PoPsDNS + risky-site proxy
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Heimdal DNS Security – Network if…

  • ✓Every device on an office network must be filtered, including printers, cameras and guest phones that can never run an agent
  • ✓Branches change public IPs, and Hybrid DNS on a local Windows or Ubuntu DNS server suits you better than static-IP registration
  • ✓You already run Heimdal modules and want office DNS policy in the same dashboard, with the Endpoint agent for laptops later

Compare alternatives if…

  • ✓You need named Indian resolver cities in writing — Umbrella, Infoblox and Cloudflare publish theirs
  • ✓Web content must be inspected, not just domains — Cloudflare Gateway and Akamai SIA offer TLS-inspecting proxies
  • ✓You want a printed price before talking to sales — Cloudflare lists $7 per user a month after 50 free users

Do not expect…

  • ✓TLS inspection, file scanning or a real CASB; the “CASB” view is DNS app discovery
  • ✓Protection for laptops once they leave the office, unless you add DNS Security – Endpoint
  • ✓An Indian data region, a published price or an analyst Magic Quadrant placement

Heimdal DNS Security – Network is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →

Do the math

What do threats from unmanaged office devices cost you?

Drag the sliders (devices on your office networks; IT-security hour cost). Estimates model staff time spent cleaning up after malware callbacks and phishing clicks from office devices at an assumed 1.5 hours per device a year, with 70% of it removed by blocking malicious domains at the network’s DNS. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual clean-up cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

No public figure exists. Heimdal’s quote builder shows DNS Security – Network on its own line, counted by device for each year of the term, and a free trial comes first. How a forwarding DNS server’s clients become a device count is not written down anywhere, so have Heimdal state the method. Roaming laptops need DNS Security – Endpoint, which is a second line. TechBag maps your sites and devices first, then quotes in INR with GST.

DNS Security – Network

Best for offices full of devices no agent reaches

  • Forwarding, or Hybrid DNS on your server
  • Per device per year, quoted
  • Covers BYOD, IoT and guests on site

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Network + Endpoint

Best when laptops also leave the office

  • Two line items in one dashboard
  • Endpoint agent for Windows and macOS
  • Matching policy on site and off

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Device count

How will Heimdal count devices behind a forwarder for a per-device licence? Get the counting method in writing.

2
Public IPs

Is every site’s public IP static and no wider than a /30? Larger ranges go through support; dynamic ones need Hybrid DNS.

3
Hybrid DNS

Do your DNS servers run Windows Server 2012+ or Ubuntu 18.04+, and is Npcap OEM safe beside your other agents?

4
Bypass

Will the firewall stop clients using their own resolvers or DoH? No client-side DoH control is documented for this product.

5
Roaming

Do laptops spend time off-site? This product covers only the network, so budget DNS Security – Endpoint for them.

6
Logs

Where will DNS logs live for CERT-In’s 180 days? Retention is not documented, so plan a CSV or REST API export.

7
Data region

Can your compliance team accept an EU, US or UK tenant? Heimdal has no Indian region and names no resolver city.

8
Inspection

Do you need content inspection or a CASB? This product decides on domains only; a proxy gateway is a different buy.

FAQ

Questions buyers ask

It is Heimdal’s agentless DNS filter for networks. Your internal DNS servers forward lookups to Heimdal’s resolvers, which refuse malicious and policy-blocked domains, so every device using those servers is covered — managed PCs, guest phones, printers and IoT — with nothing installed on them.

Ready to evaluate Heimdal DNS Security – Network?

Map your offices’ DNS servers and public IPs first, or let a TechBag advisor run a trial on one site and plan the bypass rules and log export.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.