Malware and phishing usually need a DNS lookup first. A malicious domain shouldn’t resolve at all — Infoblox Threat Defense checks every DNS lookup from your offices, roaming devices and cloud workloads against Infoblox threat intelligence, and malicious domains never resolve — in the cloud, on your NIOS servers, or through Infoblox Endpoint.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Infoblox Threat Defense — protective DNS in the cloud and on NIOS, with IQ, Dossier and lookalike monitoring as token add-ons. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A resolver that refuses to answer for malicious domains, so malware and phishing pages never get an address.
What consolidation actually replaces, dimension by dimension.
| Dimension | An open resolver and a firewall blocklist | Infoblox Threat Defense |
|---|---|---|
| Where threats are stopped | At the firewall, after the connection opens | At the lookup, before any connection starts |
| New and unknown domains | Blocklists updated by hand | DGA, zero-day and TDS detection from Infoblox intelligence |
| Laptops off the network | Unprotected until they reconnect | Infoblox Endpoint steers their DNS on any network |
| Encrypted DNS bypass | Browsers use any public DoH they like | Public_DoH feeds block known DoH services |
| How it is licensed | Per user, whoever the user is | Three Security Tokens per protected asset |
| What it is NOT | — | A web proxy, TLS inspection, a CASB, or a published price |
The cheapest test is Detection Mode: point it at real traffic for a few weeks, block nothing, and read what it would have stopped.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Sites send DNS through a DNS Forwarding Proxy, NIOS or third-party forwarders, or anycast for external networks; Infoblox Endpoint carries roaming devices.
Infoblox’s status page lists 16 resolution points, Mumbai and Hyderabad among them; a lookup to a blocked domain gets a block or redirect instead of an address.
Estates that run Infoblox NIOS can enforce the same policy on those appliances on site, and mix it with the cloud service under one token agreement.
Policies, feeds, custom lists and the 60-day Historical Data Viewer sit in the Infoblox Portal, hosted in North America or Europe; exports need Reporting Tokens.
Queries forwarded from sites, NIOS or Infoblox Endpoint — blocked at Infoblox resolvers, Mumbai and Hyderabad included.
Infoblox Threat Defense blocks malicious domains at the lookup, so the connection never starts.
Every query from offices, devices and workloads goes through Infoblox’s resolver, and each one is written to a DNS query log.
Threat Defense Cloud and Threat Defense for NIOS can be mixed in one token agreement, so branches and data centres share policy.
Infoblox Endpoint steers a device’s DNS to Threat Defense on any network; Windows 10 is limited and cloud VMs are not supported.
Detection Mode reports threats with no change to your infrastructure, Microsoft DNS included, before any blocking is switched on.
Analytics look for DNS tunnelling and exfiltration, where malware hides stolen data or commands inside ordinary-looking lookups.
Domain-generation-algorithm and zero-day domain detection catch freshly registered names that no blocklist carries yet.
Threat Defense detects traffic distribution systems (TDS), and Infoblox says it tracks over 204,000 threat-actor clusters.
The Advanced tier discovers applications from DNS, telling consumer and enterprise versions of generative-AI apps apart.
Public_DoH and Public_DoH_IP feeds come with every subscription and stop browsers quietly using a public DoH resolver.
Lookalike domain monitoring, a Security-Token add-on, flags imitations of your domains, with a takedown service behind it.
Dossier, licensed from the same Security Token pool, pulls Infoblox’s intelligence on an indicator into one investigation view.
IQ for Threat Defense, generally available since June 2026, is an add-on licensed as a percentage of your Cloud Security Tokens.
Detection Mode on Microsoft DNS, the IQ for Threat Defense add-on, roaming protection beside the Zscaler agent, and an investigation with custom lists. All from Infoblox’s official channel, 2025–2026.
How Detection Mode reads threats from Microsoft DNS without changing how your network resolves names.
The AI add-on that went generally available in June 2026, licensed as a share of your Cloud Security Tokens.
Running Infoblox Endpoint beside the Zscaler agent so roaming laptops keep DNS protection.
A 2025 walkthrough of working a finding in the portal and blocking it with a custom list.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Malware callbacks, phishing pages and command servers usually need a DNS lookup first. Threat Defense answers that lookup with a block or a redirect, so the connection never starts, on any port or protocol. Infoblox says this stops 90% of threats before the first query and spots threats 68 days earlier on average.
Few DNS filters also run on your own DNS servers. Threat Defense Cloud needs no Infoblox hardware, Threat Defense for NIOS enforces on Infoblox appliances, and Infoblox Endpoint covers roaming devices; one token agreement can mix them. That suits estates where DNS is already an Infoblox service.
Infoblox dropped per-user (FTE) licensing. Threat Defense Cloud counts three Security Tokens for each device, server or workload sending DNS queries, takes a daily snapshot and compares a rolling three-month average with what you bought. It does not shut off when you run over.
It sees domains, not content: there is no web proxy, no TLS inspection and no CASB, so it does not replace a secure web gateway. There is no public price. Lookups resolve in Mumbai and Hyderabad, but the portal and its logs are hosted in North America or Europe, and the viewer keeps 60 days.
List which resolvers offices, data centres, roaming laptops and cloud workloads use today, and where NIOS already runs.
Turn on Detection Mode, Microsoft DNS included, and let it report threats for a few weeks without blocking anything.
Count devices, servers and workloads that send DNS queries, apply three tokens each, and add Reporting Tokens for logs.
Switch policies to block at one site, add the Public_DoH feeds, then roll Infoblox Endpoint out to roaming devices.
Export DNS logs to your SIEM for 180-day retention, and decide whether Dossier or IQ add-ons earn their tokens.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Detection Mode ran against our Microsoft DNS for a month before we blocked anything. The report sold the purchase internally.”
“We already ran NIOS in the data centres, so enforcing on those appliances and adding the cloud for branches was one policy.”
“It caught a DNS-tunnelling beacon on a build server that our firewall logs showed only as normal port 53 traffic.”
“Counting tokens per device instead of per employee helped us, because half our assets are kiosks and sensors with no user.”
“Sixty days in the viewer is not enough for our auditors, so we budgeted Reporting Tokens and push everything to the SIEM.”
“Good at blocking domains, but it is not a web gateway. We still needed a proxy for file scanning and upload control.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the protective DNS market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote only; three Security Tokens per protected asset.
The grid nobody publishes — how many places a product can enforce DNS policy vs how deeply it analyses what the lookups reveal.
Cloud, NIOS, Endpoint and anycast; tunnelling, DGA and TDS.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Cisco Umbrella, Cloudflare One Gateway, Palo Alto Advanced DNS Security, N-able DNS Filtering and AWS Route 53 Resolver DNS Firewall — on deployment, inspection depth, encrypted-DNS bypass, roaming, detection, price, logs and India.
| Dimension | Infoblox Threat Defense | Cisco Umbrella | Cloudflare One Gateway | Palo Alto Advanced DNS Security | N-able DNS Filtering | AWS Route 53 Resolver DNS Firewall |
|---|---|---|---|---|---|---|
| What it is | Protective DNS service | DNS tiers, then SIG | Gateway inside SSE | DNS service + Resolver | MSP DNS filter | VPC DNS filter |
| Deployment | Cloud, NIOS or agent | Resolver change, client | Locations, WARP, tunnels | Forwarder or NGFW | Site IP, relay or agent | Rule groups per VPC |
| Layer, TLS and CASB | DNS only | Proxy at SIG tiers | Full TLS, CASB both ways | DNS layer only | Domains only | DNS queries only |
| Encrypted DNS bypass | Public_DoH feeds | DoH category | Per-location DoH/DoT | DoH and DoT accepted | DoT; DoH needs firewall | Resolver traffic only |
| Roaming devices | Infoblox Endpoint | Roaming client | WARP client | Prisma Agent only | Windows and macOS | Not applicable |
| Threat detection | Tunnels, DGA, TDS | Talos + OpenDNS data | Network-wide intel | Query and response | DNSFilter categories | Managed lists, Advanced |
| Pricing model | Security Tokens | Per user, tiered | Per user, listed | Per user or per device | Quoted to MSPs | Pay per query |
| Published entry price | Quote only | ~$30–40/user/yr | Free to 50, then $7 | Not published | Not published | $0.60 per million |
| Included vs add-on | Add-ons on tokens | Proxy a tier up | DNS, HTTP, network | Separate SKUs | DNS filter only | Advanced costs extra |
| Scale and limits | 17,000+ named estate | Verified large estates | Verified large estates | 5,000 queries/user/day | Not verified at scale | Per VPC, per Region |
| Logs and retention | 60 days, then export | Not verified here | Longer on Enterprise | Follows tenant region | 9 days | Your own destination |
| India presence | Resolvers in, portal out | Mumbai and Chennai | Six Indian cities | Country, not city | No Indian city | Mumbai and Hyderabad |
| Lock-in and exit | Easy in cloud, not NIOS | Repoint and uninstall | Grows with HTTP use | Re-point forwarders | Tied to N-able tools | AWS only |
| Best fit | Infoblox DNS estates | DNS now, SIG later | Listed-price inspection | Palo Alto shops | MSP-managed clients | AWS workloads |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Infoblox Threat Defense is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (devices and workloads protected; security analyst-hour cost). Estimates model analyst time spent chasing malware callbacks, phishing clicks and DNS-tunnel alerts at an assumed 1.5 hours per device a year, with 70% of it removed by blocking malicious domains at resolution. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Infoblox publishes no price for Threat Defense, and the AWS and Azure marketplaces sell it by private offer. Licensing is token-based, not per user: Threat Defense Cloud counts three Security Tokens per protected device, server or workload, measured as a rolling three-month average, while Threat Defense for NIOS counts by appliance model. IQ for Threat Defense, Dossier and lookalike monitoring draw on the same Security Tokens, and exporting DNS logs needs Reporting Tokens (40 per 10 million entries a month). TechBag counts your assets first, then quotes in INR with GST.
Best for sites, roaming users and workloads
Best for a broader rollout
Best for estates already running Infoblox DNS
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
How many devices, servers and workloads send DNS queries? At three tokens each, this number drives the quote.
Will you enforce in the cloud, on NIOS appliances on site, or both under one token agreement?
Do your laptops and phones run an OS Infoblox Endpoint supports? Windows 10 is limited and cloud VMs are excluded.
Are the Public_DoH feeds switched on, and does the firewall stop devices reaching outside resolvers directly?
The viewer keeps 60 days; how will you export logs to keep the 180 days CERT-In requires, and at what token cost?
Is it acceptable that the portal and logs sit in North America or Europe while resolution happens in India?
Do you also need TLS inspection, file scanning or a CASB? Threat Defense has none, so plan a proxy if so.
Does the quote itemise IQ, Dossier, lookalike monitoring and Reporting Tokens, in INR with GST?
Count the devices and workloads that send DNS queries first, or let a TechBag advisor run a Detection Mode pilot, size your tokens and plan the log export.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.