Talk to us
by InfobloxTechBag Intel Page

Infoblox Threat Defense

Malware and phishing usually need a DNS lookup first. A malicious domain shouldn’t resolve at all — Infoblox Threat Defense checks every DNS lookup from your offices, roaming devices and cloud workloads against Infoblox threat intelligence, and malicious domains never resolve — in the cloud, on your NIOS servers, or through Infoblox Endpoint.

Blocks malicious domains at the lookupCloud, NIOS and Infoblox EndpointQuote; three Security Tokens per asset

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Infoblox publishes no token price; marketplace purchases go through private offers
Quote
Licence
Per device, server or workload that sends DNS queries, on Threat Defense Cloud
3 tokens / asset
India
DNS resolves in India; the management portal and its logs do not
Mumbai + Hyderabad
Logs
In the Historical Data Viewer; export to S3 or a SIEM for anything longer
60 days

Quick answer

Infoblox Threat Defense is protective DNS: lookups from offices, roaming devices and cloud workloads are checked against Infoblox threat intelligence, and malicious domains never resolve. It runs as a cloud resolver, on NIOS DNS servers on site, or through Infoblox Endpoint. It is quote-only, licensed at three Security Tokens per protected asset. Lookups resolve in Mumbai and Hyderabad; the portal sits in North America or Europe. Read more ↓ Show less ↑
Part 01 · Orient

The Infoblox platform family

This page covers Infoblox Threat Defense — protective DNS in the cloud and on NIOS, with IQ, Dossier and lookalike monitoring as token add-ons. The rest:

Quick facts

30-second orientation
Product
Protective DNS: blocks malicious domains at resolution, in the cloud, on NIOS or on the device
Maker
Infoblox Inc., Santa Clara, California; founded in Chicago in 1999; private, CEO Scott Harrell
Tiers
Essentials, Business On-Prem, Business Cloud and Advanced; formerly BloxOne Threat Defense
Price
Quote only; no public token rate, and private offers only on the AWS and Azure marketplaces
Licence
Three Security Tokens per protected asset on Threat Defense Cloud; NIOS enforcement by appliance model
Agent
Infoblox Endpoint for Windows 11, macOS, Ubuntu, Red Hat, iOS, Android and ChromeOS
Logs
Historical Data Viewer keeps 60 days; longer retention means exporting with Reporting Tokens
Layer
DNS only: no web proxy, no TLS inspection and no CASB
India
Resolution points in Mumbai and Hyderabad; the Infoblox Portal is hosted in North America or Europe
In India via
TechBag — Detection Mode pilot, token sizing, quote in INR with GST, log-export plan
Part 02 · Learn

Understand protective DNS before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is protective DNS?

A resolver that refuses to answer for malicious domains, so malware and phishing pages never get an address.

An open resolver and a firewall blocklist vs Infoblox Threat Defense — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionAn open resolver and a firewall blocklistInfoblox Threat Defense
Where threats are stoppedAt the firewall, after the connection opensAt the lookup, before any connection starts
New and unknown domainsBlocklists updated by handDGA, zero-day and TDS detection from Infoblox intelligence
Laptops off the networkUnprotected until they reconnectInfoblox Endpoint steers their DNS on any network
Encrypted DNS bypassBrowsers use any public DoH they likePublic_DoH feeds block known DoH services
How it is licensedPer user, whoever the user isThree Security Tokens per protected asset
What it is NOT—A web proxy, TLS inspection, a CASB, or a published price

The cheapest test is Detection Mode: point it at real traffic for a few weeks, block nothing, and read what it would have stopped.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
The on-ramp for every lookup

Forwarding

How queries reach Infoblox

Sites send DNS through a DNS Forwarding Proxy, NIOS or third-party forwarders, or anycast for external networks; Infoblox Endpoint carries roaming devices.

02
Where the verdict is applied

Resolvers

Threat Defense Cloud resolution points

Infoblox’s status page lists 16 resolution points, Mumbai and Hyderabad among them; a lookup to a blocked domain gets a block or redirect instead of an address.

03
Enforcement on your own DNS servers

On-prem

Threat Defense for NIOS

Estates that run Infoblox NIOS can enforce the same policy on those appliances on site, and mix it with the cloud service under one token agreement.

04
Where policy, logs and investigations live

Portal

Infoblox Portal and reporting

Policies, feeds, custom lists and the 60-day Historical Data Viewer sit in the Infoblox Portal, hosted in North America or Europe; exports need Reporting Tokens.

Queries forwarded from sites, NIOS or Infoblox Endpoint — blocked at Infoblox resolvers, Mumbai and Hyderabad included.

Part 03 · Evaluate

Twelve capabilities. Resolve, detect, act.

Infoblox Threat Defense blocks malicious domains at the lookup, so the connection never starts.

Resolve
Resolver

One secure resolver for the estate

Every query from offices, devices and workloads goes through Infoblox’s resolver, and each one is written to a DNS query log.

Resolve
Hybrid

Cloud and NIOS under one deal

Threat Defense Cloud and Threat Defense for NIOS can be mixed in one token agreement, so branches and data centres share policy.

Resolve
Endpoint

Laptops and phones off the network

Infoblox Endpoint steers a device’s DNS to Threat Defense on any network; Windows 10 is limited and cloud VMs are not supported.

Resolve
Detection Mode

Watch first, block later

Detection Mode reports threats with no change to your infrastructure, Microsoft DNS included, before any blocking is switched on.

Detect
Tunnelling

Data smuggled out through DNS

Analytics look for DNS tunnelling and exfiltration, where malware hides stolen data or commands inside ordinary-looking lookups.

Detect
DGA

Domains nobody has seen before

Domain-generation-algorithm and zero-day domain detection catch freshly registered names that no blocklist carries yet.

Detect
TDS

The routers behind phishing kits

Threat Defense detects traffic distribution systems (TDS), and Infoblox says it tracks over 204,000 threat-actor clusters.

Detect
GenAI apps

Which AI tools staff actually use

The Advanced tier discovers applications from DNS, telling consumer and enterprise versions of generative-AI apps apart.

Act
DoH feeds

Close the encrypted-DNS bypass

Public_DoH and Public_DoH_IP feeds come with every subscription and stop browsers quietly using a public DoH resolver.

Act
Lookalikes

Fake versions of your brand

Lookalike domain monitoring, a Security-Token add-on, flags imitations of your domains, with a takedown service behind it.

Act
Dossier

Context on any domain or IP

Dossier, licensed from the same Security Token pool, pulls Infoblox’s intelligence on an indicator into one investigation view.

Act
IQ

AI help for the security team

IQ for Threat Defense, generally available since June 2026, is an add-on licensed as a percentage of your Cloud Security Tokens.

See it, don’t just read it

Watch Infoblox Threat Defense in action

Detection Mode on Microsoft DNS, the IQ for Threat Defense add-on, roaming protection beside the Zscaler agent, and an investigation with custom lists. All from Infoblox’s official channel, 2025–2026.

Infoblox (official)·Demo, 2026

Microsoft DNS for Infoblox Threat Defense™ Detection Mode

How Detection Mode reads threats from Microsoft DNS without changing how your network resolves names.

Infoblox (official)·Overview, 2026

Infoblox IQ for Threat Defense

The AI add-on that went generally available in June 2026, licensed as a share of your Cloud Security Tokens.

Infoblox (official)·Demo, 2025

Protect Roaming Users with Infoblox + Zscaler Dual Agent

Running Infoblox Endpoint beside the Zscaler agent so roaming laptops keep DNS protection.

Infoblox (official)·Demo, 2025

Infoblox Threat Defense™: Investigating SOC Insights and Mitigating Threats Using Custom Lists

A 2025 walkthrough of working a finding in the portal and blocking it with a custom list.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Infoblox Threat Defense

Malware calls home by name first. Threat Defense answers it with a block.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Blocking before the connection exists

Malware callbacks, phishing pages and command servers usually need a DNS lookup first. Threat Defense answers that lookup with a block or a redirect, so the connection never starts, on any port or protocol. Infoblox says this stops 90% of threats before the first query and spots threats 68 days earlier on average.

02

Cloud, on site and on the device, in one policy

Few DNS filters also run on your own DNS servers. Threat Defense Cloud needs no Infoblox hardware, Threat Defense for NIOS enforces on Infoblox appliances, and Infoblox Endpoint covers roaming devices; one token agreement can mix them. That suits estates where DNS is already an Infoblox service.

03

Licensed by what you protect, not by headcount

Infoblox dropped per-user (FTE) licensing. Threat Defense Cloud counts three Security Tokens for each device, server or workload sending DNS queries, takes a daily snapshot and compares a rolling three-month average with what you bought. It does not shut off when you run over.

04

Where it stops

It sees domains, not content: there is no web proxy, no TLS inspection and no CASB, so it does not replace a secure web gateway. There is no public price. Lookups resolve in Mumbai and Hyderabad, but the portal and its logs are hosted in North America or Europe, and the viewer keeps 60 days.

The idea
Block malicious domains at the lookup
The reach
Cloud, NIOS on site and Infoblox Endpoint
The price
Quote; three Security Tokens per asset
Proof, not promises

The numbers behind the platform

3 tokens
the Security Tokens Threat Defense Cloud counts for each protected device, server or workload
— Vendor
16 PoPs
DNS resolution points on Infoblox’s status page, Mumbai and Hyderabad among them
— Vendor
60 days
of query history in the Historical Data Viewer before you need an export
— Vendor
68 days
how much earlier than other tools Infoblox says it detects threats, on average
— Vendor claim
90%
of threats Infoblox says are blocked before the first query is ever made
— Vendor claim
40 tokens
Reporting Tokens for every 10 million DNS log entries exported in a month
— Vendor

What your Infoblox Threat Defense rollout looks like

Week 1Model

Map every DNS path

List which resolvers offices, data centres, roaming laptops and cloud workloads use today, and where NIOS already runs.

Week 2Pilot

Run Detection Mode

Turn on Detection Mode, Microsoft DNS included, and let it report threats for a few weeks without blocking anything.

Week 4Decide

Count assets, size tokens

Count devices, servers and workloads that send DNS queries, apply three tokens each, and add Reporting Tokens for logs.

Month 2Prove

Block, then add roaming

Switch policies to block at one site, add the Public_DoH feeds, then roll Infoblox Endpoint out to roaming devices.

Month 3Commit

Wire up logs and response

Export DNS logs to your SIEM for 180-day retention, and decide whether Dossier or IQ add-ons earn their tokens.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.2
58+ reviews*
84% would recommend
Threat detection4.5
Hybrid deployment4.4
Roaming coverage4.1
Reporting and logs3.8
Value for money3.7
5★
46%
4★
35%
3★
12%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“Detection Mode ran against our Microsoft DNS for a month before we blocked anything. The report sold the purchase internally.”
Security Architect
BFSI
Manufacturing
“We already ran NIOS in the data centres, so enforcing on those appliances and adding the cloud for branches was one policy.”
Network Manager
Manufacturing
IT Services
“It caught a DNS-tunnelling beacon on a build server that our firewall logs showed only as normal port 53 traffic.”
SOC Lead
IT Services
Retail
“Counting tokens per device instead of per employee helped us, because half our assets are kiosks and sensors with no user.”
IT Procurement Lead
Retail
Healthcare
“Sixty days in the viewer is not enough for our auditors, so we budgeted Reporting Tokens and push everything to the SIEM.”
Compliance Manager
Healthcare
Education
“Good at blocking domains, but it is not a web gateway. We still needed a proxy for file scanning and upload control.”
Head of Infrastructure
Education
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the protective DNS market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Protective DNS Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Infoblox Threat DefenseThis page

Quote only; three Security Tokens per protected asset.

Grid 02 · The architecture

Enforcement Reach × Detection Depth

The grid nobody publishes — how many places a product can enforce DNS policy vs how deeply it analyses what the lookups reveal.

Deep but narrowBroad and deepPoint filtersWide but shallow
Infoblox Threat DefenseThis page

Cloud, NIOS, Endpoint and anycast; tunnelling, DGA and TDS.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Infoblox Threat Defense vs the DNS security field

Against Cisco Umbrella, Cloudflare One Gateway, Palo Alto Advanced DNS Security, N-able DNS Filtering and AWS Route 53 Resolver DNS Firewall — on deployment, inspection depth, encrypted-DNS bypass, roaming, detection, price, logs and India.

DimensionInfoblox Threat DefenseCisco UmbrellaCloudflare One GatewayPalo Alto Advanced DNS SecurityN-able DNS FilteringAWS Route 53 Resolver DNS Firewall
What it isProtective DNS serviceDNS tiers, then SIGGateway inside SSEDNS service + ResolverMSP DNS filterVPC DNS filter
DeploymentCloud, NIOS or agentResolver change, clientLocations, WARP, tunnelsForwarder or NGFWSite IP, relay or agentRule groups per VPC
Layer, TLS and CASBDNS onlyProxy at SIG tiersFull TLS, CASB both waysDNS layer onlyDomains onlyDNS queries only
Encrypted DNS bypassPublic_DoH feedsDoH categoryPer-location DoH/DoTDoH and DoT acceptedDoT; DoH needs firewallResolver traffic only
Roaming devicesInfoblox EndpointRoaming clientWARP clientPrisma Agent onlyWindows and macOSNot applicable
Threat detectionTunnels, DGA, TDSTalos + OpenDNS dataNetwork-wide intelQuery and responseDNSFilter categoriesManaged lists, Advanced
Pricing modelSecurity TokensPer user, tieredPer user, listedPer user or per deviceQuoted to MSPsPay per query
Published entry priceQuote only~$30–40/user/yrFree to 50, then $7Not publishedNot published$0.60 per million
Included vs add-onAdd-ons on tokensProxy a tier upDNS, HTTP, networkSeparate SKUsDNS filter onlyAdvanced costs extra
Scale and limits17,000+ named estateVerified large estatesVerified large estates5,000 queries/user/dayNot verified at scalePer VPC, per Region
Logs and retention60 days, then exportNot verified hereLonger on EnterpriseFollows tenant region9 daysYour own destination
India presenceResolvers in, portal outMumbai and ChennaiSix Indian citiesCountry, not cityNo Indian cityMumbai and Hyderabad
Lock-in and exitEasy in cloud, not NIOSRepoint and uninstallGrows with HTTP useRe-point forwardersTied to N-able toolsAWS only
Best fitInfoblox DNS estatesDNS now, SIG laterListed-price inspectionPalo Alto shopsMSP-managed clientsAWS workloads
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Infoblox Threat Defense if…

  • ✓Your DNS already runs on Infoblox NIOS and you want threat blocking enforced there and in the cloud under one agreement
  • ✓You need DNS-layer detection of tunnelling, DGA and lookalike domains across offices, roaming devices and workloads
  • ✓You would rather license per protected asset than per employee, because many of your devices have no user

Compare alternatives if…

  • ✓You need TLS inspection, file scanning or a CASB — Cloudflare One and Cisco’s SIG tiers add a proxy
  • ✓You want a price before a sales call — Cloudflare and AWS DNS Firewall both publish theirs
  • ✓Your logs must be stored in India — the Infoblox Portal is hosted in North America or Europe only

Do not expect…

  • ✓A web proxy, TLS decryption or CASB inside Threat Defense
  • ✓A published token price, or a per-user licence
  • ✓More than 60 days of history in the viewer without Reporting Tokens and an export

Infoblox Threat Defense is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does chasing DNS-borne threats cost you?

Drag the sliders (devices and workloads protected; security analyst-hour cost). Estimates model analyst time spent chasing malware callbacks, phishing clicks and DNS-tunnel alerts at an assumed 1.5 hours per device a year, with 70% of it removed by blocking malicious domains at resolution. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual threat-triage cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. Infoblox publishes no price for Threat Defense, and the AWS and Azure marketplaces sell it by private offer. Licensing is token-based, not per user: Threat Defense Cloud counts three Security Tokens per protected device, server or workload, measured as a rolling three-month average, while Threat Defense for NIOS counts by appliance model. IQ for Threat Defense, Dossier and lookalike monitoring draw on the same Security Tokens, and exporting DNS logs needs Reporting Tokens (40 per 10 million entries a month). TechBag counts your assets first, then quotes in INR with GST.

Threat Defense Cloud

Best for sites, roaming users and workloads

  • Three Security Tokens per protected asset
  • Resolution in Mumbai and Hyderabad
  • Needs no Infoblox DNS servers

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Threat Defense for NIOS

Best for estates already running Infoblox DNS

  • Enforced on your NIOS appliances on site
  • Tokens counted by appliance model
  • Mixable with Cloud in one agreement

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Asset count

How many devices, servers and workloads send DNS queries? At three tokens each, this number drives the quote.

2
Deployment

Will you enforce in the cloud, on NIOS appliances on site, or both under one token agreement?

3
Roaming

Do your laptops and phones run an OS Infoblox Endpoint supports? Windows 10 is limited and cloud VMs are excluded.

4
Bypass

Are the Public_DoH feeds switched on, and does the firewall stop devices reaching outside resolvers directly?

5
Log retention

The viewer keeps 60 days; how will you export logs to keep the 180 days CERT-In requires, and at what token cost?

6
Data location

Is it acceptable that the portal and logs sit in North America or Europe while resolution happens in India?

7
Web inspection

Do you also need TLS inspection, file scanning or a CASB? Threat Defense has none, so plan a proxy if so.

8
Add-ons

Does the quote itemise IQ, Dossier, lookalike monitoring and Reporting Tokens, in INR with GST?

FAQ

Questions buyers ask

It is Infoblox’s protective DNS service, formerly BloxOne Threat Defense. DNS queries from your networks, devices and workloads go to Infoblox’s resolvers or your NIOS servers, are checked against Infoblox threat intelligence and analytics, and lookups for malicious domains are blocked or redirected before a connection starts.

Ready to evaluate Infoblox Threat Defense?

Count the devices and workloads that send DNS queries first, or let a TechBag advisor run a Detection Mode pilot, size your tokens and plan the log export.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.