A user clicks a fake courier link on hotel Wi-Fi. The domain shouldn’t even resolve — N-able DNS Filtering refuses phishing, malware and policy-blocked domains at lookup for whole sites, and Windows and macOS roaming clients keep that policy on laptops wherever they connect — built on technology licensed from DNSFilter.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers N-able DNS Filtering — the standalone DNS-layer filter built on licensed DNSFilter technology. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A filtering resolver refuses to turn a bad domain into an address, so the connection never starts.
What consolidation actually replaces, dimension by dimension.
| Dimension | The ISP’s resolver and no policy | N-able DNS Filtering |
|---|---|---|
| Where lookups go | Whatever resolver the ISP hands out | Filtering resolvers you set per site |
| A phishing domain | Resolves, and the page loads | Refused at lookup, with a block page |
| Laptops at home | No policy once they leave the office | Windows and macOS roaming clients |
| Per-person rules | One rule for every IP address | AD or Entra ID users and groups |
| Evidence for an audit | None kept anywhere | Query logs and reports, exported for retention |
| What it is NOT | — | TLS inspection, CASB or a published price |
The cheapest test is one client site: point its DNS at the resolvers in monitor mode for a week and read what would have been blocked.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Sites and agents send DNS to filtering resolvers on what N-able calls a global Anycast network; a blocked domain gets a block page instead of an address.
Point an office’s public IP at the resolvers, or run a relay on VMware ESXi, Hyper-V, VirtualBox, Docker or a cloud image to apply policy by LAN subnet.
A roaming client intercepts DNS on the device and applies the assigned policy at home, on hotel Wi-Fi or on a hotspot, and can send its lookups over DNS over TLS.
Policies combine categories, threats, AppAware and allow or block lists, applied per site, per user or per agent, with scheduled reports and an admin audit log.
Filtering resolvers on an Anycast network — sites point their DNS at them, laptops carry a roaming client.
N-able DNS Filtering stops a bad domain from ever resolving, on every site and every roaming laptop you manage.
Phishing, malware and botnet domains are refused before a connection opens, and N-able claims a 10-day lead over traditional feeds.
Block whole categories such as social networking or P2P, force SafeSearch, and keep your own allow and block lists per policy.
AppAware blocks an application’s full domain list at once, so Discord, TeamViewer or Facebook can go without hunting domains.
Windows and macOS roaming clients filter DNS wherever the laptop connects, and can carry lookups to the resolvers over DNS over TLS.
A relay on ESXi, Hyper-V, VirtualBox or Docker resolves internal domains locally and applies different policy to each LAN subnet.
N-able ships a script that installs the Windows agent from either RMM and a monitor that checks the agent is bound to port 53.
Active Directory and Entra ID sync map lookups to people, so policy and reports can follow a user rather than an IP address.
Scheduled reports go to each client, and the query log can be exported; plan a SIEM copy if you need 180 days on file.
An administrative audit log records policy edits, and the console supports single sign-on and multi-factor sign-in for admins.
A 2025 N-able webinar on protective DNS with a live demo, plus three short N-able U walkthroughs from 2023: what the product is, building a policy and adding a site. All from N-able’s official channels.
An N-able webinar with DNSFilter’s partner evangelist on DNS-borne phishing, with a live demo.
What the standalone product is, how its filtering is structured and how a lookup gets judged.
Building a policy from categories, SafeSearch, threats, AppAware and allow or block domains.
Adding a client site by name, address and public IP, then attaching a policy to it.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
A resolver change at each site and a light agent on laptops: no certificate on every device, nothing in the traffic path. For an MSP with dozens of small clients, that is a control live this week rather than a proxy project nobody schedules. N-able ships install and monitor scripts for its RMMs.
The filtering is DNSFilter’s, under licence, at the feature level of its former Pro plan. N-able adds the wrapper: one vendor, contract and support line beside N-central, N-sight, Cove and its security stack. If you already buy N-able, that is the argument; if not, compare DNSFilter direct.
Active Directory and Entra ID sync tie lookups to people, so finance and the warehouse get different policies and reports name who hit a phishing domain. A relay adds subnet policy inside an office. N-able rates the sync at 500,000 users: a capacity claim, not a reference.
It sees domains, never content: no TLS inspection, file scanning or CASB. Browsers using their own DNS-over-HTTPS route round it unless the firewall blocks DoH providers. N-able prints no price, licence unit or Indian resolver city, and DNSFilter’s Plus-only features may be missing.
Get the licence unit, term and feature list in writing, and confirm which DNSFilter Pro features your quote includes.
Run lookups from each office to the Anycast addresses and compare latency with your current resolver before you commit.
Point one site at the resolvers, push agents from your RMM, and log what the policy would block before enforcing it.
Block known DoH providers and outbound port 53 at the firewall, block VPN and proxy domains, and test from a laptop.
Enforce across sites, install the block-page certificate, and export query logs to a SIEM so 180 days are on file.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We pushed the Windows agent to 600 laptops across 30 clients from N-central in an afternoon and saw blocks the same day.”
“A clerk clicked a fake courier link on a hotel network; the roaming client refused the domain before the page could load.”
“AppAware let us block one remote-access tool without touching anything else. Doing that by domain list used to take an hour.”
“Chrome on a few machines was using its own encrypted DNS. Blocking known DoH providers on the firewall closed the gap.”
“Query logs roll off fast, so we export them nightly to our SIEM. Plan that before an auditor asks for six months.”
“It does the job, but we had to ask N-able for a quote and the licence unit before we could even budget a pilot.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the secure web and DNS market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote only; no published unit or rate.
The grid nobody publishes — how little you must deploy to switch it on vs how far inside the traffic it can see.
Resolver change or a light agent; domains only.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against DNSFilter, Cisco Umbrella, Cloudflare One (Gateway), OpenText Core DNS Protection and Zscaler Internet Access — on deployment, encrypted-DNS bypass, price, inspection depth, logs, India resolvers and exit.
| Dimension | N-able DNS Filtering | DNSFilter | Cisco Umbrella | Cloudflare One (Gateway) | OpenText Core DNS Protection | Zscaler Internet Access |
|---|---|---|---|---|---|---|
| What it is | Licensed DNSFilter tech | The source engine | DNS tiers, SIG above | Gateway in a SASE | Ex-Webroot DNS filter | Inline proxy, not DNS |
| Deployment and roaming | Site, relay, agents | Five agent platforms | DNS change + client | Resolver IPs or WARP | Windows agent only | Connector or tunnels |
| Encrypted DNS and bypass | DoT; DoH via firewall | Same documented steps | DoH/DoT category | Per-location DoH | Agent blocks 53/443/853 | DoH seen in the proxy |
| Pricing model | Quoted; unit unstated | Per licence, monthly | Per user, four tiers | Per user, monthly | Per site, quoted | Per user, editions |
| Published entry price | Not published | $1/licence/month | ~$30–40/user/year | Free, then $7/user/mo | Not published | ~$6–12/user/month |
| Included vs add-on | Pro-level features | Roaming from Plus | Proxy at SIG tiers | DNS even when free | One SKU, all features | Depth by edition |
| Scale | 500k-user sync, claimed | 80+ data centres | Large estates | 330+ city network | SMB and MSP scale | 500B+ transactions/day |
| Inspection depth | Domains only | Domains only | Selective proxy at SIG | Full TLS, inline + API | Domains only | Full inline + CASB |
| Integrations | N-central, N-sight, AD | API, SIEM, OIDC | Cisco and Meraki | One Cloudflare console | RMM, PSA hooks | Zero Trust Exchange |
| Governance and logs | Short query logs | 9 days; 90 on Plus | Logs to S3 | 24 h free, 30 days paid | 13-month reports | SIEM streaming |
| India resolver or PoP | No city documented | Regions, no cities | Mumbai and Chennai | Six Indian cities | Not documented | Four Indian cities |
| Support and trial | Free trial, length n/a | 14-day trial | Free trial | Free to 50 users | 30-day trial | Trial on request |
| Lock-in and exit | Repoint DNS first | Change resolvers | Repoint DNS | Monthly, no term | Agent reverts DNS | Tunnels and client |
| Best fit | N-able MSPs | Price-led DNS buyers | DNS now, proxy later | Free start, India PoPs | Windows-heavy MSPs | Content, not domains |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
N-able DNS Filtering is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (users you filter; IT staff-hour cost). Estimates model the staff time spent cleaning up after phishing clicks and malware from web lookups, at an assumed 1.5 hours per user a year, with 70% of it avoided by blocking bad domains at lookup. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. N-able publishes no price and no licence unit for the standalone DNS Filtering product; its page offers a demo, a call with a specialist or a free trial. DNSFilter, whose technology N-able licenses, prints its own rates (Core from $1.00 a licence a month billed yearly), but those are DNSFilter’s plans, not N-able’s, and N-able’s version matches DNSFilter’s older Pro licence. No rupee price is published. TechBag gets the unit, term and feature list in writing first, then quotes in INR with GST.
Best for offices behind one public IP
Best for a broader rollout
Best for laptops that leave the office
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Is the quote per user, per device or per site, and what is the minimum term? N-able publishes neither.
Which DNSFilter features does your licence carry? N-able’s matches the Pro plan, not DNSFilter’s newer Plus plan.
Which devices roam? Windows and macOS agents are documented; get Android and iOS support confirmed in writing.
Can your firewall block known DoH providers and outbound port 53, so browsers cannot route round the resolver?
Where do lookups from your Indian offices resolve? No Indian city is documented, so measure before you sign.
How will you hold 180 days of logs for CERT-In when the platform keeps query logs 9 days? Plan the export.
Will you deploy the block-page certificate? Without it users see a certificate error rather than a block notice.
Do you have a fallback resolver ready? Cancelling stops the resolvers answering, which cuts sites off the internet.
Measure resolver latency from your Indian offices first, or let a TechBag advisor scope a monitor-mode pilot, plan the DoH lock-down and get the licence itemised in INR.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.