A laptop on hotel Wi-Fi, a browser with its own encrypted resolver. Your firewall never sees the lookup — OpenText Core DNS Protection, formerly Webroot DNS Protection, checks every lookup against 78 categories — through a Windows agent that speaks DoH, or by forwarding a whole site’s DNS to its resolvers.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers OpenText Core DNS Protection — DNS filtering for devices and networks, formerly Webroot DNS Protection. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Every connection starts with a DNS lookup. A filtering resolver refuses to answer for malicious or unwanted domains, so the connection never starts.
What consolidation actually replaces, dimension by dimension.
| Dimension | Router DNS and firewall rules | OpenText Core DNS Protection |
|---|---|---|
| A browser using its own DoH resolver | Lookups bypass the firewall unseen | Leak Prevention blocks DoH and DoT side doors |
| A laptop working from home | Unfiltered once off the office network | The Windows agent filters it on any network |
| Printers, phones and guest Wi-Fi | Need an agent each, so get none | Covered by forwarding the site’s DNS |
| A domain wrongly blocked | Edit each firewall or router by hand | One override, global or per site, in ~15 minutes |
| Who looked up what, last quarter | Router logs, if anyone kept them | 13 months of category reports in the console |
| What it is NOT | — | A proxy, TLS inspection, CASB, or a listed Indian resolver |
The cheapest test is the 30-day trial: forward one office’s DNS, put the agent on ten laptops, and read the security-risk report a week later.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
The agent points the adapter at loopback, sends outside lookups to the resolvers over DoH, and leaves Active Directory names to your local DNS servers.
Register a site’s public IP, or a dynamic-DNS name, then set the router or Windows DNS forwarders to the primary and secondary resolvers for your region.
Resolvers answer on port 53 or DoH and check each domain against BrightCloud categories; a 2020 datasheet says they are hosted on Google Cloud.
One console per site holds DNS policies, allow and block overrides, privacy settings and reports, beside Core Endpoint Protection where it is also used.
A Windows agent or a site forwarder — every lookup goes to filtering resolvers, every policy lives in one console.
OpenText Core DNS Protection stops bad domains at the lookup, on the laptop or across the whole site.
Malware sites, phishing and fraud, botnets, spyware and adware, keyloggers, proxy avoidance and spam URLs are blocked by policy.
Gambling, adult, streaming, social and dozens more sit beside the security set; High and Medium starter policies are provided.
DNS rewrites force SafeSearch on Google, Bing and DuckDuckGo, and YouTube Restricted Mode in a moderate or strict setting.
The Windows agent sends outside lookups over DoH and reverts any change to the adapter’s DNS settings while its service runs.
Blocks plain DNS, known DoH providers and DoT so every lookup is filtered; it needs agent 4.2 or later on Windows 10 or newer.
Register a static IP or a dynamic-DNS name and forward to the resolvers; phones, printers and guest Wi-Fi are then filtered too.
Global, site or policy overrides take wildcards and up to 50 domains an entry; changes apply within about 15 minutes.
Category reports keep 13 months, top blocked and requested domains 90 days, and the security-risk view 30 days.
Hide User Information masks names in logs, Local Echo copies lookups to your own resolver, and Fail Open keeps DNS up in an outage.
Dynamic DNS detection, Leak Prevention, the MSP case and an engineering deep dive — all from the official Webroot channel, recorded between 2021 and 2024 under the former Webroot DNS Protection name.
How the service spots unapproved authoritative DNS servers, filmed under the former Webroot name.
The setting that blocks plain DNS, DoH and DoT around the agent, shown in 2024 before the OpenText rebrand.
Why the product was designed for managed service providers, from the Webroot era.
An hour-long engineering session on the agent, resolvers and policies, recorded under the Webroot brand.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Browsers and apps now send lookups over DoH, which a firewall cannot read. The agent sends its own queries to the resolvers over DoH, and Leak Prevention shuts plain DNS, known DoH providers and DoT around it, so a browser’s private resolver cannot skip the policy. It needs agent 4.2+ on Windows 10 or newer.
Laptops get the Windows agent, deployed by MSI or switched on in a Core Endpoint Protection policy. Everything else on a site — phones, printers, guests, cameras — is covered by registering the office’s public IP and forwarding DNS to the resolvers. Both draw on the same categories, overrides and reports in one console.
The console’s MSP view has a site list, global overrides every site can inherit, and per-site keycodes and trials. One MSP quoted on OpenText’s page says its clients’ help-desk calls fell by almost 40%. Logs can hide user names, or be echoed to a local resolver for a SIEM.
It filters by domain only: no proxy, no TLS inspection, no CASB. The documented agent is Windows; Macs and phones rely on network forwarding. No price or Indian resolver is published. OpenText keeps its SMB and consumer security line, which includes this product, outside its core and is divesting non-core units; ask about the roadmap.
Count Windows laptops, other devices and each site’s public IP or dynamic-DNS name, and note your Active Directory domains.
Choose each site’s region in the console, run nslookup against both resolvers, and ask OpenText where they are hosted.
Start the 30-day trial, apply the High policy, add AD domains to the bypass list and deploy the agent to a pilot group.
Turn on Leak Prevention, add allow overrides for blocked business apps, and check the security-risk report daily.
Point each site’s forwarders at the resolvers, roll the agent out through endpoint policy, and schedule monthly reports.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We turned on DNS in the endpoint policy and the agent rolled out with the next check-in. No separate deployment project at all.”
“Leak Prevention ended the problem of browsers using their own DoH resolver. Our block page finally shows up on every laptop.”
“Guest Wi-Fi and the CCTV recorders are filtered by forwarding alone. We registered the office IP and changed two forwarders.”
“Global overrides save us hours: one allow entry for a client’s accounting portal reaches all forty sites within fifteen minutes.”
“Thirteen months of category history settled an HR question about streaming at work that a 30-day log never could have.”
“Fine for Windows, but our Mac designers are only covered in the office. Off-site they need another tool, so plan for that.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the secure web and DNS market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quoted, usually by an MSP; no price published.
The grid nobody publishes — how easily you can buy and switch it on alone vs how deep into the traffic it can see.
DNS only; Windows agent or forwarding, sold standalone.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Cisco Umbrella, Cloudflare One Gateway, Zscaler Internet Access, Netskope Next Gen SWG and Palo Alto DNS Security — on layer, roaming, encrypted DNS, price, logs and India.
| Dimension | OpenText Core DNS Protection | Cisco Umbrella | Cloudflare One (Gateway) | Zscaler Internet Access | Netskope Next Gen SWG | Palo Alto DNS Security |
|---|---|---|---|---|---|---|
| What it is | MSP-sold DNS filter | DNS layer, then SIG | DNS inside a SASE | Cloud proxy first | Instance-aware proxy | Firewall subscription |
| Enforcement layer | DNS only | DNS, proxy at SIG | DNS, HTTP, network | Full inline proxy | Full inline proxy | DNS on the firewall |
| Deployment and roaming | Windows agent + forward | Point DNS + client | Resolver IPs or WARP | Client or tunnels | Client or tunnels | Needs the platform |
| Encrypted DNS control | Blocks 53, DoH, DoT | DoH/DoT category | Own DoH and DoT | Inspects DoH inline | Tunnel blocking | Firewall policy |
| Categories and intelligence | 78 BrightCloud cats | Talos + OpenDNS | Cloudflare network | Zero Trust Exchange | App-instance aware | DGA and tunnelling |
| Pricing model | Quoted, often by MSP | Per user, by tier | Per user a month | Per user, by edition | Per user, platform | Per firewall SKU |
| Published entry price | Not published | ~$30–40/user/year | Free; then $7/user/mo | ~$6–12/user/month | Not published | Not published |
| Included vs add-on | All features inside | Proxy at higher tiers | DNS in the free tier | Editions add depth | Modules by licence | Separate SKUs |
| Reporting and logs | Up to 13 months | Export to S3 | 24 h free; 30 days paid | Stream to your SIEM | Stream to your SIEM | On firewall or cloud |
| Integrations and admin | MSP console, API | Cisco and Meraki | Cloudflare One stack | Zero Trust Exchange | Netskope One stack | Strata management |
| India resolver or PoP | Not documented | Chennai, Mumbai sites | Six Indian cities | Indian data centres | Mumbai, Chennai, Delhi | Your own firewall |
| Support and trial | 30-day trial | Free trial | Free up to 50 users | Trial on request | Trial on request | Partner evaluation |
| Lock-in and exit | Stop service, reverts | Repoint DNS | Monthly, change DNS | Unwind tunnels, client | Platform-bound | Tied to firewalls |
| Best fit | MSPs with Windows fleets | Start at DNS, grow | Price-led, India-near | Deep inspection | SaaS tenant control | Palo Alto estates |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
OpenText Core DNS Protection is one of 44 secure web & dns products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (users whose devices are filtered; admin-hour cost). Estimates model IT time spent cleaning up after malicious-site visits, chasing unfiltered encrypted lookups and editing router blocklists by hand, at an assumed 1.5 hours per user a year, with 70% of it removed by DNS-layer blocking and central overrides. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. OpenText publishes no price and no licence unit for Core DNS Protection: a site is switched on in the console with a paid keycode or a 30-day trial, and most buyers are quoted by OpenText or their MSP. Third-party listings show seat bundles that OpenText does not confirm. TechBag counts sites and devices first, then quotes in INR with GST.
Best for proving it on one site
Best for a broader rollout
Best for MSP-run multi-site estates
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
How many devices are Windows laptops that roam, and how will Macs and phones be filtered when they leave the office?
Are endpoints on Windows 10 or newer with agent 4.2+, so Leak Prevention can block DNS, DoH and DoT side doors?
Which resolver region will each site use? OpenText documents no Indian location, so measure latency before rollout.
Which internal domains must go on the bypass list so the agent hands them to your local DNS servers?
Does the brief need content inspection or CASB? If so, DNS filtering alone will not meet it — price a proxy too.
Should user names be hidden in logs, and does your SIEM need lookups echoed to a local resolver?
OpenText treats SMB and consumer security as non-core. What does the contract say if the product changes owner?
Does the quote state the licence unit, term, currency and support route? Ask about INR billing and add GST.
Count your sites and Windows devices first, or let a TechBag advisor test the resolvers from your offices, run the pilot with Leak Prevention on and get the quote in INR.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.