Talk to us
by OpenTextTechBag Intel Page

OpenText Core DNS Protection

A laptop on hotel Wi-Fi, a browser with its own encrypted resolver. Your firewall never sees the lookup — OpenText Core DNS Protection, formerly Webroot DNS Protection, checks every lookup against 78 categories — through a Windows agent that speaks DoH, or by forwarding a whole site’s DNS to its resolvers.

78 categories, seven for securityWindows DoH agent or site forwardingQuoted; no Indian resolver documented

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
OpenText prints no price or licence unit; a partner or MSP quotes it
Quote
Reviews
The Software Advice score, from 55 reviews, shown on OpenText’s product page
4.5 / 5
Categories
Domain categories in a DNS policy, seven of them security risks
78
India
No Indian resolver location appears in OpenText’s public documentation
Not listed

Quick answer

OpenText Core DNS Protection, formerly Webroot DNS Protection, filters every DNS lookup against 78 BrightCloud categories, seven of them security risks. A Windows agent sends queries over DoH and can block rival DNS on ports 53, 443 and 853; networks are covered by forwarding to its resolvers. It is quoted, mostly through MSPs, and OpenText documents no Indian resolver location. Read more ↓ Show less ↑
Part 01 · Orient

The OpenText platform family

This page covers OpenText Core DNS Protection — DNS filtering for devices and networks, formerly Webroot DNS Protection. The rest:

OpenText Content Management
Enterprise content management, formerly Extended ECM.
View page →
OpenText Fortify
Application security testing: SAST, DAST and SCA.
View page →
NetIQ Identity Governance
Access reviews, provisioning and identity lifecycle.
View page →
NetIQ Access Manager
Single sign-on, federation and adaptive MFA.
View page →
NetIQ Privileged Access Manager
Privileged session control and credential vaulting.
View page →
OpenText Voltage SecureData
Format-preserving encryption and tokenisation.
View page →
OpenText Enterprise Security Manager
Real-time SIEM correlation, formerly ArcSight.
View page →
OpenText Service Management
ITSM and asset management, formerly SMAX.
View page →
OpenText AI Operations Management
Event and performance monitoring, formerly Operations Bridge.
View page →
OpenText ZENworks
Endpoint management, patching and disk encryption.
View page →
OpenText Data Protector
Enterprise backup for servers, VMs and applications.
View page →
OpenText Availability
Real-time replication and failover, formerly Carbonite.
View page →
OpenText Cloudally Backup
Microsoft 365, Google, Salesforce, Box and Dropbox backup.
View page →
OpenText Performance Engineering
Load and performance testing, formerly LoadRunner.
View page →
OpenText Functional Testing
Automated functional testing, formerly UFT One.
View page →
OpenText Core Endpoint Protection
Cloud endpoint security for SMBs and MSPs, ex-Webroot.
View page →
OpenText Core DNS Protection
This page.
You’re here
OpenText Core Email Threat Protection
Email security and encryption, ex-Zix.
View page →

Quick facts

30-second orientation
Product
Cloud DNS filtering for devices and networks, run from the OpenText management console
Maker
Open Text Corporation, Waterloo, Ontario; NASDAQ and TSX: OTEX; CEO Ayman Antoun since April 2026
Lineage
Built as Webroot DNS Protection; Webroot joined Carbonite in 2019, then OpenText bought Carbonite
Price
Not published: quoted by OpenText or an MSP; a 30-day trial runs from the console
Coverage
Windows agent for roaming devices; any device on a network that forwards DNS to the resolvers
Encrypted DNS
The agent resolves over DoH and can block other DNS on ports 53, 443 (known DoH) and 853
Categories
78 BrightCloud categories, seven of them security risks such as malware, botnets and spyware
Reporting
Category history kept 13 months; top blocked and requested domains 90 days
India
No Indian resolver location is published; ask which resolvers your offices would use
In India via
TechBag — site and user sizing, pilot design, quote in INR with GST, MSP hand-off
Part 02 · Learn

Understand DNS filtering before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is DNS filtering?

Every connection starts with a DNS lookup. A filtering resolver refuses to answer for malicious or unwanted domains, so the connection never starts.

Router DNS and firewall rules vs OpenText Core DNS Protection — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionRouter DNS and firewall rulesOpenText Core DNS Protection
A browser using its own DoH resolverLookups bypass the firewall unseenLeak Prevention blocks DoH and DoT side doors
A laptop working from homeUnfiltered once off the office networkThe Windows agent filters it on any network
Printers, phones and guest Wi-FiNeed an agent each, so get noneCovered by forwarding the site’s DNS
A domain wrongly blockedEdit each firewall or router by handOne override, global or per site, in ~15 minutes
Who looked up what, last quarterRouter logs, if anyone kept them13 months of category reports in the console
What it is NOT—A proxy, TLS inspection, CASB, or a listed Indian resolver

The cheapest test is the 30-day trial: forward one office’s DNS, put the agent on ten laptops, and read the security-risk report a week later.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
How a roaming device is covered

Agent

Windows DNS Protection agent

The agent points the adapter at loopback, sends outside lookups to the resolvers over DoH, and leaves Active Directory names to your local DNS servers.

02
How everything else on a LAN is covered

Network

Registered sites and forwarders

Register a site’s public IP, or a dynamic-DNS name, then set the router or Windows DNS forwarders to the primary and secondary resolvers for your region.

03
Where each lookup is judged

Resolve

Filtering resolvers

Resolvers answer on port 53 or DoH and check each domain against BrightCloud categories; a 2020 datasheet says they are hosted on Google Cloud.

04
Where policy, overrides and reports live

Console

OpenText management console

One console per site holds DNS policies, allow and block overrides, privacy settings and reports, beside Core Endpoint Protection where it is also used.

A Windows agent or a site forwarder — every lookup goes to filtering resolvers, every policy lives in one console.

Part 03 · Evaluate

Nine capabilities. Filter, enforce, govern.

OpenText Core DNS Protection stops bad domains at the lookup, on the laptop or across the whole site.

Filter
Security risk

Seven threat categories

Malware sites, phishing and fraud, botnets, spyware and adware, keyloggers, proxy avoidance and spam URLs are blocked by policy.

Filter
Content

78 categories in all

Gambling, adult, streaming, social and dozens more sit beside the security set; High and Medium starter policies are provided.

Filter
SafeSearch

Search and YouTube locked down

DNS rewrites force SafeSearch on Google, Bing and DuckDuckGo, and YouTube Restricted Mode in a moderate or strict setting.

Enforce
DoH agent

Lookups leave encrypted

The Windows agent sends outside lookups over DoH and reverts any change to the adapter’s DNS settings while its service runs.

Enforce
Leak Prevention

No side doors on 53, 443, 853

Blocks plain DNS, known DoH providers and DoT so every lookup is filtered; it needs agent 4.2 or later on Windows 10 or newer.

Enforce
Network

Guests and IoT, no agent

Register a static IP or a dynamic-DNS name and forward to the resolvers; phones, printers and guest Wi-Fi are then filtered too.

Govern
Overrides

Allow and block lists

Global, site or policy overrides take wildcards and up to 50 domains an entry; changes apply within about 15 minutes.

Govern
Reports

Thirteen months of history

Category reports keep 13 months, top blocked and requested domains 90 days, and the security-risk view 30 days.

Govern
Privacy

Hide users, echo to the SIEM

Hide User Information masks names in logs, Local Echo copies lookups to your own resolver, and Fail Open keeps DNS up in an outage.

See it, don’t just read it

Watch OpenText Core DNS Protection in action

Dynamic DNS detection, Leak Prevention, the MSP case and an engineering deep dive — all from the official Webroot channel, recorded between 2021 and 2024 under the former Webroot DNS Protection name.

Webroot channel (official)·Feature demo, November 2024

DNS Protection's Dynamic DNS Detection

How the service spots unapproved authoritative DNS servers, filmed under the former Webroot name.

Webroot channel (official)·Feature demo, March 2024

Webroot DNS Leak Prevention

The setting that blocks plain DNS, DoH and DoT around the agent, shown in 2024 before the OpenText rebrand.

Webroot channel (official)·Overview, January 2021

Webroot DNS Protection: Purpose-built for MSPs

Why the product was designed for managed service providers, from the Webroot era.

Webroot channel (official)·Webinar, April 2021 (55 min)

Webroot DNS Protection: Technical Deep Dive

An hour-long engineering session on the agent, resolvers and policies, recorded under the Webroot brand.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why OpenText Core DNS Protection

Encrypted DNS is quietly routing around your filters. Core DNS Protection filters the lookup and shuts the side doors.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Encrypted DNS is filtered, not just blocked

Browsers and apps now send lookups over DoH, which a firewall cannot read. The agent sends its own queries to the resolvers over DoH, and Leak Prevention shuts plain DNS, known DoH providers and DoT around it, so a browser’s private resolver cannot skip the policy. It needs agent 4.2+ on Windows 10 or newer.

02

Two ways in, one policy

Laptops get the Windows agent, deployed by MSI or switched on in a Core Endpoint Protection policy. Everything else on a site — phones, printers, guests, cameras — is covered by registering the office’s public IP and forwarding DNS to the resolvers. Both draw on the same categories, overrides and reports in one console.

03

Made for MSPs running many small sites

The console’s MSP view has a site list, global overrides every site can inherit, and per-site keycodes and trials. One MSP quoted on OpenText’s page says its clients’ help-desk calls fell by almost 40%. Logs can hide user names, or be echoed to a local resolver for a SIEM.

04

Where it stops

It filters by domain only: no proxy, no TLS inspection, no CASB. The documented agent is Windows; Macs and phones rely on network forwarding. No price or Indian resolver is published. OpenText keeps its SMB and consumer security line, which includes this product, outside its core and is divesting non-core units; ask about the roadmap.

The idea
Stop bad domains at the lookup
The residency
No Indian resolver documented
The price
Quoted; 30-day console trial
Proof, not promises

The numbers behind the platform

78 categories
domain categories a DNS policy can allow or block, from malware sites to streaming
— Vendor
7 risk types
security categories, including botnets, spyware, keyloggers and proxy avoidance
— Vendor
3 ports shut
Leak Prevention blocks plain DNS on 53, known DoH on 443 and DoT on 853
— Vendor
13 months
of category reporting kept in the console, per device and per IP address
— Vendor
~40% fewer calls
help-desk calls one MSP says its clients saw, quoted on OpenText’s product page
— Vendor
30 days
the free trial a site can start from the console before a paid keycode
— Vendor

What your OpenText Core DNS Protection rollout looks like

Days 1–2Model

List sites, IPs and devices

Count Windows laptops, other devices and each site’s public IP or dynamic-DNS name, and note your Active Directory domains.

Week 1Decide

Pick resolvers and test them

Choose each site’s region in the console, run nslookup against both resolvers, and ask OpenText where they are hosted.

Week 2Pilot

Trial on one site

Start the 30-day trial, apply the High policy, add AD domains to the bypass list and deploy the agent to a pilot group.

Week 3Prove

Close the side doors

Turn on Leak Prevention, add allow overrides for blocked business apps, and check the security-risk report daily.

Month 2Commit

Forward every site

Point each site’s forwarders at the resolvers, roll the agent out through endpoint policy, and schedule monthly reports.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.3
38+ reviews*
84% would recommend
Ease of deployment4.5
Blocking accuracy4.3
MSP management4.4
Reporting4.0
Platform coverage3.7
5★
50%
4★
35%
3★
10%
2★
3%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Logistics
“We turned on DNS in the endpoint policy and the agent rolled out with the next check-in. No separate deployment project at all.”
IT Manager
Logistics
BFSI
“Leak Prevention ended the problem of browsers using their own DoH resolver. Our block page finally shows up on every laptop.”
Systems Administrator
BFSI
Hospitality
“Guest Wi-Fi and the CCTV recorders are filtered by forwarding alone. We registered the office IP and changed two forwarders.”
Network Engineer
Hospitality
IT Services
“Global overrides save us hours: one allow entry for a client’s accounting portal reaches all forty sites within fifteen minutes.”
Service Delivery Lead
IT Services
Manufacturing
“Thirteen months of category history settled an HR question about streaming at work that a 30-day log never could have.”
Head of IT
Manufacturing
Media
“Fine for Windows, but our Mac designers are only covered in the office. Off-site they need another tool, so plan for that.”
IT Lead
Media
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the secure web and DNS market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Secure Web & DNS Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
OpenText Core DNS ProtectionThis page

Quoted, usually by an MSP; no price published.

Grid 02 · The architecture

Ease of Adoption × Inspection Depth

The grid nobody publishes — how easily you can buy and switch it on alone vs how deep into the traffic it can see.

Deep, heavy rolloutsDeep and easy to startPlatform add-onsLight DNS filters
OpenText Core DNS ProtectionThis page

DNS only; Windows agent or forwarding, sold standalone.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

OpenText Core DNS Protection vs the secure web and DNS field

Against Cisco Umbrella, Cloudflare One Gateway, Zscaler Internet Access, Netskope Next Gen SWG and Palo Alto DNS Security — on layer, roaming, encrypted DNS, price, logs and India.

DimensionOpenText Core DNS ProtectionCisco UmbrellaCloudflare One (Gateway)Zscaler Internet AccessNetskope Next Gen SWGPalo Alto DNS Security
What it isMSP-sold DNS filterDNS layer, then SIGDNS inside a SASECloud proxy firstInstance-aware proxyFirewall subscription
Enforcement layerDNS onlyDNS, proxy at SIGDNS, HTTP, networkFull inline proxyFull inline proxyDNS on the firewall
Deployment and roamingWindows agent + forwardPoint DNS + clientResolver IPs or WARPClient or tunnelsClient or tunnelsNeeds the platform
Encrypted DNS controlBlocks 53, DoH, DoTDoH/DoT categoryOwn DoH and DoTInspects DoH inlineTunnel blockingFirewall policy
Categories and intelligence78 BrightCloud catsTalos + OpenDNSCloudflare networkZero Trust ExchangeApp-instance awareDGA and tunnelling
Pricing modelQuoted, often by MSPPer user, by tierPer user a monthPer user, by editionPer user, platformPer firewall SKU
Published entry priceNot published~$30–40/user/yearFree; then $7/user/mo~$6–12/user/monthNot publishedNot published
Included vs add-onAll features insideProxy at higher tiersDNS in the free tierEditions add depthModules by licenceSeparate SKUs
Reporting and logsUp to 13 monthsExport to S324 h free; 30 days paidStream to your SIEMStream to your SIEMOn firewall or cloud
Integrations and adminMSP console, APICisco and MerakiCloudflare One stackZero Trust ExchangeNetskope One stackStrata management
India resolver or PoPNot documentedChennai, Mumbai sitesSix Indian citiesIndian data centresMumbai, Chennai, DelhiYour own firewall
Support and trial30-day trialFree trialFree up to 50 usersTrial on requestTrial on requestPartner evaluation
Lock-in and exitStop service, revertsRepoint DNSMonthly, change DNSUnwind tunnels, clientPlatform-boundTied to firewalls
Best fitMSPs with Windows fleetsStart at DNS, growPrice-led, India-nearDeep inspectionSaaS tenant controlPalo Alto estates
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose OpenText Core DNS Protection if…

  • ✓Your MSP already runs Core Endpoint Protection, so DNS filtering is a policy switch rather than a new rollout
  • ✓Browsers and apps using their own DoH resolvers are slipping past the filters you have today
  • ✓You need guests, printers and IoT on each site filtered by forwarding, with no agent to install

Compare alternatives if…

  • ✓Resolvers must be documented in India — Cloudflare lists six cities; Netskope and Cisco publish Indian sites
  • ✓You need a published price before a call — Cloudflare prints one
  • ✓Macs and phones must be filtered off-site, or content inspection is the real need — Umbrella, Cloudflare or Zscaler

Do not expect…

  • ✓A price list, INR billing or a documented Indian resolver
  • ✓Proxy inspection, TLS decryption or CASB — this is DNS filtering
  • ✓A documented macOS or mobile agent for roaming devices

OpenText Core DNS Protection is one of 44 secure web & dns products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does an unfiltered DNS layer cost you?

Drag the sliders (users whose devices are filtered; admin-hour cost). Estimates model IT time spent cleaning up after malicious-site visits, chasing unfiltered encrypted lookups and editing router blocklists by hand, at an assumed 1.5 hours per user a year, with 70% of it removed by DNS-layer blocking and central overrides. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual DNS-incident cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. OpenText publishes no price and no licence unit for Core DNS Protection: a site is switched on in the console with a paid keycode or a 30-day trial, and most buyers are quoted by OpenText or their MSP. Third-party listings show seat bundles that OpenText does not confirm. TechBag counts sites and devices first, then quotes in INR with GST.

30-day trial

Best for proving it on one site

  • Full product, free for 30 days
  • Started per site from the console
  • Agent stops filtering when it lapses

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Full subscription

Best for MSP-run multi-site estates

  • Quoted by OpenText or your MSP
  • Agent and network filtering included
  • Bought apart from Core Endpoint Protection

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Devices

How many devices are Windows laptops that roam, and how will Macs and phones be filtered when they leave the office?

2
Encrypted DNS

Are endpoints on Windows 10 or newer with agent 4.2+, so Leak Prevention can block DNS, DoH and DoT side doors?

3
Resolvers

Which resolver region will each site use? OpenText documents no Indian location, so measure latency before rollout.

4
Active Directory

Which internal domains must go on the bypass list so the agent hands them to your local DNS servers?

5
Depth

Does the brief need content inspection or CASB? If so, DNS filtering alone will not meet it — price a proxy too.

6
Logs and privacy

Should user names be hidden in logs, and does your SIEM need lookups echoed to a local resolver?

7
Roadmap

OpenText treats SMB and consumer security as non-core. What does the contract say if the product changes owner?

8
Quote

Does the quote state the licence unit, term, currency and support route? Ask about INR billing and add GST.

FAQ

Questions buyers ask

It is OpenText’s cloud DNS filtering service, formerly Webroot DNS Protection. Every lookup from a device or network is checked against 78 BrightCloud categories, so malicious, command-and-control and unwanted domains are blocked before a connection is made. It is run from the same console as Core Endpoint Protection.

Ready to evaluate OpenText Core DNS Protection?

Count your sites and Windows devices first, or let a TechBag advisor test the resolvers from your offices, run the pilot with Leak Prevention on and get the quote in INR.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.