Malware calls home through DNS. Your resolver shouldn’t answer it — Palo Alto Advanced DNS Security checks every DNS query and answer, on a Palo Alto firewall or, through the standalone Advanced DNS Security Resolver, with no firewall at all.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Palo Alto Advanced DNS Security, including the standalone Advanced DNS Security Resolver. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A resolver that checks each lookup against threat data and refuses or redirects the bad ones, before any connection is made.
What consolidation actually replaces, dimension by dimension.
| Dimension | An ISP resolver with no policy | Palo Alto Advanced DNS Security |
|---|---|---|
| Who answers a lookup | An ISP or public resolver, no policy | Palo Alto’s resolver, applying your profile |
| What gets inspected | Nothing, or the domain asked for | Both the query and the answer returned |
| Hardware needed | A firewall with a DNS subscription | None; a forwarder change and verified IPs |
| Finding infected hosts | Guesswork from firewall logs | Sinkhole hits tied to a source address |
| Encrypted DNS | Clients bypass via public DoH | DoH and DoT to the Resolver itself |
| What it is NOT | — | A web proxy, a CASB, or a roaming agent |
The cheapest test is one site: forward its DNS servers to the Resolver, alert for a week, and read what it would have blocked.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Your DNS servers forward to Palo Alto’s anycast resolver, or clients use edge-dns.service.paloaltonetworks.com over DoH or DoT; policy is applied before the answer returns.
Each office or data-centre egress IP or subnet is registered and proved with a token from inside it; a tenant can list up to 1,000 subnets, IPv4 or IPv6.
A Strata firewall or Prisma Access sends DNS requests and responses to the ADNS cloud for a verdict; a regional service domain in Mumbai serves India.
Profiles, lists, sinkholes and sources are set in Strata Cloud Manager or its APIs; DNS logs land in the tenant data region you chose at activation.
A cloud resolver you forward to from verified egress IPs — or the same detections enforced on a Strata firewall.
Palo Alto Advanced DNS Security stops bad destinations at the lookup, with or without a Palo Alto firewall.
Point existing DNS servers at the resolver and every device behind them is covered, with no agent and no Palo Alto firewall.
DoH arrived in October 2025 and DoT on TCP 853 in September 2026, both on one domain with TLS 1.2 or newer required.
Prisma Access Agent 25.7 or later on Windows or macOS sends DNS over DoH to the resolver whenever its tunnel is down.
The resolver inspects replies as well as queries, to catch hijacked records, compromised DNS provider accounts and poisoned answers.
Each query is scored on its own, so slow, low-volume tunnelling used to smuggle data or commands out can be caught early.
Detections added in 2026 flag sites posing as software vendors, and expired third-party domains attackers re-register.
Block categories such as file converters or remote-access tool sites, and force SafeSearch on Google, Bing and YouTube.
Custom FQDN lists and external dynamic lists take allow, block, alert or sinkhole, with an option to cover every subdomain.
Up to 10 sinkhole servers redirect bad lookups so infected hosts reveal themselves, and users see a custom block page.
The Resolver service at launch, two of its newer detections, and the same DNS categories inside Amazon Route 53 DNS Firewall.
A walk-through of the Resolver service in its launch month: sources, profiles and logs.
How two of the newer detections work: low-and-slow tunnelling and dangling DNS records.
The same DNS categories applied inside Route 53 DNS Firewall for AWS VPC workloads.
A one-minute pitch for Advanced DNS Security, from before the Resolver existed.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Until July 2025, Advanced DNS Security meant a Strata firewall or Prisma Access plus Threat Prevention. The Resolver drops both: forward your DNS servers to it, verify your egress IPs, and every device behind them is filtered. A shop on another firewall brand can buy the DNS layer alone.
Most protective DNS checks only the domain asked for. The Resolver also inspects the reply, where hijacked records, compromised DNS provider accounts and poisoned answers appear. Palo Alto sorts its detections into six families and claims twice the coverage of its closest rival.
Strata Cloud Manager holds one set of DNS Security profiles for PA-Series firewalls, Prisma Access and the Resolver. The same detections also reach Amazon Route 53 DNS Firewall, in AWS preview since June 2026 with Mumbai among its regions.
It is a DNS filter: it cannot read a page, scan a download or stop an upload, and has no CASB. There is no price list. Off-network laptops are covered only through Prisma Access Agent, so a Resolver-only buyer has no roaming client. No Indian resolver city or large named deployment is published.
List each office’s DNS servers and public egress IPs, find devices using public DoH, and note internal zones to bypass.
Add egress IPs and subnets in Strata Cloud Manager, verify each with a token from inside it, and attach a profile.
Point one office’s forwarders at the resolver, set categories to alert, and read a week of logs before blocking.
Turn alerts into blocks, set sinkholes and the block page, then repoint the remaining sites one change window at a time.
Block outside DoH and DoT at the firewall, decide on roaming cover, and route logs to meet 180-day retention.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We run another vendor’s firewalls at 40 branches. Forwarding our Windows DNS servers to the Resolver took one change window.”
“The response-side check flagged a record our registrar account had changed. A query-only filter would have resolved it happily.”
“Sinkholes per profile let us send guest Wi-Fi and plant networks to different addresses, so triage starts with the right team.”
“Verifying each egress subnet with a token was fiddly where an ISP changed our ranges. Keep a list of every public IP first.”
“SafeSearch by DNS rewrite gave our labs the control the board wanted, without decrypting student traffic.”
“Good detection, but no roaming client unless you also buy Prisma Access, and the quote took a while to arrive.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the DNS security market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quoted per user per year for the Resolver; no list price.
The grid nobody publishes — how many places and devices the filter reaches, India included, vs how deeply it inspects DNS itself.
Query and response checks; roaming only via Prisma Access Agent.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Cisco Umbrella, Cloudflare One Gateway, Infoblox Threat Defense, Zscaler Internet Access and OpenText Core DNS Protection — on layer, encrypted DNS, roaming, price, scale and India.
| Dimension | Palo Alto Advanced DNS Security | Cisco Umbrella | Cloudflare One Gateway | Infoblox Threat Defense | Zscaler Internet Access | OpenText Core DNS Protection |
|---|---|---|---|---|---|---|
| What it is | DNS service + resolver | DNS layer to SIG ladder | SSE gateway | Protective DNS | Inline web proxy | SMB DNS filter |
| Deployment | Forwarder or firewall | Point DNS or SD-WAN | Resolver, agent, tunnel | Cloud, NIOS or endpoint | Tunnels or PAC files | Windows agent or site |
| Layer and TLS | DNS only, no TLS | Selective at SIG tiers | Full TLS inspection | DNS only, no TLS | Full TLS inspection | DNS only, no TLS |
| Encrypted DNS | Accepts DoH and DoT | Bypass not verified | DoH and DoT endpoints | Public DoH feeds | Proxy sees DoH | Agent blocks bypass |
| Roaming devices | Only via Prisma Agent | Roaming client | WARP client | Infoblox Endpoint | Client Connector | Windows-only agent |
| Threat detection | Query and response | Talos intelligence | Cloudflare threat intel | DNS threat intelligence | Full-session engines | 78 categories |
| Policy controls | Lists and sinkholes | Categories by identity | Identity-aware rules | Policies and feeds | Full web policy | Per-site policies |
| Pricing model | Per user / per device | Per user, by tier | Per user, published | Tiers, token-based | Per user, by edition | Quote via MSPs |
| Published entry price | Not published | ~$2.25/user/mo reported | Free to 50, then $7 | Not published | ~$6–12/user/mo reported | Not published |
| Included vs add-on | Resolver is its own SKU | Proxy costs a tier up | DNS and HTTP together | Depth by tier | Data protection extra | DNS only, nothing more |
| Scale and limits | 5,000 queries/user/day | Large estates | Large estates | Named large customer | Large estates | SMB and MSP focus |
| India presence | Country listed, no city | Mumbai and Chennai | Six Indian cities | Mumbai + Hyderabad | Four Indian cities | None published |
| Lock-in and exit | Undo a forwarder | Undo a DNS setting | Deeper with each tier | Tied to DDI if used | Proxy is the path | Remove agent, repoint |
| Best fit | Response-aware DNS | Fast DNS, grow to SIG | Published-price SSE | DDI-led enterprises | Deep inspection | MSP-run small sites |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Palo Alto Advanced DNS Security is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (DNS-borne alerts your team triages a year; analyst-hour cost). Estimates model analyst time spent chasing malware callbacks, phishing clicks and tunnelling that began with a DNS lookup, at an assumed 1.5 hours per alert, with 70% of it avoided by blocking at the resolver. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: the Advanced DNS Security Resolver is licensed per user per year, with 5,000 DNS requests per user a day, and needs no firewall or Threat Prevention licence. Advanced DNS Security on a firewall is sold per device by model and term, inside Palo Alto bundles, or with Flex credits for software firewalls, and needs Threat Prevention. Palo Alto offers a 90-day trial. TechBag counts your users and sources first, then quotes in INR with GST.
Best for any estate, with or without Palo Alto firewalls
Best for a broader rollout
Best for existing Strata NGFW and Prisma Access estates
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Resolver, firewall service or both? The Resolver needs no Threat Prevention; the firewall service does.
How many users will you license, and will 5,000 queries per user a day cover servers and IoT behind them?
Are all office egress IPs static and known? Each must be verified, and dynamic ISP ranges break that.
How will laptops off the network be covered: Prisma Access Agent, another agent, or not at all?
Will the firewall block public DoH and DoT, so browsers cannot skip the resolver with their own?
Which internal domains must bypass the cloud resolver, so Active Directory lookups do not fail?
Which tenant data region will hold logs, and how will you keep 180 days for CERT-In and SEBI CSCRF audits?
Does the quote name the SKU, user count, term and any Strata Logging Service charge? Ask for INR with GST.
Map your users and egress IPs first, or let a TechBag advisor scope a pilot that forwards one office’s DNS to the Resolver in alert mode.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.