Talk to us
by Palo Alto NetworksTechBag Intel Page

Palo Alto Advanced DNS Security

Malware calls home through DNS. Your resolver shouldn’t answer it — Palo Alto Advanced DNS Security checks every DNS query and answer, on a Palo Alto firewall or, through the standalone Advanced DNS Security Resolver, with no firewall at all.

Query and response inspectionStandalone resolver, no firewallQuoted per user per year

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Palo Alto prints no price; the Resolver is per user per year, the firewall service per device
Quote
Layer
Blocks a destination at lookup; it does not decrypt or read web content
DNS only
Roaming
Off-network laptops need Prisma Access Agent, Windows or macOS, as a fallback path
Via agent
India
India appears in the Resolver’s sub-processor list; logs follow your tenant region
Country, no city

Quick answer

Palo Alto Advanced DNS Security inspects DNS requests and responses with Precision AI models, either on a Strata firewall or Prisma Access, or through the Advanced DNS Security Resolver: a cloud resolver, launched in July 2025, that you forward DNS to with no firewall at all. The Resolver is licensed per user per year with 5,000 queries a user a day, on quote. It works at the DNS layer only, with no TLS decryption of web traffic and no CASB. Read more ↓ Show less ↑
Part 01 · Orient

The Palo Alto Networks platform family

This page covers Palo Alto Advanced DNS Security, including the standalone Advanced DNS Security Resolver. The rest:

Quick facts

30-second orientation
Product
DNS-layer threat prevention, as a firewall subscription or as a standalone cloud resolver
Maker
Palo Alto Networks, Santa Clara, California; founded 2005, CEO Nikesh Arora
Status
Resolver launched 23 July 2025; plain DNS Security is end-of-sale, Advanced is the current tier
Price
Not published; the Resolver is quoted per user per year, the firewall service per device and term
Licence
Resolver needs no firewall or Threat Prevention; the firewall service needs Threat Prevention
Allowance
5,000 DNS requests per licensed user a day on the Resolver; up to 1,000 source subnets per tenant
Transport
DNS over UDP and TCP, DoH since October 2025 and DoT on port 853 since September 2026
Detection
Six threat families, request and response side, including hijacking and DNS tunnelling
India
Privacy datasheet lists India among sub-processor locations; no Indian resolver city is named
In India via
TechBag — source mapping, pilot on one site, quote in INR with GST, log-retention design
Part 02 · Learn

Understand protective DNS before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is a protective DNS resolver?

A resolver that checks each lookup against threat data and refuses or redirects the bad ones, before any connection is made.

An ISP resolver with no policy vs a protective resolver — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionAn ISP resolver with no policyPalo Alto Advanced DNS Security
Who answers a lookupAn ISP or public resolver, no policyPalo Alto’s resolver, applying your profile
What gets inspectedNothing, or the domain asked forBoth the query and the answer returned
Hardware neededA firewall with a DNS subscriptionNone; a forwarder change and verified IPs
Finding infected hostsGuesswork from firewall logsSinkhole hits tied to a source address
Encrypted DNSClients bypass via public DoHDoH and DoT to the Resolver itself
What it is NOT—A web proxy, a CASB, or a roaming agent

The cheapest test is one site: forward its DNS servers to the Resolver, alert for a week, and read what it would have blocked.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where the lookup is answered

Resolver

Advanced DNS Security Resolver

Your DNS servers forward to Palo Alto’s anycast resolver, or clients use edge-dns.service.paloaltonetworks.com over DoH or DoT; policy is applied before the answer returns.

02
Who the resolver will serve

Sources

Verified connection sources

Each office or data-centre egress IP or subnet is registered and proved with a token from inside it; a tenant can list up to 1,000 subnets, IPv4 or IPv6.

03
Where existing Palo Alto estates enforce

Firewall path

ADNS on NGFW and Prisma Access

A Strata firewall or Prisma Access sends DNS requests and responses to the ADNS cloud for a verdict; a regional service domain in Mumbai serves India.

04
Where policy and evidence live

Console

Strata Cloud Manager and logs

Profiles, lists, sinkholes and sources are set in Strata Cloud Manager or its APIs; DNS logs land in the tenant data region you chose at activation.

A cloud resolver you forward to from verified egress IPs — or the same detections enforced on a Strata firewall.

Part 03 · Evaluate

Nine capabilities. Resolve, detect, control.

Palo Alto Advanced DNS Security stops bad destinations at the lookup, with or without a Palo Alto firewall.

Resolve
Forwarding

Protection by changing a forwarder

Point existing DNS servers at the resolver and every device behind them is covered, with no agent and no Palo Alto firewall.

Resolve
DoH and DoT

Encrypted lookups to the resolver

DoH arrived in October 2025 and DoT on TCP 853 in September 2026, both on one domain with TLS 1.2 or newer required.

Resolve
Agent fallback

Cover laptops when the tunnel drops

Prisma Access Agent 25.7 or later on Windows or macOS sends DNS over DoH to the resolver whenever its tunnel is down.

Detect
Responses

Answers are checked, not just questions

The resolver inspects replies as well as queries, to catch hijacked records, compromised DNS provider accounts and poisoned answers.

Detect
Tunnelling

Data hidden inside DNS queries

Each query is scored on its own, so slow, low-volume tunnelling used to smuggle data or commands out can be caught early.

Detect
Lookalikes

Fake software and dangling domains

Detections added in 2026 flag sites posing as software vendors, and expired third-party domains attackers re-register.

Control
Categories

Content categories and SafeSearch

Block categories such as file converters or remote-access tool sites, and force SafeSearch on Google, Bing and YouTube.

Control
Lists

Your own domains, your own actions

Custom FQDN lists and external dynamic lists take allow, block, alert or sinkhole, with an option to cover every subdomain.

Control
Sinkholes

Find the infected machine

Up to 10 sinkhole servers redirect bad lookups so infected hosts reveal themselves, and users see a custom block page.

See it, don’t just read it

Watch Palo Alto Advanced DNS Security in action

The Resolver service at launch, two of its newer detections, and the same DNS categories inside Amazon Route 53 DNS Firewall.

Palo Alto Networks LIVEcommunity (official)·Session, August 2025

August 2025 - Spark User Summit - ADNS Resolver Service - Part 1

A walk-through of the Resolver service in its launch month: sources, profiles and logs.

Palo Alto Networks LIVEcommunity (official)·11 min, October 2025

ADNS: Ultra Slow DNS Tunneling and Dangling DNS

How two of the newer detections work: low-and-slow tunnelling and dangling DNS records.

Palo Alto Networks LIVEcommunity (official)·8 min, September 2026

Introducing ADNS for Amazon Route 53 Resolver DNS Firewall AWS

The same DNS categories applied inside Route 53 DNS Firewall for AWS VPC workloads.

Strata by Palo Alto Networks (official)·Short, June 2024

Palo Alto Networks Advanced DNS Security: Stop Juggling and Start Securing

A one-minute pitch for Advanced DNS Security, from before the Resolver existed.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Palo Alto Advanced DNS Security

Most DNS filters only check the question. Palo Alto checks the answer too.

Here’s what genuinely sets it apart — and exactly where it stops.

01

A Palo Alto DNS control without a Palo Alto firewall

Until July 2025, Advanced DNS Security meant a Strata firewall or Prisma Access plus Threat Prevention. The Resolver drops both: forward your DNS servers to it, verify your egress IPs, and every device behind them is filtered. A shop on another firewall brand can buy the DNS layer alone.

02

It reads the answer, not only the question

Most protective DNS checks only the domain asked for. The Resolver also inspects the reply, where hijacked records, compromised DNS provider accounts and poisoned answers appear. Palo Alto sorts its detections into six families and claims twice the coverage of its closest rival.

03

One policy across firewall, SASE, resolver and AWS

Strata Cloud Manager holds one set of DNS Security profiles for PA-Series firewalls, Prisma Access and the Resolver. The same detections also reach Amazon Route 53 DNS Firewall, in AWS preview since June 2026 with Mumbai among its regions.

04

Where it stops

It is a DNS filter: it cannot read a page, scan a download or stop an upload, and has no CASB. There is no price list. Off-network laptops are covered only through Prisma Access Agent, so a Resolver-only buyer has no roaming client. No Indian resolver city or large named deployment is published.

The idea
Inspect the DNS answer, not just the query
The residency
India listed as a location; no city named
The price
Quoted per user per year for the Resolver
Proof, not promises

The numbers behind the platform

5000 queries
the daily DNS request allowance for each licensed user of the Resolver
— Vendor
1000 subnets
the most connection-source subnets one Resolver tenant can register
— Vendor
10 sinkholes
custom sinkhole servers a tenant can define since February 2026
— Vendor
6 families
threat groups in Palo Alto’s taxonomy, from callback domains to response attacks
— Vendor
90 days
how long Palo Alto keeps data on analysed domains, which holds no personal data
— Vendor
180 days
the log retention CERT-In’s April 2022 Directions require, whichever DNS filter you run
— Regulator

What your Palo Alto Advanced DNS Security rollout looks like

Week 1Model

Map every DNS path out

List each office’s DNS servers and public egress IPs, find devices using public DoH, and note internal zones to bypass.

Week 2Decide

Register and verify sources

Add egress IPs and subnets in Strata Cloud Manager, verify each with a token from inside it, and attach a profile.

Week 3Pilot

Forward one site in alert mode

Point one office’s forwarders at the resolver, set categories to alert, and read a week of logs before blocking.

Month 2Prove

Block, sinkhole and roll out

Turn alerts into blocks, set sinkholes and the block page, then repoint the remaining sites one change window at a time.

Month 3Commit

Close the gaps

Block outside DoH and DoT at the firewall, decide on roaming cover, and route logs to meet 180-day retention.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.2
41+ reviews*
82% would recommend
Threat detection4.5
Ease of onboarding4.3
Policy controls4.1
Reporting4.0
Value for money3.6
5★
45%
4★
35%
3★
13%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Retail
“We run another vendor’s firewalls at 40 branches. Forwarding our Windows DNS servers to the Resolver took one change window.”
Network Architect
Retail
BFSI
“The response-side check flagged a record our registrar account had changed. A query-only filter would have resolved it happily.”
Security Analyst
BFSI
Manufacturing
“Sinkholes per profile let us send guest Wi-Fi and plant networks to different addresses, so triage starts with the right team.”
SOC Lead
Manufacturing
Logistics
“Verifying each egress subnet with a token was fiddly where an ISP changed our ranges. Keep a list of every public IP first.”
Infrastructure Manager
Logistics
Education
“SafeSearch by DNS rewrite gave our labs the control the board wanted, without decrypting student traffic.”
IT Head
Education
Professional Services
“Good detection, but no roaming client unless you also buy Prisma Access, and the quote took a while to arrive.”
Head of IT
Professional Services
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the DNS security market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Secure Web & DNS Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Palo Alto Advanced DNS SecurityThis page

Quoted per user per year for the Resolver; no list price.

Grid 02 · The architecture

Coverage Reach × Detection Depth

The grid nobody publishes — how many places and devices the filter reaches, India included, vs how deeply it inspects DNS itself.

Deep but site-boundDeep and everywhereBasic and site-boundWide but shallow
Palo Alto Advanced DNS SecurityThis page

Query and response checks; roaming only via Prisma Access Agent.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Palo Alto Advanced DNS Security vs the DNS security field

Against Cisco Umbrella, Cloudflare One Gateway, Infoblox Threat Defense, Zscaler Internet Access and OpenText Core DNS Protection — on layer, encrypted DNS, roaming, price, scale and India.

DimensionPalo Alto Advanced DNS SecurityCisco UmbrellaCloudflare One GatewayInfoblox Threat DefenseZscaler Internet AccessOpenText Core DNS Protection
What it isDNS service + resolverDNS layer to SIG ladderSSE gatewayProtective DNSInline web proxySMB DNS filter
DeploymentForwarder or firewallPoint DNS or SD-WANResolver, agent, tunnelCloud, NIOS or endpointTunnels or PAC filesWindows agent or site
Layer and TLSDNS only, no TLSSelective at SIG tiersFull TLS inspectionDNS only, no TLSFull TLS inspectionDNS only, no TLS
Encrypted DNSAccepts DoH and DoTBypass not verifiedDoH and DoT endpointsPublic DoH feedsProxy sees DoHAgent blocks bypass
Roaming devicesOnly via Prisma AgentRoaming clientWARP clientInfoblox EndpointClient ConnectorWindows-only agent
Threat detectionQuery and responseTalos intelligenceCloudflare threat intelDNS threat intelligenceFull-session engines78 categories
Policy controlsLists and sinkholesCategories by identityIdentity-aware rulesPolicies and feedsFull web policyPer-site policies
Pricing modelPer user / per devicePer user, by tierPer user, publishedTiers, token-basedPer user, by editionQuote via MSPs
Published entry priceNot published~$2.25/user/mo reportedFree to 50, then $7Not published~$6–12/user/mo reportedNot published
Included vs add-onResolver is its own SKUProxy costs a tier upDNS and HTTP togetherDepth by tierData protection extraDNS only, nothing more
Scale and limits5,000 queries/user/dayLarge estatesLarge estatesNamed large customerLarge estatesSMB and MSP focus
India presenceCountry listed, no cityMumbai and ChennaiSix Indian citiesMumbai + HyderabadFour Indian citiesNone published
Lock-in and exitUndo a forwarderUndo a DNS settingDeeper with each tierTied to DDI if usedProxy is the pathRemove agent, repoint
Best fitResponse-aware DNSFast DNS, grow to SIGPublished-price SSEDDI-led enterprisesDeep inspectionMSP-run small sites
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Palo Alto Advanced DNS Security if…

  • ✓You want a protective resolver that inspects DNS answers as well as queries, to catch hijacked or poisoned records
  • ✓Your firewalls are from another vendor, or you have none, and you want Palo Alto’s DNS detections without buying one
  • ✓You already run Strata firewalls or Prisma Access and want the same DNS detections across them, the Resolver and AWS

Compare alternatives if…

  • ✓You need a roaming client without buying a SASE platform — Umbrella, Cloudflare and Infoblox each ship one
  • ✓You want a printed price before a sales call — Cloudflare One Gateway publishes $7 per user a month
  • ✓You need content, not destinations, inspected — Zscaler’s proxy decrypts every session

Do not expect…

  • ✓TLS decryption of web traffic, file scanning or CASB from the Resolver
  • ✓A published price, or a named Indian resolver city
  • ✓Coverage for roaming laptops unless Prisma Access Agent is also licensed

Palo Alto Advanced DNS Security is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does DNS-borne triage cost you?

Drag the sliders (DNS-borne alerts your team triages a year; analyst-hour cost). Estimates model analyst time spent chasing malware callbacks, phishing clicks and tunnelling that began with a DNS lookup, at an assumed 1.5 hours per alert, with 70% of it avoided by blocking at the resolver. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual DNS-incident triage cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: the Advanced DNS Security Resolver is licensed per user per year, with 5,000 DNS requests per user a day, and needs no firewall or Threat Prevention licence. Advanced DNS Security on a firewall is sold per device by model and term, inside Palo Alto bundles, or with Flex credits for software firewalls, and needs Threat Prevention. Palo Alto offers a 90-day trial. TechBag counts your users and sources first, then quotes in INR with GST.

Advanced DNS Security Resolver

Best for any estate, with or without Palo Alto firewalls

  • Licensed per user per year, quoted
  • 5,000 DNS requests per user a day
  • No firewall or Threat Prevention needed

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Advanced DNS Security (firewall)

Best for existing Strata NGFW and Prisma Access estates

  • Per device by model and term, quoted
  • Needs a Threat Prevention licence
  • Flex credits for software firewalls

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Licence path

Resolver, firewall service or both? The Resolver needs no Threat Prevention; the firewall service does.

2
User count

How many users will you license, and will 5,000 queries per user a day cover servers and IoT behind them?

3
Egress IPs

Are all office egress IPs static and known? Each must be verified, and dynamic ISP ranges break that.

4
Roaming

How will laptops off the network be covered: Prisma Access Agent, another agent, or not at all?

5
DoH bypass

Will the firewall block public DoH and DoT, so browsers cannot skip the resolver with their own?

6
Internal zones

Which internal domains must bypass the cloud resolver, so Active Directory lookups do not fail?

7
Logs and retention

Which tenant data region will hold logs, and how will you keep 180 days for CERT-In and SEBI CSCRF audits?

8
Quote

Does the quote name the SKU, user count, term and any Strata Logging Service charge? Ask for INR with GST.

FAQ

Questions buyers ask

It is Palo Alto’s DNS-layer threat service. It checks DNS requests and responses against Precision AI models and threat data, and blocks or sinkholes bad lookups. It runs on Strata firewalls and Prisma Access, or through the Advanced DNS Security Resolver, a cloud resolver that needs no firewall.

Ready to evaluate Palo Alto Advanced DNS Security?

Map your users and egress IPs first, or let a TechBag advisor scope a pilot that forwards one office’s DNS to the Resolver in alert mode.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.