A phishing email only works if its link resolves. Refuse the lookup and the page never loads — WebTitan checks every DNS lookup from your offices and OTG laptops against threat and content policy, so refused domains never resolve — served from an instance TitanHQ lists in Mumbai, quoted through MSPs.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers WebTitan DNS Filtering — WebTitan Cloud with its OTG roaming agent, also sold for guest Wi-Fi. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Before a browser can open a site it asks DNS for an address; a filtering resolver withholds the answer for harmful or unwanted domains.
What consolidation actually replaces, dimension by dimension.
| Dimension | Antivirus alone and the ISP’s resolver | WebTitan DNS Filtering |
|---|---|---|
| When a malicious domain is refused | After the download, if antivirus spots it | At the DNS lookup, before any connection |
| Laptops away from the office | Unfiltered on home and hotel Wi-Fi | OTG on Windows laptops, Macs and Chromebooks |
| Different rules for different staff | One block list for the whole office | Per user or group via DNS Proxy and WADA |
| Branches on changing IPs | Filtering breaks when the ISP reassigns | The Dynamic IP Agent keeps the site registered |
| Where lookups are answered | The ISP’s resolver, wherever it sits | A WebTitan instance; Mumbai is one of ten |
| What it is NOT | — | A web proxy, TLS inspection, a CASB or a printed price |
The cheapest test is the free trial: repoint one office’s DNS, put OTG on three laptops, and read what got refused.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Every account lives on one of ten regional instances, Mumbai among them; offices send DNS to that instance’s primary and secondary redirect IPs, and policy is applied per lookup.
An office is added by its external IP address before its resolvers are repointed; where the ISP keeps changing that address, the Dynamic IP Agent keeps the registration current.
OTG 2 runs on Windows, macOS and Chromebooks and can be pushed by Intune or an RMM; it returns a generic block page and is not supported on virtual machines.
A DNS Proxy on your network, paired with the WebTitan Active Directory Agent, ties each lookup to an AD user or group, including servers running in an Azure VNet.
Offices point DNS at a regional instance — OTG agents and an AD-aware DNS Proxy carry the same policy to laptops and users.
WebTitan checks each domain at lookup, so a phishing or malware site is never reached.
TitanHQ says more than 500 million visited URLs feed its threat corpus, with crowd-sourced URL analysis behind its AI-driven blocking.
Predefined content categories apply by default, so a fresh policy refuses unwanted classes of site before anyone writes a block list.
When someone clicks a link in a phishing email, the lookup is judged at that moment, which TitanHQ markets as time-of-click protection.
Register an office’s external IP and repoint its DNS to the instance’s redirect IPs, and every device behind that address is filtered.
The OTG agent carries policy to Windows, macOS and Chromebook devices at home or travelling, and installs through Intune or an RMM.
Branches whose broadband provider reassigns the public IP run the Dynamic IP Agent, so the site keeps its policy after every change.
Policies can be set per network, group, user or device; with the DNS Proxy and WADA, Active Directory accounts carry their own rules.
MSPs can enforce two-factor sign-in on the WebTitan console, so a stolen technician password alone cannot change a customer’s policy.
TitanHQ provides a REST API set for scripting WebTitan; ask which log data it exposes before relying on it for 180-day retention.
An explainer, the onboarding guide, and two 2019 clips on the OTG agent and MSP use, recorded on the old interface. All from TitanHQ’s official channel, now named @CyberSentriq.
What a DNS filtering layer adds, and how WebTitan applies threat and content policy at the lookup.
The newest WebTitan clip on the channel: setting up an account, adding a site and building a first policy.
Installing the OTG roaming agent; recorded in 2019 on the old interface, before OTG 2 replaced the first agent.
WebTitan Cloud as an MSP sells it, from 2019 and pre-merger branding; the console has changed since.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
TitanHQ’s redirect-IP documentation lists ten regional WebTitan instances, one of them Mumbai on AWS ap-south-1 addresses. Of the rivals compared here, only Cisco Umbrella also names an Indian location. The instance is set per account, so confirm yours.
WebTitan mostly reaches buyers via TitanHQ’s MSP Partner Program, whose resellers number circa 4,000 MSPs and VARs reaching 125,000 SMBs (CyberSentriq, June 2026). Admin 2FA can be enforced and a REST API automates it. In India, Pace Infotech offers it to the 1,000 customers it manages.
The DNS Proxy and WADA agent read Active Directory, so a rule can follow a user or group, Azure VNet included. OTG reaches Windows, macOS and Chromebooks off the network, and the Dynamic IP Agent keeps branches filtered when their public address changes.
Domains only: no proxy, TLS inspection or CASB. No price or licence unit is published. Antivirus ‘Secure DNS’ features that tunnel lookups elsewhere bypass it, OTG does not run on virtual machines, and log retention is unpublished, so plan an export for CERT-In’s 180 days.
Ask TitanHQ or your MSP which instance your account will sit on, Mumbai or not, and how WebTitan is counted on the quote.
Start the free trial, add one site’s external IP, point its DNS at the two redirect IPs, and review what gets refused.
Push OTG 2 by Intune or your RMM to some Windows, Mac and Chromebook users, and switch off any antivirus Secure DNS.
Add the DNS Proxy and WADA for per-user AD rules and the Dynamic IP Agent where addresses change, then roll out widely.
Agree how logs leave through the REST API for CERT-In’s 180 days, enforce admin 2FA, and name who reviews blocks.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We changed DNS on two branch routers and added each external IP in the console; both offices were filtered that morning.”
“Our field teams carry Chromebooks and Windows laptops. OTG covered both, and the Windows agent went out through Intune.”
“Two laptops kept slipping past the filter. Their antivirus had its own secure DNS switched on, and turning it off closed it.”
“The Mumbai instance counted in its favour, but we still had to ask TitanHQ to confirm our account was actually placed there.”
“We roll it out client by client from our RMM, and being able to force 2FA on every technician login was non-negotiable.”
“No price on the website, so budgeting meant a call. Keeping six months of logs for auditors needed a plan of its own.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the DNS filtering market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quoted through MSPs or direct; no published rate or unit.
The grid nobody publishes — how many ways a product can enforce DNS policy vs how much of it is documented in India.
Sites, OTG on three platforms, AD proxy, dynamic IP; Mumbai instance.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against DNSFilter, Cisco Umbrella, N-able DNS Filtering, OpenText Core DNS Protection and Heimdal DNS Security – Endpoint — on deployment, roaming, price, inspection, encrypted-DNS bypass, logs and India.
| Dimension | WebTitan DNS Filtering | DNSFilter | Cisco Umbrella | N-able DNS Filtering | OpenText Core DNS Protection | Heimdal DNS Security – Endpoint |
|---|---|---|---|---|---|---|
| What it is | DNS filter for MSPs | Anycast protective DNS | DNS tiers, SIG above | DNSFilter tech, resold | Formerly Webroot DNS | Resolver on the device |
| Deployment and roaming | Sites, OTG, AD proxy | Anycast, relay, 5 OSes | Resolver, Meraki, client | Site, relay, Win + Mac | Win agent, forwarders | Agent only, Win + Mac |
| Pricing model | Quote, unit unstated | Per licence, not head | Per user, yearly | MSP quote | Keycode per site | Per device per year |
| Published entry price | Not published | $1.00/licence/month | ~$30–40/user/year | Not published | Not published | Not published |
| Included vs add-on | Standalone or bundle | Roaming needs Plus | Proxy at SIG tiers | Older feature set | Policy extras included | One agent, many modules |
| Regions and scale | 10 instances, no scale | 80+ data centres | Verified past 5,000 | 500,000-user claim | Unverified at scale | No large deployment |
| Inspection depth | Domain only | Domain only | Selective proxy at SIG | Domain only | Domain, 78 categories | Domain only |
| Encrypted DNS bypass | AV Secure DNS bypasses | Firefox only, auto | DoH/DoT as a category | Firewall rule needed | Agent shuts other DNS | Chrome, Firefox handled |
| Integrations | REST API, Intune, RMM | API, PSA, SIEM export | Cisco and Meraki | N-central, N-sight | RMM, PSA, Unity API | PSA, RMM, REST API |
| Governance and logs | 2FA; retention unstated | 9-day raw log | S3 log export | 9 days on platform | 13 months by category | Retention unstated |
| India resolver | Mumbai instance listed | No Indian city named | Mumbai and Chennai | Not documented | Not documented | EU, US or UK data |
| Support and trial | Free trial, 5 minutes | 14-day full trial | Trial, then partners | Trial length unstated | 30-day console trial | Trial, Mumbai support |
| Lock-in and exit | Repoint and uninstall | Monthly billing option | Easy on DNS tiers | Tied to N-able RMM | Uninstall restores DNS | Agent carries more |
| Best fit | MSP-run SMBs in India | Printed-price SMBs | DNS now, SIG later | N-able RMM shops | Windows MSP fleets | Heimdal agent fleets |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
WebTitan DNS Filtering is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (devices covered; IT staff-hour cost). Estimates model the IT time spent rebuilding infected machines, resetting phished accounts and answering site-access requests, at an assumed 1.5 hours per device a year, with 70% of it avoided once harmful domains stop resolving. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote-only: TitanHQ publishes no WebTitan price and no licence unit; quotes come in dollars, euros or pounds, never rupees, and the free trial is running in about 5 minutes. WebTitan is sold standalone or inside the Complete bundle with TitanHQ’s email security, backup, training and archiving. Per-user rates on third-party blogs are not TitanHQ’s figures. TechBag confirms the licence unit and your instance first, then quotes in INR with GST.
Best for DNS filtering on its own
Best for a broader rollout
Best for MSPs selling the whole TitanHQ line
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Will your account be placed on the Mumbai instance? It is chosen per account, so get the answer in writing.
Is WebTitan counted by user, device or site on your quote? TitanHQ publishes no unit, so ask before comparing.
Are roaming devices Windows, macOS or Chromebooks? OTG covers those three; phones and virtual machines are left out.
Does any endpoint run antivirus with a Secure DNS feature, as AVG and Avast do? It sends lookups around WebTitan.
How will browsers’ own DNS over HTTPS be handled? Ask TitanHQ, and plan a firewall rule against known DoH providers.
Do you need per-user rules? That means a DNS Proxy and the WADA agent against Active Directory, on site or in Azure.
Where will 180 days of DNS logs live for CERT-In? Retention is unpublished, so plan an export through the REST API.
Standalone or the Complete bundle, and in which currency? Ask TechBag for INR with GST and the renewal terms.
Confirm your instance and licence unit first, or let a TechBag advisor run the free trial on one office and a few OTG laptops and plan a 180-day log export.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.