Skip to content

Home Expertise / Network security

NET / NET-07

DNS security and protective resolution filtering

Protect the service that resolves domain names and control destinations resolved by devices. The service addresses internal DNS availability and detection or blocking of domains considered dangerous.

WHEN IT HELPS

A focused response
to a defined need.

Uncontrolled DNS, endpoints using external resolvers, suspicious-communication alerts or critical dependence on poorly documented internal DNS.

AT A GLANCE

Family
Network security

Engagement
Implementation

Reference
NET-07

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Resolver architecture
  • internal/external separation
  • change control
  • filtering
  • proportionate logging
  • administrative access
  • continuity
  • handling encrypted DNS use

Deliverables

  • DNS architecture
  • resolution policies
  • configurations
  • exception list
  • incident procedures
  • resolution and failover tests
  • sensitive-zone documentation

Acceptance evidence

Business resolution is validated; an agreed test domain is blocked; administration is protected; continuity is tested; known bypasses are documented with agreed measures.

DELIVERY

How the work is structured.

Approach

Map traffic; design and size; pilot; migrate gradually with rollback; test and document operations.

Prerequisites & responsibilities

Customer: networking, applications, carriers, change windows and business acceptance. Provider: design, migration and tests. Third-party access and TLS inspection require suitable approvals.

Scope factors

Sites, actual inspected throughput, traffic, rules, remote users, availability and integrations. Hardware, security subscriptions and recurring operations are separate.

Questions to clarify

Who administers zones and domains? Can endpoints bypass resolvers? Which services fail during a DNS outage?

IMPORTANT BOUNDARIES

DNS filtering does not see every exchange and does not replace EDR or firewalls. Encrypted DNS and direct IP access can change its coverage.

Changes preserve essential services and recovery paths. Sizing, licensing and acceptance tests reflect the features that will actually be enabled.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A company has different DNS configurations across sites. Project: standardise resolvers and apply common filtering. Target outcome: consistent behaviour and resolution incidents that support can diagnose.

Scenario 02

An organisation loses services when its primary DNS fails. Project: review redundancy, backups and change controls. Target outcome: verified recovery; non-redundant dependencies remain identified as risks requiring treatment.

Technology and reference context

Examples: secured internal resolvers and protective DNS services; firewall integration depends on subscriptions and architecture.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.