DNS filtering blocks the lookup, not the page. Before a device connects to any website, it asks a DNS server to translate the name into an address. A DNS filter sits in that step. If the domain is known to be malicious, or belongs to a category you have blocked, the answer never comes back and the connection is never made.

That is the whole mechanism, and it explains both the strength and the limit. Nothing is downloaded, nothing is inspected, no traffic is decrypted. It is fast and cheap. It also cannot see anything beyond the domain name.

What DNS filtering actually stops

What it does not stop

Good to know: modern browsers can use DNS over HTTPS, sending name lookups directly to a third-party resolver and straight past your filter. If you deploy DNS filtering without disabling or redirecting DoH by policy, a meaningful share of your traffic simply will not be filtered. This is the single most common reason a deployment quietly does nothing.

DNS filtering vs a secure web gateway

These get compared constantly and they operate at different layers.

DNS filteringSecure web gateway
What it seesThe domain requestedThe full session, including files
Inspects encrypted trafficNoYes, where configured
Blocks a bad file on a good domainNoYes
Deployment effortLowModerate to high
Performance impactNegligibleNoticeable if misconfigured
Typical costLow per userConsiderably higher

A secure web gateway, sometimes called a secure internet gateway, is the more capable control. For most organisations under a few hundred staff, DNS filtering delivers a large share of the practical benefit for a fraction of the licensing and operational effort. Start there, and add a gateway when a specific requirement demands it.

Key takeaways
  • DNS filtering blocks the name lookup, so the connection never opens.
  • Handle DNS over HTTPS in policy, or a large share of traffic bypasses the filter entirely.
  • Deploy a roaming agent, not just a router setting, or remote workers are unprotected.
  • It complements email security and endpoint protection. It does not replace either.

Deploying it without breaking things

  1. Start in monitor mode. Run for a week logging what would have been blocked before you block anything. Every organisation has a legitimate business tool sitting in an unexpected category.
  2. Block threat categories first. Malware, phishing, command-and-control. These are uncontroversial and nobody complains.
  3. Decide productivity categories deliberately. This is a management conversation, not a technical one. Involve HR before you block anything that touches how people work.
  4. Deploy the roaming client. Filtering at the office router protects people only at the office, which is not where most of them are.
  5. Handle DNS over HTTPS. Disable or redirect it by group policy or device management, or accept that the control is partially decorative.
  6. Publish the block page. A page that tells the user what happened and how to request an exception prevents most of the help desk noise.

Firewall rules for small teams

One rule matters more than the rest: block outbound DNS on port 53 to everything except your approved resolvers. Without it, any device configured with its own DNS server ignores your filtering entirely. This is a five-minute change on most firewalls and it is regularly missing.

Where it fits in a small business security stack

DNS filtering is a layer, not a strategy. It sits alongside email security, endpoint protection and multi-factor authentication, each catching what the others miss. On its own it is a meaningful improvement over nothing. Sold as complete protection, it is misleading.

Frequently asked questions

What is DNS filtering?

DNS filtering intercepts the name lookup a device performs before connecting to a website. If the domain is known to be malicious or falls into a blocked category, the lookup fails and the connection never opens. It is among the cheapest and least intrusive security controls available.

What is a secure web gateway and how is it different from DNS filtering?

A secure web gateway inspects the actual traffic to and from websites, including downloads and, where configured, encrypted sessions. DNS filtering only sees the domain requested. The gateway offers deeper control at higher licensing and operational cost.

Does DNS filtering stop phishing?

Some of it. Links pointing to already-known malicious domains are blocked. Newly registered domains used in targeted campaigns often are not categorised yet, so DNS filtering reduces phishing risk without replacing email security or user training.

Does DNS filtering work for remote and home workers?

Only with an agent on the device. Filtering configured at the office firewall protects devices only while they are on that network. For a hybrid workforce, a roaming client on each laptop is what makes the control meaningful.

Keep exploring

Ready for a clear path forward?

Start with a Navigate Clarity Conversation. A free 30 minute review of where you stand and what to do first.

Start with a Clarity Conversation