● VeraDNS - Enterprise DNS Firewall · Zero agents

Stop threats before the connection.

VeraDNS inspects every DNS query on your network and blocks malware, phishing, ransomware and C2 the instant it's requested — entirely on your own infrastructure.

Data never leaves your network Live in under 60 minutes
Live DNS Query Flow
Healthy
Clients · Resolver · Destinations — sampled live
Allowed Blocked 2,481 qps
Why the DNS layer

One control acts before the connection. The rest react after.

Almost every connection starts with a DNS lookup — a device resolves a domain name before it opens a single socket. Filtering at that step stops a threat at the earliest link of the attack chain; the controls behind it can only inspect or contain traffic that is already flowing.

Control layer Blocks before
connection
All ports &
protocols
Every device,
agentless
Protects IoT
& OT
Deployment
effort
Firewall / NGFW High
Proxy / Secure Web Gateway High
Web Application Firewall Medium
Endpoint Security / EDR High
VeraDNS · DNS Security Low

● full · ◐ partial · ✕ none — DNS security complements the stack; it does not replace it. It stops the majority of commodity threats before they ever reach the controls behind it.

Defense in depth

The DNS layer is the outermost ring of a layered defence — it removes the easy, high-volume threats so your firewall, proxy and EDR can focus on what's left.

NIST SP 800-53Layered controls

Disrupt the kill chain early

A domain is resolved before any connection opens. Blocking it severs Delivery and Command-and-Control at the earliest stage — neutralising DNS-based C2 before exploitation.

Cyber Kill ChainATT&CK T1071.004

A preventive control, mapped

Acts under the NIST CSF Protect function — not just Detect. It aligns directly to recognised secure-DNS and boundary-protection controls.

NIST CSF: PRSP 800-81SC-20/21CIS 9.2

Protocol- and device-agnostic

Because resolution happens before any port or protocol is chosen, one policy covers every device — including agentless IoT and OT that endpoint tools can't reach.

Any portIoT / OTZero agents
How it works

DNS filtering at the network level.

Zero agents. Zero client software. VeraDNS evaluates every DNS query against your policies, blocklists and threat intelligence before a single connection is made.

01

Deploy on your infra

Install via Docker on your own server or VM, then point your network's DNS to VeraDNS. No data ever leaves your environment.

02

Every query inspected

Each DNS request is evaluated against your security policies, blocklists and access rules — in real time, at the resolver.

03

Threats blocked instantly

Malware, phishing, trackers and policy-violating domains are stopped before a connection is established — for every device at once.

04

Full visibility & audit

Every query, block and admin action is logged. Investigate incidents, generate reports and demonstrate compliance on demand.

Platform

One platform. Every DNS control.

From network-wide filtering to compliance reporting — everything your team needs to secure DNS, running entirely on your own infrastructure.

Network-wide filtering

Filter every DNS query for every device — users, servers, IoT and OT — with no endpoint agents to install or maintain.

Real-time threat intel

Auto-updating feeds block malware, phishing, ransomware and C2 domains the moment they're known — no manual upkeep.

Role-based access

Admin, Editor and Viewer tiers — enforced at the API layer with JWT auth, not just hidden in the interface.

Programmable policy

Define allow/block rules by category, group, client or time window — and roll them out across your whole estate instantly.

One-click compliance

Branded executive reports mapped to NIST 800-53, CIS v8, ISO 27K and NCSC — generated locally, never sent off-box.

Complete query log

Every request — domain, client, type, status, answer, latency — searchable live, with time-series trends.

SIEM & API export

Stream audit and query logs to Splunk, Sentinel or Elastic via REST in JSON or CSV — your data, your pipeline.

Encrypted DNS

Standard DNS, DoH, DoT and DNSSEC validation — enforce encrypted transport for internal clients to stop interception.

Self-hosted & sovereign

Runs on-premise, in your private cloud or your own VMs. No third-party dependency, no external query visibility.

Real-time query log

See every DNS query the moment it happens.

VeraDNS streams every resolution to a live, searchable log — domain, client, country, category, answer and latency — the instant it resolves. Filter to any device or threat category, replay any second, and export forensic evidence without a single query ever leaving your network.

What you're looking at
  • Each row is a single resolution captured in real time — newest at the top, streaming as clients query.
  • Allowed and Blocked verdicts are tagged inline; malware, phishing and ad/tracker hits are stopped before a connection is ever made.
  • Cache hits resolve in 0 ms; the Hits over time chart plots query volume second-by-second.
Retention 365 days Ingest 50k qps Export CSV · JSON · SIEM
Query Log LIVE
Filters: none Total DB 31,937 Filtered 31,937 Page 1 / 32
DateTimeDomainCountryClientTypeStatusCategoriesAnswer IPLatency
Hits over time per 1 sec · loaded page Trend
Page 1 of 32 · 1000 rows
Global threat landscape

Enforced locally. Informed globally.

VeraDNS blocks on your own infrastructure, but it learns from the whole internet. Every resolver draws on a worldwide threat feed — attack hotspots, hostile networks, phishing and DDoS telemetry — refreshed continuously, so a domain weaponised in one region is already blocked on yours.

Most-attacked locationsworldwide · last 24hLIVE
🇺🇸United States
38.1%
🇨🇳China
13.3%
🇨🇦Canada
9.9%
🇸🇬Singapore
9.1%
🇳🇬Nigeria
6.8%
🇺🇦Ukraine
2.6%
DDoS attack type L3 / L4
UDP
82.5
TCP
17.4
ICMP
0.1
GRE
0.0
Mitigation L7
WAF
50.9
DDoS
43.7
Access rules
2.5
IP reputation
2.3
Bot mgmt
0.6
WAF rule groups L7
Directory trav.
38.7
HTTP anomaly
22.1
SQLi
7.2
XSS
6.5
Command inj.
6.0
Attack methods L7
GET
80.5
POST
17.8
HEAD
1.0
OPTIONS
0.4
PATCH
0.1
Top attacking networks ASN
AS16509 Amazon
3.4
AS29465 MTN
2.9
AS8075 Microsoft
2.3
AS14618 Amazon
1.6
AS14061 DigitalOcean
1.5
AS132203 Tencent
1.5
Email threats classified
Link
67.3
Scam
54.4
Identity
48.7
Brand imp.
46.9
IP reputation
29.3

// aggregated, anonymised threat telemetry — illustrative of the global feed VeraDNS consumes; figures refresh continuously.

Vera Insight

Every query, summarized into answers.

Vera Insight turns raw resolution logs into board-ready intelligence — threat trends, compliance posture mapped to your frameworks, and the categories driving risk. Computed entirely on your own infrastructure.

0.00M
Queries analyzed
12.4% vs prev
0
Threats blocked
8.1% caught
0.0%
Compliance posture
2 controls closed
0.0ms
Median resolve
0.1ms faster
Query volume & threats AllowedBlocked
Security postureLIVE
0.0
posture score
Grade A
Risk events 14Open 0SLA 99.99%
Top blocked categorieslast 30 days
Malware & C2128,420 · 41%
Phishing84,610 · 27%
Trackers & ads56,240 · 18%
Cryptojacking25,010 · 8%
Newly-registered domains18,200 · 6%
Compliance framework coveragecontrol mapping
NIST 800-53SC-7, SC-20, SI-4
96%
CIS Controls v89.2, 13.3
94%
ISO/IEC 27001A.8.20, A.8.23
98%
NCSC Active Cyber DefencePDNS
92%
GDPR Art. 32Integrity & confidentiality
90%
SOC 2 Type IICC6.1, CC7.2
95%
Mapped automatically from policy & resolution data — export as evidence in one click.
Access control

Role-based access, enforced at the API level.

Manage your team with built-in RBAC. Admins configure everything; Editors manage policy; Viewers get read-only — and permissions hold at the API layer, not just the interface.

Three role tiers

Admin, Editor and Viewer, each with clearly scoped permissions.

API-level enforcement

Permissions can't be bypassed through the UI or direct API calls.

JWT authentication

Secure HttpOnly cookies, configurable session expiry, and every permission change recorded in the audit log.

Users & Role ManagementRBAC
LAL. AdminAdmin
NEN. EditorEditor
AVA. ViewerViewer
PermissionADMEDIVIW
View dashboard & logs
Manage blocklists
Modify DNS settings
Manage users & roles
Export audit records

DNS Security Posture Report

Executive report · generated locally · never sent off-box
PDF
957QUERIES
646ALLOWED
311BLOCKED
0.4msLATENCY
NIST 800-53CIS v8ISO 27KNCSC
Audit & compliance

Compliance reports ready to send — in one click.

Generate branded executive reports as PDF, CSV or HTML in a single click, mapped to NIST 800-53, CIS v8, ISO 27K and NCSC. Ready to hand to your auditor today.

DNS Security Posture report

Resolution outcomes, latency and top talkers, with severity ratings.

Identity & Access report

Every admin action, user change and login attempt in one export.

Generated locally

Every export is produced on your own infrastructure, never sent off-box.

Use cases

Built for the way your sector runs.

One resolver, many mandates. VeraDNS adapts to the threat model, compliance regime and scale of each kind of organization — without changing how your network works.

Enterprise IT

Agentless protection across every site and endpoint

Roll out network-wide filtering to thousands of devices — laptops, servers, BYOD and unmanaged IoT — without installing a thing. Policy follows the network, not the device.

How it's deployed

Point each site's internal resolvers (or DHCP) at an HA pair of VeraDNS appliances. Active Directory groups map to policies, so Finance, Engineering and Guest Wi-Fi each enforce their own rules from one console.

99.7%of malware C2 callbacks stopped at resolution
MSP & MSSP

Multi-tenant policy and per-client reporting from one console

Isolate every client in its own tenant with separate policy, branding and audit trail. Push a baseline globally, tune per customer, and hand each one a clean monthly report.

How it's deployed

Spin up a tenant per client, apply your managed baseline, and white-label the portal and monthly PDF. New customers go live just by repointing their resolver — no on-site visit.

40+client tenants served per appliance
Education

Safe, compliant browsing for students on any device

Enforce age-appropriate filtering and block proxies, malware and adult content across campus Wi-Fi and 1:1 devices — with the category logs auditors ask for.

How it's deployed

Deploy at the district gateway and sync with your SIS / Google Workspace so student, staff and lab devices inherit the right filtering tier. Block-page messaging is branded per school.

CIPAaligned content filtering & reporting
Healthcare

Protect PHI and medical IoT you can't put an agent on

Shield infusion pumps, imaging systems and EHR workstations from C2 and data exfiltration at the DNS layer — segmenting clinical VLANs without disrupting care.

How it's deployed

Sit VeraDNS between clinical VLANs and the internet. Biomedical IoT and EHR subnets get strict allowlists; guest Wi-Fi gets standard filtering — every query logged for HIPAA audits.

HIPAAsupports §164.312 technical safeguards
Finance & Fintech

Stop phishing and exfiltration before the session opens

Block newly-registered domains, lookalike phishing and DNS-tunnelling exfil in real time — adding negligible latency to trading and core-banking traffic.

How it's deployed

Run inline on core-banking and trading segments with sub-millisecond caching, then stream the query log to your SIEM and SOC for real-time tunnelling and beaconing detection.

<0.4msadded resolution latency
Government

Sovereign, on-prem DNS with a complete audit trail

Keep every query inside your perimeter — no third-party cloud, air-gap-friendly deployment, and immutable logs mapped to national cyber-defence standards.

How it's deployed

Install fully on-prem or air-gapped with signed threat-feed updates. RBAC and immutable logs satisfy auditors, and no query ever crosses the national boundary.

100%on-premise, zero data egress
How it stacks up

VeraDNS vs. the alternatives.

On-premise, sovereign and agent-free — compared to the protective-DNS platforms teams evaluate most.

Capability VeraDNSOn-premise Cisco UmbrellaCloud InfobloxAppliance DNSFilterCloud
On-premise & data-sovereign Appliance
Zero endpoint agents Roaming client Roaming client
Real-time threat intelligence
Full query log on your infra
One-click compliance reports Partial Partial Limited
Encrypted DNS (DoH / DoT / DNSSEC) Partial
SIEM & REST export
No per-query cloud dependency
Deploy in under an hour

// comparison based on publicly available vendor information; capabilities vary by edition and configuration.

Pricing

Plans for every scale of deployment.

Three packages that scale with your network, plus optional security add-ons. Every plan runs on your own infrastructure.

Starter

Essentials

For small teams and single-site offices getting started with network-wide DNS security.

2,000queries / sec
100users
  • RBAC — Admin & Viewer roles
  • Query log & audit log
  • Standard blocklist library
  • Email support
  • SIEM / REST API export
Contact sales
Most popular
Professional

Professional

For growing organisations needing higher throughput, richer threat feeds and SIEM integration.

10,000queries / sec
500users
  • Everything in Essentials
  • Extended blocklist library
  • SIEM & REST API export
  • Priority email & chat support
  • Custom integration development
Contact sales
Advanced

Advanced

For large enterprises and MSPs needing maximum scale, custom integrations and 24/7 SLA support.

20,000queries / sec
1,000+users
  • Everything in Professional
  • Custom integration development
  • SLA-backed 24/7 support
  • SSO via SAML 2.0 & LDAP / AD
Contact sales
Add-on

Advanced Threat

Deeper threat intelligence, malware sandboxing and command-and-control (C2) detection beyond the standard feeds.

Add-on

Advanced Analytics

Extended dashboards, behavioural anomaly detection and custom report builders for your SOC team.

Network365 · Authorized distribution

Ready to secure your network at the DNS layer?

Request a 7-day trial with full Professional-plan features, or talk to Network365 about on-premise deployment, integration and support.