← Back to blog

DVG Systems DNS Filtering

DNS Filtering Explained: The $2/User Security Control Most MSPs Skip

7 min read
On this page

Every time someone on your network visits a website, clicks a link, or opens a cloud app, their device sends a DNS query — essentially asking the internet, “where does this address live?” That query happens before any data is transferred, before any page loads, before any file downloads.

DNS filtering intercepts that query. It checks the destination against a constantly updated list of malicious, suspicious, and policy-violating domains — and if it finds a match, it blocks the connection before it happens. For a domain on that list, the malware never downloads, the phishing page never loads, and the ransomware never phones home. A brand-new domain nobody has classified yet can still get through, which is why it is one layer among several.

It sounds simple. It is. And that’s exactly why it’s one of the most effective security controls available to small and mid-sized businesses.

The Threat Landscape Your Business Is Navigating

Before getting into how DNS filtering works, it helps to understand what it’s protecting you from.

According to DNSFilter’s 2025 Annual Security Report, one in every 174 DNS requests is malicious — meaning that across a normal business day, across your staff, across all their devices, a meaningful percentage of the internet traffic on your network is trying to do something harmful.

Phishing attempts increased by 203% in the most recent analysis period. The 2024 Verizon Data Breach Investigations Report found that phishing was involved in 15% of all confirmed breaches — and that users often click phishing links in under 60 seconds of receiving them. Your email filter may catch many of these, but phishing links also arrive via text messages, calendar invites, Teams messages, and search engine results. DNS filtering catches them regardless of how they arrive.

And the cost of getting it wrong is significant. IBM’s 2024 Cost of a Data Breach Report put the global average cost of a data breach at $4.88 million USD — a record high, up 10% from the prior year. For small businesses, even a fraction of that cost can be existential.

What DNS Filtering Actually Does

Think of DNS filtering as a security checkpoint at the entrance to your network’s internet traffic — before anything gets in or out.

When a device on your network tries to connect to a website or online service, it first queries a DNS server to resolve the domain name to an IP address. A DNS filter sits at that point and evaluates every query against threat intelligence databases before allowing or denying the connection.

What gets blocked:

  • Phishing sites — fake login pages designed to steal your Microsoft 365, banking, or other credentials
  • Malware distribution domains — sites that silently push malicious software to your devices
  • Ransomware command-and-control (C2) servers — the servers ransomware calls home to receive instructions and exfiltrate data
  • Botnet infrastructure — networks of compromised systems used to conduct attacks
  • Newly registered domains — a large proportion of malicious domains are registered and weaponized within hours; DNS filtering can block entire categories of brand-new domains before threat intelligence has time to classify them specifically
  • Content policy violations — gambling, adult content, or other categories your organization wants blocked during business hours

What makes it powerful is that it operates at the DNS layer — before a connection is established, before a page renders, before a file download begins. For a blocked domain there is nothing to scan after the fact, because the connection never happened.

The MSP Perspective: Why We Deploy This on Every Network

From an MSP’s standpoint, DNS filtering is one of the highest signal-to-noise security controls available. Here’s why:

It’s network-wide, not device-by-device. Antivirus and endpoint protection must be installed and maintained on every device. DNS filtering, deployed at the network or via an agent, covers every device that uses your network’s DNS — including personal phones on your Wi-Fi, guest devices, smart TVs, and any device that hasn’t had its endpoint software updated — provided the firewall forces DNS through the filter so a device cannot quietly use its own resolver.

It catches what email filters miss. Email security is essential, but it only covers one delivery channel. Phishing links arrive through Teams, Slack, SMS, calendar invites, and browser search results. DNS filtering works regardless of how the link was delivered, as long as the destination is already known to be bad.

It provides visibility. A properly configured DNS filter generates logs of every DNS query on your network. For an MSP, this is valuable threat intelligence — it shows which devices are making unusual requests, which domains are being queried, and whether any machines are already compromised and communicating with known bad infrastructure. Many infections are discovered this way.

It stops ransomware mid-attack. Even if ransomware does get onto a device — through an unpatched vulnerability or a USB drive — it typically needs to communicate with a C2 server to receive its encryption key and instructions. DNS filtering blocks that communication, which can stop the ransomware from activating even after it has been installed. CISA flagged DNS-based C2 communication as a national security threat in April 2025, noting that attackers increasingly rely on fast-flux DNS techniques to maintain resilient command infrastructure.

It’s lightweight and non-intrusive. Unlike tools that inspect packet contents or proxy all web traffic, DNS filtering adds negligible latency and requires no complex configuration on individual devices.

Common Objections — and the Honest Answers

“Won’t it block legitimate sites?”

False positives exist but are manageable. Enterprise-grade DNS filtering solutions (Cisco Umbrella, DNSFilter, TitanHQ, and others) use AI-based categorization and have override mechanisms. An MSP will tune the policy for your environment. The rare false positive is a minor inconvenience; a successful ransomware attack is not.

“We already have antivirus.”

Antivirus and DNS filtering are complementary, not redundant. Antivirus catches malicious files after they arrive on a device. DNS filtering prevents the device from connecting to the source in the first place. Layered security is the standard because no single control catches everything.

“Our staff are careful about what they click.”

The 2024 Verizon DBIR found that users click phishing links in under 60 seconds. Training matters — but it is not a substitute for a technical control. DNS filtering doesn’t rely on anyone making the right decision in a moment of distraction or pressure.

“We’re too small to be a target.”

Automated attacks don’t select targets by size. They scan for vulnerability. Small businesses are frequently targeted precisely because attackers assume their defences are weaker — and are often right. DNSFilter’s 2025 report notes that 32% of malware is now delivered via web-based channels, which DNS filtering directly addresses.

What Good DNS Filtering Looks Like in Practice

A well-deployed DNS filtering setup for a small business typically includes:

  • Threat category blocking — malware, phishing, botnet, cryptomining, and newly registered domains blocked by default
  • Content policy — optionally blocking categories like gambling or adult content during business hours, based on the organization’s needs
  • Agent-based coverage — an agent on company laptops ensures filtering applies even when staff are working from home, a coffee shop, or a client site — not just on the office network
  • Logging and alerting — query logs reviewed by the MSP for anomalies; alerts on high-risk activity
  • Regular policy review — categories and exceptions reviewed as the organization’s tools and needs change

The Bottom Line

DNS filtering is not a complex or expensive control. It is a well-established, proven layer of network security that catches a significant proportion of threats before they can cause harm — at the DNS query level, before any connection is established.

For an MSP, it is one of the first controls we recommend because the ratio of protection to cost and complexity is exceptional. For a business owner, the question to ask your IT provider is simple: Is DNS filtering deployed on our network, and what is it currently blocking?

If they can’t answer that question clearly, it may be time to have a broader conversation about your security posture.

DVG Systems deploys and manages DNS filtering for Northern Ontario businesses as part of our managed security stack. If you’d like to know what’s currently hitting your network — or want a no-obligation review of your current protections — get in touch today.

Ask AI

Accessibility