LAYER 3 KNOWLEDGE CENTRE
DNS translates names such as website addresses into the network addresses devices use. Security filtering can stop requests to known unwanted or malicious destinations before a connection is completed.
Use this guide to understand where DNS security helps, where it does not and how it fits with device protection, updates, network security and backup.
DNS security can block or filter known malicious domains, phishing destinations and other unwanted categories. It does not replace antivirus, inspect everything on a device or guarantee that every threat will be stopped.
People remember names. Networks use addresses. DNS provides the lookup that connects the two.
A device asks which network address belongs to a requested name.
A security service can refuse, redirect or flag a destination that matches a known policy or threat category.
Protection depends on the service, policy and available threat information.
Known harmful destinations can be blocked before the normal connection completes.
Filtering can reduce access to known deceptive or dangerous sites.
Where configured, families or businesses can limit selected categories, advertisements or trackers.
It is an important control, not a complete security system.
It does not scan every file or inspect all device activity.
New, unknown or disguised threats may not yet be classified.
It cannot restore deleted, encrypted or damaged information.
Unpatched software and weak device security still create risk.
Different controls address different parts of the risk.
Reduces access to known bad or unwanted destinations.
Helps detect and control threats on endpoints.
Reduce known weaknesses and protect network boundaries.
Provides a recovery path when prevention is not enough.
Use comparisons that change one condition at a time. Record what was tested so the evidence is useful.
Devices using another resolver or encrypted DNS settings may follow a different policy.
A block may indicate a threat, a policy match or a classification that needs review.
Make sure filtering supports legitimate work, school and household needs.
Keep device protection and operating systems updated.
Use strong accounts and multi-factor authentication where available.
Maintain tested backups of important information.
Contact support if legitimate destinations are blocked or devices bypass expected policy.
Layer 3 should help when DNS filtering needs to cover several devices, business or family policies must be designed, legitimate services are blocked, or DNS security needs to form part of a broader protection plan.
Continue with a closely related explanation.
Continue with another useful route.
Use the Support Centre for account-specific checks, service diagnosis and escalation.