Coverage
Two routes in, one policy set, and nothing installed on the devices that matter most.
A query reaches DNS Shield by one of two routes. Which route it takes depends on where the device is, and the same policies are applied either way.
Two routes in
Coverage is a routing decision, not a rollout project
A query reaches DNS Shield by one of two routes. Which route it takes depends on where the device is, and the same policies are applied either way.
On the corporate network, through the internal resolver
Devices carry on using the organization’s own DNS server as they always have. That server answers internal names itself and forwards external lookups to DNS Shield instead of resolving them straight from the internet. Nothing is installed on the device, so printers, cameras, medical and industrial equipment, contractor laptops and guest hardware are all covered.
Away from the corporate network, through the DNS Agent
The Agent on a managed Windows or macOS device checks whether it is on the corporate LAN. When it is not, it sends that device’s external lookups directly to DNS Shield over DNS-over-HTTPS, encrypted and signed with a token issued to that endpoint.
Both routes end at the same place: on the corporate network the internal resolver forwards external lookups; away from it the DNS Agent forwards them over authenticated DoH. One policy set applies to both.
One policy set, both routes
DNS Shield applies the same eleven policies, the same four confidence bands and the same tenant policy whichever route a query arrived by. There is no reduced off-network mode and no second policy set to keep in step.
Internal names never leave
Internal corporate domains resolve privately against the organization’s own DNS servers on both routes, so a laptop on a hotel network exposes no more internal resolution than the same laptop at a desk.
What the Agent adds
Always on
Protection follows the device when it leaves the network.
Encrypted
Authenticated DoH on the Agent route. No open resolver.
Attributed
Device, process and user carried with every query.
The Agent adds two things. Reach, so a detection on a device away from the office is produced at the same moment and to the same standard as one on the network, rather than pieced together afterward from an endpoint log. And attribution, because each forwarded query carries the device, the process that made the request and the signed-in user, established through OAuth 2.0 sign-in and a signed, time-limited token.
The Agent has no detection policies of its own.
“A device resolved a known command domain” is a verdict, while the same verdict naming the workstation, the process and the user is an incident with an owner and a next step.
How the Agent works
- A local proxy decides, query by query, whether a name is internal or external. Internal names go to corporate DNS and external names go to DNS Shield.
- Network-context detection works out whether the endpoint is on or off the corporate network, with no action from the user.
- Authenticated resolution attaches the signed per-endpoint token to every DoH request.
- Tamper-resistant enforcement keeps re-applying the local resolver setting, so neither a user nor malware can quietly repoint the endpoint, and it reports the attempt as a detection.
- Browser-native DoH is blocked on the same basis.
Supported platforms
- Windows 10 and 11
- Windows Server 2016, 2019 and 2022
- Current supported releases of macOS
Not currently supported
- Linux
- iOS
- Android
- ChromeOS
What never leaves, and what is transmitted
Buyers in regulated sectors ask three questions before any others: what leaves the organization’s own infrastructure, who can see it once it does, and how long it is kept. Split-DNS routing answers the first, and it is built into the design rather than being a setting.
What the service receives is external name resolution within the authorized scope, and nothing else. No passwords are handled at the resolution service, the token is checked cryptographically, and there is no open resolver exposed to the internet. Multi-tenancy uses row-level isolation and per-tenant quotas, and cross-tenant operations are fully audited. Every transaction is recorded with a confidence band, a technique tag and, where the Agent is deployed, the device, the process and the signed-in user. Benign resolutions are recorded as well as refused ones, because baselining depends on them.
See a verdict reach an incident
A working session on your own resolver scope, showing what a refusal looks like by the time it reaches an analyst.
Connect with the team
Book a demo
For service providers
Go to the MSSP platform
