DNS Shield

You have read-only access — you can see all data, but changes are disabled.
License DNS resolution and existing threat filtering continue normally. The dashboard is read-only: threat-feed updates, enrichment refresh, scheduled hunts, reports, webhooks and syslog are paused, and configuration changes are blocked until renewal. Renew under Settings → System → License.
Your subscription has lapsed — DNS resolution continues, but threat filtering, enrichment, and behavioural alerts are suspended. Contact your provider to renew.

Overview

System Health

QPS

Uptime

Disk

Load average

/ ·

Disk IO

R W MB/s

Memory

/ GB

Telemetry ingest

DNS resolution is unaffected, but some query analytics are being lost under load. Reduce the analytics footprint (shorter retention or fewer scheduled hunts), or give the appliance more resources.

Encrypted DNS no cert self-signed renewal failing

Total Queries

Blocked

Block Rate

Unique Clients

Query Volume

DNS Traffic by Country

Where the resolved answer IPs are hosted

Traffic by CDN

Answer IPs by cloud / CDN

Traffic by AS

Answer IPs by owning network (ASN + name)

Traffic by Cloud Region

Answer IPs by AWS / Azure / GCP region

Top Domains

Domain Queries Blocked

Top Clients

IP ASN Queries

Live DNS Traffic

Time Client Domain Type RCODE

Behavioral Alerts

No alerts in the selected time range.

Blocked

Blocked queries

Distinct domains

Clients affected

Blocked by category

Share of blocked queries per policy feed in this window.

Top blocked domains

#DomainFeed HitsClients
No blocks in this window.

Top clients hitting blocks

#ClientNetworkBlocks
No blocks in this window.

Blocked queries · filtered:

TimeClient Blocked domainBlocked by
No blocked queries in this window.

Hunt

Investigate your DNS — ask a question, sweep indicators, then pivot on any endpoint or domain.

Questions

One-click investigations · hover for detail.

Risk High Medium Low

IOC sweep

Paste domains and/or IPs (space, comma or newline separated). Finds every endpoint that touched them.

Reverse lookup

An IP from a flow / firewall log → the domain(s) this resolver saw a host resolve to it ("rear view").

Passive DNS

Deduplicated collection data — which domains pointed at an IP, and which used a nameserver.

result(s)

No observations.

Saved hunts

Scheduled

Runs automatically; alerts when results appear.

Suppressed

Known-good, hidden from finding hunts.

· blocked / failed
Running…
Action
· capped at 500

Click a row for detail · click an endpoint/domain to pivot · sort by any column.

Record detail

Fields

Domain intelligence —

Loading…
⚠ Authoritative nameservers on the bulletproof watchlist:
Nameservers
Queries (window)
Distinct endpoints
Blocked
Last seen

Schedule this hunt

Runs automatically and raises an alert (and email, if configured) when it returns at least the threshold of rows.

Domain Filtering

Threat protection for isn't current. Ensure this appliance's egress IP is permitted to sync from .

Threat Categories

Select which category feeds this tenant blocks. Each is a policy feed synced from the distribution server.

No threat-feed categories defined. An admin can add them in Settings.

Threat Feed Health

Live sync state of each subscribed feed (feeds sync from ) and how many queries it blocked in the last 24h. Updates every 45s.

Feed Status Serial Last synced Rules Blocked 24h
Domain Action Added By
Domain Reason Added
None selected yet — pick from the list below.

No match — use the “Add” button to include it.

Zero-trust: every TLD is blocked except those selected. arpa stays allowed for reverse DNS. Select every TLD your users need or their lookups will fail.

The selected TLDs (and all domains under them) return NXDOMAIN for this tenant.

Threat policy administration

Global protection configuration — applies across all tenants: how blocks are served, the threat-category catalog, and the enrichment feeds that label traffic.

Block action

What clients get when a subscribed category blocks a domain. Applies to all category feeds.

Requires a wildcard *. A record at your authoritative DNS, pointing to your block page.

NXDOMAIN / NODATA / DROP block silently and won't appear on the Blocked page. Use Block page for full reporting.

Threat categories (catalog)

The global catalog tenants choose from. Each is a policy feed synced from the distribution server.

NameCategoryGroupLevelDefault
No feeds defined.

Enrichment feeds

Feed URLs for GeoIP, ASN, BGP, and cloud-provider data. Untick a source to stop loading it. These override config.yaml / env. All enrichment feeds are served from your license server, so their URLs aren't set here; the checkbox still controls whether each is loaded.

Tenants

Pick Aggregator when the netblocks are an office/college egress IP or a downstream resolver, so normal aggregate traffic doesn't trip per-device detectors.

Organization Mode Timezone CIDRs Created

Encrypted DNS

Serve DoT/DoH to your clients under your own domain, with a free Let's Encrypt cert or your own.

DoT / DoH

enabled disabled

Applying a change restarts unbound (~1s).

Requires to resolve to this appliance and inbound :80 reachable — the challenge responder is up only for the validation handshake, then torn down. Renews automatically.

Certificate: self-signed · expires

No certificate installed yet.

Clients → ·

Audit Log

Who changed what — every configuration change and login, for compliance and incident review.

Time Actor Action Target Result

No audit entries in the selected range.

Settings

Manage your account and, for admins, this appliance.

Change password

Update your dashboard login password.

Display timezone

All dashboard timestamps are shown in this timezone. Stored times stay UTC — this only changes the display.

Current:

Log Streaming (Syslog)

Stream this organisation's live DNS query log to your SIEM / syslog collector (RFC 5424). Choose protocol, format, and whether to forward all queries or blocked-only.

No destinations configured.

Email (SMTP)

Used for tenant welcome mail and threat-alert notifications.

Scheduled reports

Email a periodic summary — traffic, top blocked domains/clients, and threat / AS distribution — via the SMTP settings above. Covers all tenants.

"Send now" emails the report immediately using the saved settings — save first if you've changed anything.

Response webhooks

POST a signed alert to an EDR / NAC / SOAR endpoint when a detection at/above a severity fires — the payload carries the endpoint IP to isolate. Verify with HMAC-SHA256 (X-DNSShield-Signature).

No webhooks configured.

Endpoint identity

Map client IPs to device/user names so every screen reads "Bob's laptop" instead of 10.0.0.5. Auto-populated from DHCP leases (set identity.dhcp_leases_path); or paste a CSV (ip,hostname,user) below — each IP is filed under the tenant that owns it.

No endpoints mapped yet. Import a CSV above, or they'll auto-populate from DHCP leases.

IP Hostname User Tenant Source

License

Activate or update this appliance's license key — validated live against the license server (no restart).

Status: valid invalid / unverified no key set Trial

Feed-access netblocks

The WAN IPs / CIDRs this appliance uses to pull threat-feed zones. Reported to the license server, which grants AXFR access on the distribution server. One per line or comma-separated; leave blank to use only the auto-detected IP.

Maintenance & Backup

Configuration backup

Download a JSON backup of all configuration — tenants, CIDRs, feed subscriptions, custom blocks, whitelists, TLD policies and syslog destinations. Telemetry is not included. Secrets (license key, tokens) are excluded.

Import merges into the current config (existing tenants/feeds updated, missing ones created; CIDRs added, never removed).

Clear telemetry

Empties collected query data (query log, rollups, alerts). Tenants, feeds and all configuration are preserved. Runs live — no restart. This cannot be undone.

About

Version
Built
License
valid unverified Trial

Software Updates

Keep this appliance up to date with the latest secure release.

Current
Latest

Last checked: ·checks automatically once a day

Installs + verifies the signed binary, then restarts.

Changelog