DNS Shield

Made in 🇮🇳 for the 🌍

DNSShield

Software License Agreement

Please review and accept to continue

Agreement version · Effective 13 August 2026

DNS Shield Software License Agreement

Agreement Version: · Effective Date: 13 August 2026

This DNS Shield Software License Agreement (“Agreement”) is between Shreshta IT Technologies Pvt. Ltd., Belagavi, Karnataka (“Shreshta”, “Vendor”, “we” or “us”) and the organisation or person for whom DNS Shield has been purchased or activated (“Customer” or “you”).

By selecting “I Accept”, the person accepting this Agreement confirms that they have authority to bind the Customer. If you do not agree or do not have this authority, do not accept the Agreement or use the Software.

1. Software covered

“Software” means the DNS Shield protective-DNS software — its recursive DNS resolution, DNS filtering, query analytics, threat detection and investigation features, its administration dashboard, documentation, updates and upgrades supplied by Shreshta.

DNS Shield is software installed on a Customer-provided dedicated system, physical server or virtual machine. It is not server hardware, an operating system, an Internet connection, a public DNS service or an independent security-monitoring service.

2. Licence grant

Subject to payment of applicable charges and compliance with this Agreement, Shreshta grants the Customer a limited, non-exclusive licence to:

  • Install and operate DNS Shield on one licensed dedicated system, physical server or virtual machine.
  • Use DNS Shield to provide DNS resolution, filtering and monitoring for the Customer’s own networks and internal business activities.
  • Permit the Customer’s employees, authorised users and service providers to access DNS Shield on the Customer’s behalf.
  • Where the applicable quotation licenses a multi-tenant deployment, serve the networks and tenants identified in that quotation.

All rights not expressly granted under this Agreement remain with Shreshta.

3. Perpetual, trial and term licences

A paid perpetual DNS Shield licence remains valid for the licensed deployment unless terminated for a material breach of this Agreement.

Expiry of Update & Upgrade coverage does not terminate a paid perpetual licence. The installed and licensed Software version may continue to be used after update coverage expires.

Trial, proof-of-concept and fixed-term licences are valid only until the expiry date shown in DNS Shield or specified in the applicable quotation. Administrative functions and paid features may be restricted when such a licence expires.

4. Activation, licence verification and what is transmitted

DNS Shield requires a valid licence key and online activation.

For activation, licence validation, entitlement management, update checking and threat-feed provisioning, DNS Shield may transmit the following to Shreshta’s licensing infrastructure:

  • Licence key
  • A hardware identifier derived from the system hostname and network interface addresses
  • Installed DNS Shield version and system architecture
  • Deployment mode, licence status and validation timestamps
  • The network ranges the appliance transfers threat feeds from, where the Customer has configured them, so that feed access can be authorised
  • In a multi-tenant deployment, the tenant identifiers and tenant names configured by the Customer, so that per-tenant entitlements can be managed

DNS Shield does not transmit DNS query logs, queried or resolved domain names, client IP addresses, answers or any other DNS telemetry to Shreshta as part of licence activation, validation, entitlement management or update checking. That data remains on the Customer’s appliance.

DNS Shield periodically validates the licence. If validation cannot be completed beyond the applicable grace period, administrative functions may enter read-only mode and paid features may pause until validation succeeds. DNS resolution and filtering are not intentionally stopped solely because a licence cannot temporarily be validated.

The Customer must not share, publish, duplicate or attempt to circumvent a DNS Shield licence key or activation control.

5. Licence transfer

The licence is tied to the activated physical server or virtual machine.

One complimentary licence transfer is permitted during a rolling 12-month period for a verified system or hardware failure or replacement. Additional transfers require prior written approval from Shreshta and may be chargeable.

The Customer may not sell, rent, sublicense, assign or transfer the Software or licence to another organisation without prior written approval from Shreshta.

6. Updates and upgrades

Unless the applicable quotation states otherwise:

  • The first 12 months of updates and upgrades begin on the activation date.
  • Updates, fixes, compatibility improvements, enhancements, new features and continued threat-feed access require active Update & Upgrade coverage.
  • After coverage expires, the installed licensed version continues to operate, but access to later releases may be restricted.
  • Renewal within 30 days of coverage expiry may be charged at the standard annual renewal price.
  • Reinstatement pricing may apply after 30 days.
  • Missed years are not back-billed.

Updates may change functionality, system requirements or compatibility. The Customer is responsible for reviewing update information and maintaining a suitable system configuration.

7. Permitted and prohibited use

The Customer must not:

  • Copy the Software except for a lawful backup or installation copy.
  • Modify, adapt, translate, decompile, disassemble or reverse engineer the Software, except where applicable law expressly permits it.
  • Remove or alter copyright, trademark, ownership or licence notices.
  • Bypass or interfere with licence validation, security controls or usage restrictions.
  • Distribute, sublicense, resell, host or commercially provide the Software, or DNS resolution based on it, to another organisation without written permission.
  • Operate DNS Shield as an open resolver, or otherwise permit DNS resolution for networks the Customer does not control or is not licensed to serve.
  • Redistribute, republish or resell the threat-intelligence feeds supplied with DNS Shield, or use them independently of the Software.
  • Use DNS Shield for unlawful activities, or to intercept or monitor traffic without the authority to do so.
  • Expose the DNS Shield administration dashboard directly to the public Internet.

Secure remote access to the dashboard should be provided through a properly configured VPN or another approved secure-access solution.

8. Customer infrastructure and responsibilities

The Customer is responsible for providing and maintaining:

  • A compatible dedicated system, physical server or virtual machine, and a supported operating system.
  • Adequate processor, memory, storage and network capacity for the Customer’s query volume and chosen retention period.
  • A static address, an unshared DNS service port, and the outbound network access DNS Shield requires for resolution, threat feeds, enrichment and licensing.
  • Correct system time and administrative access.
  • UPS protection and appropriate physical security.
  • Secure administrator accounts, passwords and access control for the dashboard.
  • Operating-system and third-party security updates.
  • Endpoint security and network protection.
  • Independent backups of configuration, recovery testing and business-continuity arrangements.

The Customer must ensure that its installation and use of DNS Shield, including the collection and retention of DNS query data about its users, complies with applicable laws, contractual requirements and sector-specific obligations.

9. Installation and support

Where included in the quotation, one standard remote installation and activation may be provided, subject to system readiness, compatible infrastructure, working network and Internet access, availability of administrative credentials, and mutually agreed scheduling.

Unless separately quoted, installation does not include hardware supply, operating-system installation, onsite work, network redesign, client reconfiguration, policy design or integration with third-party systems.

Complimentary support is limited to DNS Shield Software. Hardware, operating-system, Internet, network and third-party software issues are excluded.

No guaranteed response time, resolution time or service level applies unless agreed in a separate written support agreement.

10. Customer data and DNS telemetry

The Customer retains ownership and control of all DNS query records, client identifiers, alerts, configuration and other data stored or processed by DNS Shield on its appliance.

DNS query data can reveal the browsing and application activity of identifiable individuals. The Customer is responsible for:

  • Having a lawful basis to collect, store and process that data, and for any notice or consent its jurisdiction requires.
  • Configuring a retention period appropriate to its legal and business obligations.
  • Managing dashboard access, roles and permissions.
  • Responding to requests relating to personal or regulated data.
  • Deciding what is forwarded to any third-party system it configures, including log-streaming destinations and response webhooks.

Shreshta does not claim ownership of Customer data and does not receive Customer DNS telemetry in the ordinary operation of the Software.

If the Customer authorises remote support, Shreshta may access system information or Customer data only to the extent reasonably necessary to provide that support.

11. Threat intelligence and third-party services

DNS Shield relies on threat-intelligence feeds, reputation data, geolocation and network-ownership data, and other third-party software, services or rule repositories, including operating-system components.

These components may be governed by separate third-party terms and licences, and their availability, contents and accuracy may change without notice.

Feed contents are compiled from sources believed to be reliable but are provided without warranty of accuracy or completeness.

12. Filtering, detection and investigation features

DNS Shield’s filtering, behavioural detection, alerting, hunting and response features are designed to assist with identifying and containing suspicious activity.

These features:

  • Do not guarantee that every malicious domain, campaign or technique will be detected or blocked.
  • Do not guarantee prevention of malware, phishing, data exfiltration or unauthorised access.
  • Will produce false-positive and false-negative results, and may block legitimate domains or permit harmful ones.
  • Do not replace endpoint protection, email security, network security, patching or user awareness.
  • Depend on third-party feed contents and on the Customer’s own configuration, subscriptions and policy choices.

The Customer is responsible for reviewing alerts and findings, for validating them before acting, and for maintaining its own whitelists where a filtering decision affects business-critical services.

13. DNS availability and dependency

DNS resolution is critical infrastructure. Configuring endpoints to use DNS Shield makes the appliance, its host, and the Customer’s network path to it a dependency of the Customer’s DNS service.

The Customer is responsible for designing for that dependency, including configuring a secondary or fallback resolver, monitoring availability, and maintaining a documented procedure to restore resolution if the appliance, its host or its network becomes unavailable.

Shreshta does not warrant uninterrupted DNS resolution and is not responsible for loss arising from the Customer’s failure to provide for resolver redundancy.

14. Intellectual property

DNS Shield and its original components, interface, design, documentation, trademarks and related intellectual property are owned by Shreshta IT Technologies Pvt. Ltd. or its licensors.

The purchase of a licence does not transfer ownership of the Software or its intellectual property to the Customer.

Third-party and open-source components remain subject to their respective licences.

15. Warranty disclaimer

Except for any warranty expressly stated in the applicable quotation, and to the maximum extent permitted by law, DNS Shield is provided on an “as available” basis.

Shreshta does not warrant that:

  • The Software will operate without interruption or error.
  • Every defect will be corrected.
  • The Software will detect or prevent every security incident.
  • Filtering decisions will be free of false positives or false negatives.
  • Collected telemetry will always be complete or recoverable.
  • The Software will meet requirements not stated in the applicable documentation or quotation.
  • The Software will remain compatible with unsupported hardware, operating systems or third-party components.

Nothing in this Agreement excludes a warranty or right that cannot lawfully be excluded.

16. Limitation of liability

To the maximum extent permitted by law, Shreshta will not be liable for indirect, incidental, special, punitive or consequential loss, including loss of profit, revenue, business opportunity, goodwill, data or business continuity, or for loss arising from a domain being blocked or not being blocked.

Shreshta’s total aggregate liability arising from the affected DNS Shield licence will not exceed the total amount actually paid by the Customer for that licence.

This limitation does not apply to fraud, wilful misconduct or any liability that cannot lawfully be excluded or limited.

17. Suspension and termination

Shreshta may suspend licence services or terminate this Agreement if the Customer:

  • Materially breaches this Agreement and fails to remedy the breach after notice.
  • Circumvents or attempts to circumvent licence controls.
  • Uses an unauthorised, altered or duplicated licence.
  • Unlawfully distributes or sublicenses the Software or the supplied threat-intelligence feeds.
  • Operates the Software as an open resolver or for networks it is not licensed to serve.
  • Uses the Software for unlawful activities.

On termination, the Customer must stop using and uninstall the Software, and reconfigure its endpoints to use an alternative resolver.

Termination will not automatically delete Customer data held on the appliance. The Customer remains responsible for exporting and protecting its data before uninstalling or decommissioning DNS Shield.

Expiry of Update & Upgrade coverage alone does not terminate a paid perpetual licence.

18. Changes to this Agreement

Shreshta may update this Agreement to reflect changes in the Software, licensing model or applicable law.

When a material change requires renewed acceptance, DNS Shield will display the updated agreement and request acceptance before continued administrative use.

A new agreement version does not retroactively remove perpetual licence rights already purchased, except where required by law or agreed in writing.

19. Governing law and jurisdiction

This Agreement is governed by the laws of India.

The parties should first attempt to resolve any dispute through good-faith discussions. Subject to applicable law, courts having jurisdiction in Belagavi, Karnataka will have jurisdiction over disputes arising from this Agreement.

20. Entire agreement and order of precedence

This Agreement, together with the applicable quotation, invoice, order form and any separately signed support or service agreement, forms the agreement governing the Customer’s use of DNS Shield.

If there is a conflict:

  1. A separately signed agreement takes precedence.
  2. The applicable quotation or order governs commercial terms.
  3. This Software License Agreement governs use of the Software.
  4. Product documentation governs operational instructions.

If any provision is found unenforceable, the remaining provisions will continue to apply.

Technical Support

  • Technical support is available by email at support@shreshtait.com.
  • Standard support hours are 09:30 AM to 05:30 PM IST, Monday to Saturday, excluding national holidays, Karnataka public holidays and company-declared holidays.
  • Requests received outside standard support hours will be reviewed during the next applicable support day.
  • Support requests must be submitted by the Customer’s authorised administrator or designated technical contact.
  • Support is provided on a reasonable-efforts basis and is limited to DNS Shield Software and supported DNS Shield configurations.
  • The Customer may be required to provide its licence key, DNS Shield version, system information, relevant logs, screenshots and a clear description of the issue.
  • Remote access may be required for diagnosis. It will be performed only with the Customer’s authorisation and using a mutually approved secure-access method.
  • Shreshta will access Customer data during support only when reasonably necessary, authorised by the Customer and relevant to resolving the reported issue.
  • Complimentary support applies to the current supported DNS Shield release and versions covered by an active Update & Upgrade Plan.
  • Support for an older DNS Shield version may be limited where the issue has already been corrected in a newer release.
  • Hardware, operating-system, network, Internet, third-party software and general system-administration issues are excluded unless separately quoted.
  • Technical support does not include continuous monitoring, managed administration, alert triage, policy administration or operation of the Customer’s infrastructure.
  • Support does not include guaranteed response times, resolution times or service levels unless stated in a separately signed support agreement.
  • Emergency, onsite and after-hours support are not included unless separately agreed and may be chargeable.
  • Shreshta may decline or postpone support where the system is unsafe to access, unsupported, materially modified, exposed directly to the public Internet or operated in violation of this Agreement.

21. Contact information

Shreshta IT Technologies Pvt. Ltd.
Sateri Niwas, Rani Laxmibai Road, Hindu Nagar
Tilakwadi, Belagavi, Karnataka 590006
Website: https://shreshtait.com
Email: info@shreshtait.com

Acceptance statement

I have read and agree to the DNS Shield Software License Agreement. I confirm that I am authorised to accept this Agreement on behalf of the Customer.

DNSShield

Activate your licence

Enter the licence key supplied by Shreshta to activate this appliance.

Without a licence the dashboard is read-only and paid features pause. DNS resolution and filtering keep running either way. You can add the key later under Settings → License.

You have read-only access — you can see all data, but changes are disabled.
License DNS resolution and existing threat filtering continue normally. The dashboard is read-only: threat-feed updates, enrichment refresh, scheduled hunts, reports, webhooks and syslog are paused, and configuration changes are blocked until renewal. Renew under Settings → System → License.
Your subscription has lapsed — DNS resolution continues, but threat filtering, enrichment, and behavioural alerts are suspended. Contact your provider to renew.
DNSShield is available — you are on .

Overview

System Health

QPS

Uptime

Disk

Load average

/ ·

Disk IO

R W MB/s

Memory

/ GB

Telemetry ingest

DNS resolution and filtering are unaffected — the resolver is a separate service. Query analytics are not being recorded until the analytics engine is reachable again; no restart is needed once it is.

DNS resolution is unaffected, but some query analytics are being lost under load. Reduce the analytics footprint (shorter retention or fewer scheduled hunts), or give the appliance more resources.

Encrypted DNS no cert self-signed renewal failing

Total Queries

Blocked

Block Rate

Unique Clients

Query Volume

DNS Traffic by Country

Where the resolved answer IPs are hosted

Traffic by CDN

Answer IPs by cloud / CDN

Traffic by AS

Answer IPs by owning network (ASN + name)

Traffic by Cloud Region

Answer IPs by AWS / Azure / GCP region

Top Domains

Domain Queries Blocked

Top Clients

IP ASN Queries

Live DNS Traffic

Time Client Domain Type RCODE

Behavioral Alerts

Silenced alerts

Patterns marked as expected. Detection still runs — these findings are simply not raised.

ScopeValueDetectorAdded by

Nothing is silenced.

No alerts in the selected time range.

Blocked

Blocked queries

Distinct domains

Clients affected

Blocked by category

Share of blocked queries per policy feed in this window.

Top blocked domains

#DomainFeed HitsClients
No blocks in this window.

Top clients hitting blocks

#ClientNetworkBlocks
No blocks in this window.

Blocked queries · filtered:

TimeClient Blocked domainBlocked by
No blocked queries in this window.

Hunt

Investigate your DNS — ask a question, sweep indicators, then pivot on any endpoint or domain.

Questions

One-click investigations · hover for detail.

Risk High Medium Low

Search domains & IPs

One domain or a whole IOC list — space, comma or newline separated. Matches the apex and every subdomain, plus answer IPs, and finds every endpoint that touched them over the selected time range. Searching the whole tenant fleet — results show which tenant each hit belongs to. Scoped to the selected tenant; clear the tenant filter to search the whole fleet.

Reverse lookup

An IP from a flow / firewall log → the domain(s) this resolver saw a host resolve to it ("rear view").

Trace resolution

Resolves a name from the root servers and through this appliance, then compares them — so "we can't resolve X" gets a definite answer.

From the root servers

From this appliance

Delegation chain

Passive DNS

Deduplicated collection data — which domains pointed at an IP, and which used a nameserver.

result(s)

No observations.

Saved hunts

Scheduled

Runs automatically; alerts when results appear.

Suppressed

Known-good, hidden from finding hunts.

· blocked / failed
Running…
Action
· capped at 500

Click a row for detail · click an endpoint/domain to pivot · sort by any column.

Record detail

Fields

Domain intelligence —

Loading…
⚠ Authoritative nameservers on the bulletproof watchlist:
Nameservers
Queries (window)
Distinct endpoints
Blocked
Last seen

Schedule this hunt

Runs automatically and raises an alert (and email, if configured) when it returns at least the threshold of rows.

Domain Filtering

Threat protection for isn't current.

Threat Categories

Select which category feeds this tenant blocks. Each is a policy feed synced from the distribution server.

No threat-feed categories defined. An admin can add them in Settings.

Threat Feed Health

Live sync state of each subscribed feed (feeds sync from ) and how many queries it blocked in the last 24h. Updates every 45s. Feeds are re-checked automatically every couple of minutes and re-transfer only when their content changes — so an older “last changed” means nothing new upstream, not a stale feed.

Feed Status Serial Last changed Rules Blocked 24h
Domain Action Added By
Domain Reason Added
None selected yet — pick from the list below.

No match — use the “Add” button to include it.

Zero-trust: every TLD is blocked except those selected. arpa stays allowed for reverse DNS. Select every TLD your users need or their lookups will fail.

The selected TLDs (and all domains under them) return NXDOMAIN for this tenant.

Threat policy administration

Global protection configuration — applies across all tenants: how blocks are served, the threat-category catalog, and the enrichment feeds that label traffic.

Block action

What clients get when a subscribed category blocks a domain. Applies to all category feeds.

Requires a wildcard *. A record at your authoritative DNS, pointing to your block page.

NXDOMAIN / NODATA / DROP block silently and won't appear on the Blocked page. Use Block page for full reporting.

Threat categories (catalog)

The global catalog tenants choose from. Each is a policy feed synced from the distribution server.

NameCategoryGroupLevelDefaultAll tenants
No feeds defined.

Enrichment feeds

Feed URLs for GeoIP, ASN, BGP, and cloud-provider data. Untick a source to stop loading it. These override config.yaml / env. All enrichment feeds are served from your license server, so their URLs aren't set here; the checkbox still controls whether each is loaded.

Local Zones

Your own internal forward and reverse zones, answered by this appliance.

Internal DNS zones

Your own forward and reverse zones, answered locally for this tenant. Internal names are resolved before any threat feed is consulted, so a hostname of yours can never be blocked by a category.

Leave blank to detect it from the export. Required when creating an empty zone.

Chosen automatically for this zone — change it if you prefer.

This zone already exists. Importing replaces it — the record(s) marked “removed” below will be deleted, including any you added by hand.

line(s) could not be read and were left out. SOA and NS rows are ignored on purpose and are not listed here.

Zone Records Unknown names TTL

Tenants

Pick Aggregator when the netblocks are an office/college egress IP or a downstream resolver, so normal aggregate traffic doesn't trip per-device detectors.

Organization Mode Timezone CIDRs Created

Encrypted DNS

Serve DoT/DoH to your clients under your own domain, with a free Let's Encrypt cert or your own.

DoT / DoH

enabled disabled

Applying a change briefly restarts the resolver (~1s).

Requires to resolve to this appliance and inbound :80 reachable — the challenge responder is up only for the validation handshake, then torn down. Renews automatically.

Certificate: self-signed · expires

No certificate installed yet.

Clients → ·

Audit Log

Who changed what — every configuration change and login, for compliance and incident review.

Time Actor Action Target Result

No audit entries in the selected range.

Settings

Manage your account and, for admins, this appliance.

Change password

Update your dashboard login password.

Two-factor authentication

Add a time-based code from an authenticator app (Google Authenticator, Authy, 1Password) on top of your password. Even a stolen or brute-forced password can't sign in without your device.

Display timezone

All dashboard timestamps are shown in this timezone. Stored times stay UTC — this only changes the display.

Current:

Log Streaming (Syslog)

Stream this organisation's live DNS query log to your SIEM / syslog collector (RFC 5424). Choose protocol, format, and whether to forward all queries or blocked-only.

No destinations configured.

Email (SMTP)

Used for tenant welcome mail and threat-alert notifications.

Scheduled reports

Email a periodic summary — traffic, top blocked domains/clients, and threat / AS distribution — via the SMTP settings above. Covers all tenants.

"Send now" emails the report immediately using the saved settings — save first if you've changed anything.

Response webhooks

POST a signed alert to an EDR / NAC / SOAR endpoint when a detection at/above a severity fires — the payload carries the endpoint IP to isolate. Verify with HMAC-SHA256 (X-DNSShield-Signature).

No webhooks configured.

Endpoint identity

Map client IPs to device/user names so every screen reads "Bob's laptop" instead of 10.0.0.5. Auto-populated from DHCP leases (set identity.dhcp_leases_path); or paste a CSV (ip,hostname,user) below — each IP is filed under the tenant that owns it.

No endpoints mapped yet. Import a CSV above, or they'll auto-populate from DHCP leases.

IP Hostname User Tenant Source

License

Activate or update this appliance's license key — validated live against the license server (no restart).

Status: valid invalid / unverified no key set Trial

Feed-access netblocks

The WAN IPs / CIDRs this appliance uses to pull threat-feed zones. Reported to the license server, which grants AXFR access on the distribution server. One per line or comma-separated; leave blank to use only the auto-detected IP.

Dashboard HTTPS

serving HTTPS HTTP only

Serve this dashboard over HTTPS on your own hostname, with your own certificate. No internet access required.

The key is stored on the appliance and never shown again.

Installed:

Expires — expired

This certificate does not cover the hostname above — browsers will reject it.

Saved, but HTTPS could not start:

Saved. Let's Encrypt issuance starts when DNS Shield next restarts.

HTTPS is live now — no restart needed. Reach the dashboard at . Plain HTTP stays available, so you cannot lock yourself out.

Resolver

Whether the resolver is actually running the configuration DNS Shield generated for it.

Engine
Configuration
valid invalid not verified not checked This can take a minute and is CPU-intensive on appliances with large feeds.
In effect
running the current config reload pending
IPv6

The resolver configuration has been edited outside DNS Shield. It is generated — manual changes are reverted automatically and recorded in the .

Listening on

IPv6

active unavailable off

Answer queries from IPv6 clients, and allow IPv6 transport to authoritative servers. Applying a change rebuilds the resolver config and reloads it — resolution is not interrupted.

This host cannot open an IPv6 socket — the resolver is running IPv4-only regardless of this setting. Check that IPv6 is not disabled in the kernel (ipv6.disable=1) or by sysctl, then reload this page.

IPv6 clients are refused until their prefixes are added to a tenant — set them under , the same way as IPv4 CIDRs.

Maintenance & Backup

Configuration backup

Download a JSON backup of all configuration — tenants, CIDRs, feed subscriptions, custom blocks, whitelists, TLD policies and syslog destinations. Telemetry is not included. Secrets (license key, tokens) are excluded.

Import merges into the current config (existing tenants/feeds updated, missing ones created; CIDRs added, never removed).

Clear telemetry

Empties collected query data (query log, rollups, alerts). Tenants, feeds and all configuration are preserved. Runs live — no restart. This cannot be undone.

About

Version
Built
License
valid unverified Trial

Software Updates

Keep this appliance up to date with the latest secure release.

Current
Latest

Last checked: ·checks automatically every 8 hours

Installs + verifies the signed binary, then restarts.