Overview
System Health
QPS
Uptime
Disk
Load average
/ ·
Disk IO
R W MB/s
Memory
/ GB
DNS resolution and filtering are unaffected — the resolver is a separate service. Query analytics are not being recorded until the analytics engine is reachable again; no restart is needed once it is.
DNS resolution is unaffected, but some query analytics are being lost under load. Reduce the analytics footprint (shorter retention or fewer scheduled hunts), or give the appliance more resources.
Total Queries
—
Blocked
—
Block Rate
—
Unique Clients
—
Query Volume
DNS Traffic by Country
Where the resolved answer IPs are hosted
Traffic by CDN
Answer IPs by cloud / CDN
Traffic by AS
Answer IPs by owning network (ASN + name)
Traffic by Cloud Region
Answer IPs by AWS / Azure / GCP region
Top Domains
| Domain | Queries | Blocked |
|---|---|---|
| blocked |
Top Clients
| IP | ASN | Queries |
|---|---|---|
Live DNS Traffic
| Time | Client | Domain | Type | RCODE | |
|---|---|---|---|---|---|
| VPN |
|
||||
|
Flags:
Answers:
Authority:
Blocked by:
Threat intel:
Cloud:
Region:
Answer AS:
Answer geo:
Client:
VPN
Answer section Authority section No answer or authority records captured for this query. |
|||||
Behavioral Alerts
Silenced alerts
Patterns marked as expected. Detection still runs — these findings are simply not raised.
| Scope | Value | Detector | Added by | |
|---|---|---|---|---|
Nothing is silenced.
No alerts in the selected time range.
Blocked
Blocked queries
Distinct domains
Clients affected
Blocked by category
Share of blocked queries per policy feed in this window.
Top blocked domains
| # | Domain | Feed | Hits | Clients |
|---|---|---|---|---|
| No blocks in this window. | ||||
Top clients hitting blocks
| # | Client | Network | Blocks |
|---|---|---|---|
| No blocks in this window. | |||
Blocked queries · filtered:
| Time | Client | Blocked domain | Blocked by |
|---|---|---|---|
| No blocked queries in this window. | |||
Hunt
Investigate your DNS — ask a question, sweep indicators, then pivot on any endpoint or domain.
Questions
One-click investigations · hover for detail.
Search domains & IPs
One domain or a whole IOC list — space, comma or newline separated. Matches the apex and every subdomain, plus answer IPs, and finds every endpoint that touched them over the selected time range. Searching the whole tenant fleet — results show which tenant each hit belongs to. Scoped to the selected tenant; clear the tenant filter to search the whole fleet.
Reverse lookup
An IP from a flow / firewall log → the domain(s) this resolver saw a host resolve to it ("rear view").
Trace resolution
Resolves a name from the root servers and through this appliance, then compares them — so "we can't resolve X" gets a definite answer.
From the root servers
From this appliance
Delegation chain
Passive DNS
Deduplicated collection data — which domains pointed at an IP, and which used a nameserver.
— result(s)
No observations.
Saved hunts
Scheduled
Runs automatically; alerts when results appear.
Suppressed
Known-good, hidden from finding hunts.
| Action | |
|---|---|
Click a row for detail · click an endpoint/domain to pivot · sort by any column.
Record detail
Fields
Domain intelligence —
Schedule this hunt
Runs automatically and raises an alert (and email, if configured) when it returns at least the threshold of rows.
Domain Filtering
Threat protection for isn't current. No feed is syncing at all — check that this appliance's egress IP is permitted to sync from , and that outbound TCP 53 to it is open. Other feeds are syncing from , so this is specific to these zones rather than a connectivity or permission problem — the zone is likely missing, empty or unloadable on the distribution server. Report these zone names to Shreshta.
Threat Categories
Select which category feeds this tenant blocks. Each is a policy feed synced from the distribution server.
No threat-feed categories defined. An admin can add them in Settings.
Threat Feed Health
Live sync state of each subscribed feed (feeds sync from ) and how many queries it blocked in the last 24h. Updates every 45s. Feeds are re-checked automatically every couple of minutes and re-transfer only when their content changes — so an older “last changed” means nothing new upstream, not a stale feed.
| Feed | Status | Serial | Last changed | Rules | Blocked 24h | |
|---|---|---|---|---|---|---|
| Domain | Action | Added | By | |
|---|---|---|---|---|
| Domain | Reason | Added | |
|---|---|---|---|
Threat policy administration
Global protection configuration — applies across all tenants: how blocks are served, the threat-category catalog, and the enrichment feeds that label traffic.
Block action
What clients get when a subscribed category blocks a domain. Applies to all category feeds.
Requires a wildcard *. A record at your authoritative DNS, pointing to your block page.
NXDOMAIN / NODATA / DROP block silently and won't appear on the Blocked page. Use Block page for full reporting.
Threat categories (catalog)
The global catalog tenants choose from. Each is a policy feed synced from the distribution server.
| Name | Category | Group | Level | Default | All tenants | |
|---|---|---|---|---|---|---|
| onoff | ||||||
| No feeds defined. | ||||||
Enrichment feeds
Feed URLs for GeoIP, ASN, BGP, and cloud-provider data. Untick a source to stop loading it. These override config.yaml / env. All enrichment feeds are served from your license server, so their URLs aren't set here; the checkbox still controls whether each is loaded.
Local Zones
Your own internal forward and reverse zones, answered by this appliance.
Internal DNS zones
Your own forward and reverse zones, answered locally for this tenant. Internal names are resolved before any threat feed is consulted, so a hostname of yours can never be blocked by a category.
Leave blank to detect it from the export. Required when creating an empty zone.
Chosen automatically for this zone — change it if you prefer.
This zone already exists. Importing replaces it — the record(s) marked “removed” below will be deleted, including any you added by hand.
line(s) could not be read and were left out. SOA and NS rows are ignored on purpose and are not listed here.
| Zone | Records | Unknown names | TTL | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||
Tenants
| Organization | Mode | Timezone | CIDRs | Created | |
|---|---|---|---|---|---|
|
Aggregator Suspended |
|||||
|
Users — No users yet. Syslog Streaming (read-only — the tenant manages these)
·
·
·
enableddisabled
No syslog destinations. |
|||||
Encrypted DNS
Serve DoT/DoH to your clients under your own domain, with a free Let's Encrypt cert or your own.
DoT / DoH
enabled disabledApplying a change briefly restarts the resolver (~1s).
Requires to resolve to this appliance and inbound :80 reachable — the challenge responder is up only for the validation handshake, then torn down. Renews automatically.
Certificate: self-signed · expires
No certificate installed yet.
Clients → ·
Audit Log
Who changed what — every configuration change and login, for compliance and incident review.
| Time | Actor | Action | Target | Result |
|---|---|---|---|---|
No audit entries in the selected range.
Settings
Manage your account and, for admins, this appliance.
Change password
Update your dashboard login password.
Two-factor authentication
Add a time-based code from an authenticator app (Google Authenticator, Authy, 1Password) on top of your password. Even a stolen or brute-forced password can't sign in without your device.
recovery codes remaining.
1. Scan this QR in your authenticator app:
Can't scan? Enter this key manually:
2. Enter the 6-digit code to confirm:
✓ Two-factor is now enabled.
Save these one-time recovery codes somewhere safe — each signs you in once if you lose your device. They won't be shown again.
Display timezone
All dashboard timestamps are shown in this timezone. Stored times stay UTC — this only changes the display.
Current:
Log Streaming (Syslog)
Stream this organisation's live DNS query log to your SIEM / syslog collector (RFC 5424). Choose protocol, format, and whether to forward all queries or blocked-only.
· · · enableddisabled · sent · dropped · connected · error
No destinations configured.
Email (SMTP)
Used for tenant welcome mail and threat-alert notifications.
Scheduled reports
Email a periodic summary — traffic, top blocked domains/clients, and threat / AS distribution — via the SMTP settings above. Covers all tenants.
Response webhooks
POST a signed alert to an EDR / NAC / SOAR endpoint when a detection at/above a severity fires — the payload carries the endpoint IP to isolate. Verify with HMAC-SHA256 (X-DNSShield-Signature).
No webhooks configured.
Endpoint identity
Map client IPs to device/user names so every screen reads "Bob's laptop" instead of 10.0.0.5. Auto-populated from DHCP leases (set identity.dhcp_leases_path); or paste a CSV (ip,hostname,user) below — each IP is filed under the tenant that owns it.
No endpoints mapped yet. Import a CSV above, or they'll auto-populate from DHCP leases.
| IP | Hostname | User | Tenant | Source | |
|---|---|---|---|---|---|
License
Activate or update this appliance's license key — validated live against the license server (no restart).
Feed-access netblocks
The WAN IPs / CIDRs this appliance uses to pull threat-feed zones. Reported to the license server, which grants AXFR access on the distribution server. One per line or comma-separated; leave blank to use only the auto-detected IP.
Dashboard HTTPS
serving HTTPS HTTP onlyServe this dashboard over HTTPS on your own hostname, with your own certificate. No internet access required.
The key is stored on the appliance and never shown again.
Installed:
Expires — expired
This certificate does not cover the hostname above — browsers will reject it.
Saved, but HTTPS could not start:
Saved. Let's Encrypt issuance starts when DNS Shield next restarts.
HTTPS is live now — no restart needed. Reach the dashboard at . Plain HTTP stays available, so you cannot lock yourself out.
Resolver
Whether the resolver is actually running the configuration DNS Shield generated for it.
- Engine
- Configuration
- valid invalid not verified not checked This can take a minute and is CPU-intensive on appliances with large feeds.
- In effect
- running the current config reload pending
- IPv6
The resolver configuration has been edited outside DNS Shield. It is generated — manual changes are reverted automatically and recorded in the .
Listening on
IPv6
active unavailable offAnswer queries from IPv6 clients, and allow IPv6 transport to authoritative servers. Applying a change rebuilds the resolver config and reloads it — resolution is not interrupted.
This host cannot open an IPv6 socket — the resolver is running IPv4-only regardless of this setting. Check that IPv6 is not disabled in the kernel (ipv6.disable=1) or by sysctl, then reload this page.
IPv6 clients are refused until their prefixes are added to a tenant — set them under , the same way as IPv4 CIDRs.
Maintenance & Backup
Configuration backup
Download a JSON backup of all configuration — tenants, CIDRs, feed subscriptions, custom blocks, whitelists, TLD policies and syslog destinations. Telemetry is not included. Secrets (license key, tokens) are excluded.
Import merges into the current config (existing tenants/feeds updated, missing ones created; CIDRs added, never removed).
Clear telemetry
Empties collected query data (query log, rollups, alerts). Tenants, feeds and all configuration are preserved. Runs live — no restart. This cannot be undone.
About
- Version
- Built
- License
- valid unverified Trial
Software Updates
Keep this appliance up to date with the latest secure release.
- Current
- Latest
Last checked: ·checks automatically every 8 hours