Overview
System Health
QPS
Uptime
Disk
Load average
/ ·
Disk IO
R W MB/s
Memory
/ GB
DNS resolution is unaffected, but some query analytics are being lost under load. Reduce the analytics footprint (shorter retention or fewer scheduled hunts), or give the appliance more resources.
Total Queries
—
Blocked
—
Block Rate
—
Unique Clients
—
Query Volume
DNS Traffic by Country
Where the resolved answer IPs are hosted
Traffic by CDN
Answer IPs by cloud / CDN
Traffic by AS
Answer IPs by owning network (ASN + name)
Traffic by Cloud Region
Answer IPs by AWS / Azure / GCP region
Top Domains
| Domain | Queries | Blocked |
|---|---|---|
| blocked |
Top Clients
| IP | ASN | Queries |
|---|---|---|
Live DNS Traffic
| Time | Client | Domain | Type | RCODE | |
|---|---|---|---|---|---|
| VPN |
|
||||
|
Flags:
Answers:
Authority:
Blocked by:
Threat intel:
Cloud:
Region:
Answer AS:
Answer geo:
Client:
VPN
Answer section Authority section No answer or authority records captured for this query. |
|||||
Behavioral Alerts
No alerts in the selected time range.
Blocked
Blocked queries
Distinct domains
Clients affected
Blocked by category
Share of blocked queries per policy feed in this window.
Top blocked domains
| # | Domain | Feed | Hits | Clients |
|---|---|---|---|---|
| No blocks in this window. | ||||
Top clients hitting blocks
| # | Client | Network | Blocks |
|---|---|---|---|
| No blocks in this window. | |||
Blocked queries · filtered:
| Time | Client | Blocked domain | Blocked by |
|---|---|---|---|
| No blocked queries in this window. | |||
Hunt
Investigate your DNS — ask a question, sweep indicators, then pivot on any endpoint or domain.
Questions
One-click investigations · hover for detail.
IOC sweep
Paste domains and/or IPs (space, comma or newline separated). Finds every endpoint that touched them.
Reverse lookup
An IP from a flow / firewall log → the domain(s) this resolver saw a host resolve to it ("rear view").
Passive DNS
Deduplicated collection data — which domains pointed at an IP, and which used a nameserver.
— result(s)
No observations.
Saved hunts
Scheduled
Runs automatically; alerts when results appear.
Suppressed
Known-good, hidden from finding hunts.
| Action | |
|---|---|
Click a row for detail · click an endpoint/domain to pivot · sort by any column.
Record detail
Fields
Domain intelligence —
Schedule this hunt
Runs automatically and raises an alert (and email, if configured) when it returns at least the threshold of rows.
Domain Filtering
Threat protection for isn't current. Ensure this appliance's egress IP is permitted to sync from .
Threat Categories
Select which category feeds this tenant blocks. Each is a policy feed synced from the distribution server.
No threat-feed categories defined. An admin can add them in Settings.
Threat Feed Health
Live sync state of each subscribed feed (feeds sync from ) and how many queries it blocked in the last 24h. Updates every 45s.
| Feed | Status | Serial | Last synced | Rules | Blocked 24h |
|---|---|---|---|---|---|
| Domain | Action | Added | By | |
|---|---|---|---|---|
| Domain | Reason | Added | |
|---|---|---|---|
Threat policy administration
Global protection configuration — applies across all tenants: how blocks are served, the threat-category catalog, and the enrichment feeds that label traffic.
Block action
What clients get when a subscribed category blocks a domain. Applies to all category feeds.
Requires a wildcard *. A record at your authoritative DNS, pointing to your block page.
NXDOMAIN / NODATA / DROP block silently and won't appear on the Blocked page. Use Block page for full reporting.
Threat categories (catalog)
The global catalog tenants choose from. Each is a policy feed synced from the distribution server.
| Name | Category | Group | Level | Default | |
|---|---|---|---|---|---|
| onoff | |||||
| No feeds defined. | |||||
Enrichment feeds
Feed URLs for GeoIP, ASN, BGP, and cloud-provider data. Untick a source to stop loading it. These override config.yaml / env. All enrichment feeds are served from your license server, so their URLs aren't set here; the checkbox still controls whether each is loaded.
Tenants
| Organization | Mode | Timezone | CIDRs | Created | |
|---|---|---|---|---|---|
|
Aggregator Suspended |
|||||
|
Users — No users yet. Syslog Streaming (read-only — the tenant manages these)
·
·
·
enableddisabled
No syslog destinations. |
|||||
Encrypted DNS
Serve DoT/DoH to your clients under your own domain, with a free Let's Encrypt cert or your own.
DoT / DoH
enabled disabledApplying a change restarts unbound (~1s).
Requires to resolve to this appliance and inbound :80 reachable — the challenge responder is up only for the validation handshake, then torn down. Renews automatically.
Certificate: self-signed · expires
No certificate installed yet.
Clients → ·
Audit Log
Who changed what — every configuration change and login, for compliance and incident review.
| Time | Actor | Action | Target | Result |
|---|---|---|---|---|
No audit entries in the selected range.
Settings
Manage your account and, for admins, this appliance.
Change password
Update your dashboard login password.
Display timezone
All dashboard timestamps are shown in this timezone. Stored times stay UTC — this only changes the display.
Current:
Log Streaming (Syslog)
Stream this organisation's live DNS query log to your SIEM / syslog collector (RFC 5424). Choose protocol, format, and whether to forward all queries or blocked-only.
· · · enableddisabled · sent · dropped · connected · error
No destinations configured.
Email (SMTP)
Used for tenant welcome mail and threat-alert notifications.
Scheduled reports
Email a periodic summary — traffic, top blocked domains/clients, and threat / AS distribution — via the SMTP settings above. Covers all tenants.
Response webhooks
POST a signed alert to an EDR / NAC / SOAR endpoint when a detection at/above a severity fires — the payload carries the endpoint IP to isolate. Verify with HMAC-SHA256 (X-DNSShield-Signature).
No webhooks configured.
Endpoint identity
Map client IPs to device/user names so every screen reads "Bob's laptop" instead of 10.0.0.5. Auto-populated from DHCP leases (set identity.dhcp_leases_path); or paste a CSV (ip,hostname,user) below — each IP is filed under the tenant that owns it.
No endpoints mapped yet. Import a CSV above, or they'll auto-populate from DHCP leases.
| IP | Hostname | User | Tenant | Source | |
|---|---|---|---|---|---|
License
Activate or update this appliance's license key — validated live against the license server (no restart).
Feed-access netblocks
The WAN IPs / CIDRs this appliance uses to pull threat-feed zones. Reported to the license server, which grants AXFR access on the distribution server. One per line or comma-separated; leave blank to use only the auto-detected IP.
Maintenance & Backup
Configuration backup
Download a JSON backup of all configuration — tenants, CIDRs, feed subscriptions, custom blocks, whitelists, TLD policies and syslog destinations. Telemetry is not included. Secrets (license key, tokens) are excluded.
Import merges into the current config (existing tenants/feeds updated, missing ones created; CIDRs added, never removed).
Clear telemetry
Empties collected query data (query log, rollups, alerts). Tenants, feeds and all configuration are preserved. Runs live — no restart. This cannot be undone.
About
- Version
- Built
- License
- valid unverified Trial
Software Updates
Keep this appliance up to date with the latest secure release.
- Current
- Latest
Last checked: ·checks automatically once a day