Your entire DNS layer, sovereign end to end
DNS Armor™ Protect stops malware, phishing and ransomware at the first query — on-premises with local AI, or cloud-delivered. DNS Armor™ Resolve serves your own zones with DNSSEC and smart-health GSLB. Two independently licensed products on one control plane — across 52 data centres in 32 countries, with query processing and log archival pinned to the region you choose.
- Global data centres
- 52
- 32 countries · 5 regions
- DNS queries processed
- 10M+
- Every day
- Active threat indicators
- 20M+
- Continuously updated
- Platform uptime
- 99.99%
- Resolution SLA
- Dubai DET Licence No. 1357380
- Regional data residency by design
- Multi-tenant for MSPs and group subsidiaries
Book your free demo
See DNS Armor™ live on your own environment. 30 minutes with a solutions architect — no credit card, no obligation.
One console for protection and authority
Real screens from the DNS Armor™ admin portal — not mockups.

DNS security overview
Query volume, firewall hits, match rate and security score across every tenant, with DNS Firewall, Authoritative DNS and Tenants as tabs on one page.
Built for the frameworks your auditor actually uses
GCC regulators have moved from broad principles to specific technical controls, and a large share of that control surface runs through DNS. Here is where the resolution layer earns you credit.
Authority
UAE Cyber Security Council
Current version
Information Assurance Standard V2
Applies to
Entities operating critical information infrastructure in the UAE. Six management and nine technical control domains.
What the framework asks at the DNS layer
What DNS Armor™ gives you to evidence it
- T4.5
Network Security Management — implementation guidance names ingress and egress filtering to permit only documented ports and protocols, and restricting access to trusted sites.
Web, application and content filtering by category, with Cloud Policies that activate on a schedule and Local Rulesets for explicit allow and block decisions.
Protect - T4.5
The same guidance names deploying Sender Policy Framework (SPF) records in DNS with receiver-side verification in mail servers.
SPF, DKIM and DMARC are published as DNS records — host those zones on DNS Armor™ Resolve with automated DNSSEC signing and keys pinned to your chosen region.
Resolve - T3
Operations Management — protection against malware and unauthorised software, and monitoring of system operations to detect and prevent incidents.
AI and behavioural detection of tunnelling, exfiltration and DGA activity, with DNS Monitor, Daily DNS Analytics and Discovery Analytics feeding your SOC.
Protect Assured availability and integrity of name resolution.
99.99% platform uptime on an anycast edge, with smart-health GSLB and priority-group failover for the zones you host.
Resolve
52 data centres. You choose which ones serve you.
DNS query processing and log archival take place within the geographic region assigned to your organisation — and do not leave it for processing or storage.
- 0
- Data centres
- 0
- Countries
- 0
- Global regions
Coverage by region
Your assigned region is a deployment choice, not a contractual promise — pin to the UAE alone, the GCC, the EU, or any combination you need.
Two licences. One control plane.
Protect and Resolve are licensed independently — hold either, or both. Both run on the same portal, the same role model and the same regional residency guarantees.
DNS Armor™ Protect
DNS firewall · protective DNS
- AI and behavioural detection of DNS tunnelling and data exfiltration
- Built-in threat feeds plus external RPZ feed ingestion and export
- Cloud Policies with time-based policy scheduling
- Web, application and content filtering
- DoH and DoT for encrypted DNS transport
- Endpoint Agent for Windows, macOS and Linux
- Local Resolver appliance in proxy or local mode
DNS Armor™ Resolve
Authoritative DNS · zone hosting
- Zone records, configuration and signing keys pinned to your region
- Smart-health GSLB with priority-group failover
- Geo and source-IP traffic steering
- EDNS Client Subnet for sub-region accuracy
- DNSSEC with automated KSK and ZSK rotation
- HTTP, TCP, ICMP and custom-script health checks
- Round-robin or latency-ordered selection within the active tier
Across both products
Shared platform services
- Regional data residency for query processing and log archival
- Multi-tenancy for MSPs and group subsidiaries
- Nine RBAC roles with enforced separation of duties
- Audit logs, API keys and reseller audit trails
- Daily analytics, domain discovery and per-zone statistics
- Cloud delivered, or cloud managed on your own infrastructure
The capabilities that decide the evaluation
Every one of these ships inside the two product licences — nothing here is a separate purchase.
AI threat detection
Advanced machine learning watches how DNS traffic behaves to surface DNS tunnelling and data exfiltration that signature and reputation lists miss entirely.
Sovereignty of logs and PoPs
You choose the region. Query processing and log archival happen inside it, and personal information does not leave it — for Protect telemetry and Resolve zones alike.
Multi-tenancy
Multi-tier tenant scoping for MSPs and group structures, with delegated administration, per-tenant policies and segregated audit trails.
Policy scheduling
Cloud Policies activate on a schedule, so daytime and after-hours postures differ without re-compiling rules or touching the resolver.
Smart-health GSLB
Continuous health probes drive priority-group failover and latency-ordered answers. Unhealthy endpoints leave the response set within seconds.
RPZ interoperability
Ingest external Response Policy Zone feeds over HTTPS on a sync schedule, and export your own for BIND, Infoblox and third-party resolvers.
One platform vs. stitched-together point solutions
What changes when protective DNS and authoritative DNS share a control plane, a role model and a residency guarantee.
Protective and authoritative DNS
DNS Armor™ Platform
Both products, one portal and one role model
One evaluation, one integration, one audit trail
Separate point solutions
Separate vendors and separate consoles
Data residency
DNS Armor™ Platform
Query processing and log archival pinned to your assigned region
Residency is architectural, not a contractual promise
Separate point solutions
Telemetry commonly routed through US or EU clusters
Threat detection
DNS Armor™ Platform
AI and behavioural detection of tunnelling and exfiltration
Catches covert channels that never match a signature
Separate point solutions
Signature and reputation lists only
Policy scheduling
DNS Armor™ Platform
Time-based Cloud Policy activation
Daytime and after-hours postures without rule re-compilation
Separate point solutions
Static rules requiring manual change windows
Traffic steering and GSLB
DNS Armor™ Platform
Geo and source-IP steering with smart-health GSLB built in
No separate GSLB appliance or add-on licence
Separate point solutions
Add-on module or a dedicated appliance
Multi-tenancy
DNS Armor™ Platform
Multi-tier tenancy with delegated RBAC
Segregated audit trails per entity
Separate point solutions
Monolithic single-tenant management planes
RPZ interoperability
DNS Armor™ Platform
Bidirectional — ingest external feeds and export your own
Keeps existing BIND, Infoblox and SOC stacks in play
Separate point solutions
Third-party connectors or manually maintained lists
Deployment model
DNS Armor™ Platform
Cloud delivered, or cloud managed on-premises
One platform covers both estates
Separate point solutions
Usually one model or the other, rarely both
What security teams tell us
From regional financial institutions, government entities and managed service providers.
“DNS Armor™ has transformed our security posture. We've seen a 70% reduction in security incidents since implementation, and the data sovereignty controls make compliance a breeze.”
“As an MSP, the multi-tenancy capabilities in DNS Armor™ allow us to efficiently manage security for all our clients from a single dashboard while maintaining complete separation of data.”
“The AI-driven threat detection caught sophisticated attacks that our previous solutions missed. DNS Armor™'s ability to detect DNS tunneling has been particularly impressive.”
Technical and compliance questions
Licensing, residency, deployment and integration.
No. They are two separate licences and you can take either one on its own — Resolve is not an add-on to Protect. Protect is the DNS firewall that blocks threats; Resolve hosts your own domain names. You only see the products you have paid for, and each has its own set of permissions, so the person who runs security does not have to be the person who runs DNS.
In the region you choose. Your DNS traffic is processed there and your logs are stored there, and personal data does not leave it. Logs are kept for the period in your contract — usually 30, 60 or 90 days. Every customer sits in a separate, isolated space, and we never combine or compare data between customers.
Yes — Dubai. Across the wider Middle East and Africa we also run from Doha, Riyadh, Cairo, Istanbul and Cape Town. In total the platform runs from 52 data centres in 32 countries, and you choose which of them serve you.
Yes. You can run it entirely in our cloud, or install it in your own data centre and still manage it from the cloud. The on-premises version is a virtual machine that runs on VMware ESXi, Hyper-V or KVM. It can pass queries to our cloud over an encrypted connection, or do everything locally — filtering, AI detection and your own rules — so nothing leaves your premises. Running locally, cached answers come back in under a millisecond.
Each tenant — a branch, a subsidiary, or a customer if you are a service provider — is kept fully separate, with its own networks, policies, reports and users. You hand out access through nine roles, and the system prevents any combination that would undermine separation of duties. Service providers also get an audit trail across every tenant they manage.
Using the tools you already have — Microsoft Intune, Jamf or Workspace ONE, Windows Group Policy, or SCCM, Ansible, Puppet and Chef. The install runs with no prompts: DNS-Armor-Setup.exe /S /API=<api-code>, or drop an API-code.txt file next to the installer. Devices appear under Monitoring → Endpoints as they register.
Yes. The on-premises appliance sends three separate streams — firewall events, DNS query logs and portal audit logs. They use CEF, a common security-log format, so Microsoft Sentinel, ArcSight and Elastic read them as they are, and we provide ready-made setup templates for Splunk and QRadar. Send them over TCP, encrypted TLS or RELP rather than plain UDP — longer records can be cut short over UDP without any warning.
Book a free demo using the form on this page. A solutions architect will show you the platform running against your own setup — what you use today, where your data has to stay, and what it needs to connect to — and plan a trial from there. Around thirty minutes, no credit card, no obligation.
Sovereign residency, in-region logging and encrypted transport
DNS query processing and log archival take place within the geographic region assigned to your organisation — data does not leave that region for processing or storage. Channels are end-to-end encrypted, data at rest is encrypted with customer-isolated key scope, and tenants are held in logically isolated containers. Secure Domains acts as data processor under a Data Processing Addendum, with your organisation as controller.
- Query processing and log archival stay in your assigned region
- Query log retention per contracted period — typically 30, 60 or 90 days
- Customer data is never sold, rented or shared for marketing
- No correlation, mining or aggregation across customer organisations

