In-region logging on Enterprise.Details
Secure Domains
DNS Armor™ platform

One platform for DNS security and authoritative DNS.

Protect secures every lookup your users make. Resolve answers for every domain you own. Run either on its own, or both from one portal, one policy model and one audit trail.

Which do you need?

Start from the problem you have.

Most organisations begin with one product and add the other later. Each is licensed on its own.

Protective DNS

DNS Armor Protect™

Stops malware, phishing, ransomware and DNS tunnelling at the first lookup, for users, networks and roaming devices.

Choose Protect if you need to

  • Block threats before a connection is made, on and off the network
  • Detect DNS tunnelling and data exfiltration
  • Filter web and application categories by schedule
  • Stream DNS evidence to your SIEM
Explore Protect
Authoritative DNS

DNS Armor Resolve™

Hosts your zones with automated DNSSEC and steers traffic by geography and health, with keys and logs in your region.

Choose Resolve if you need to

  • Host public zones in a jurisdiction you choose
  • Sign zones with DNSSEC without managing keys by hand
  • Fail over automatically when an endpoint goes down
  • Route users by geography or source network
Explore Resolve
Sovereign cloud

Your region, your rules

Choose where queries are processed and logs are stored, with private cloud and on-premises options for regulated estates.

Where your data runsSelf-service accounts are served from our Frankfurt, Germany service plane, with DNS logs archived in the region you choose at signup. On the Enterprise track, the service plane and logging plane sit together in the region you choose.
Data residency

DNS Armor decision engine

Powered by threat intelligence and AI detection

Classifies every domainCategory, age, reputation and look-alike checks at resolution time.
Scores the riskAI models flag tunnelling, DGA and fast-flux behaviour.
Enforces your policyAllow, block or redirect in milliseconds, per tenant and schedule.
Infrastructure

52 data centres. One policy model.

Every account is served from its assigned region.

Every decision is logged where you choose.

Service and logging planes sit where you place them, not on a shared global edge.

Architecture

Three layers, one control plane.

Security, DNS and traffic intelligence share one portal, one policy model and one set of logs.

  1. 01

    Security layer

    Decides whether a destination is safe to reach.

    • AI detection
    • Threat intelligence
    • Domain classification
    • Policy engine
    • RPZ and DNS filtering
  2. 02

    DNS layer

    Answers queries, recursive and authoritative.

    • Recursive DNS
    • Authoritative DNS
    • DNSSEC signing and validation
    • DoH and DoT
  3. 03

    Traffic intelligence

    Sends users to the healthiest, closest endpoint.

    • Geo steering
    • GSLB
    • Health checks
    • Performance routing
Integrations

Fits the stack you already run.

Stream to your SIEM, deploy with your endpoint tools and exchange RPZ feeds with your existing resolvers.

By category

SIEM and SOC

  • Microsoft Sentinel
  • Splunk
  • IBM QRadar
  • Elastic
  • ArcSight

Endpoint deployment

  • Microsoft Intune
  • Jamf
  • Workspace ONE
  • Group Policy
  • SCCM
  • Ansible
  • Puppet
  • Chef

DNS and identity

  • BIND (RPZ)
  • Infoblox (RPZ)
  • Active Directory
Deployment models

Run it where your architecture needs it.

The same platform, delivered four ways. Enterprise customers can combine them.

Cloud delivered

Point networks at DNS Armor™ and install the Endpoint Agent on roaming devices. Nothing to host.

Local resolver

A virtual appliance on ESXi, Hyper-V or KVM, forwarding to the cloud or resolving fully on-site.

Private cloud

Dedicated tenancy and storage for one organisation, with service and logging planes in the region you choose.

On-premises

Cloud-managed enforcement running on your own infrastructure, for estates that must stay in-house.

Not sure where to start?

A solutions engineer will map Protect and Resolve to your network and regulator in a 30-minute call.