AI detection
Behavioural models flag DNS tunnelling, DGA domains and slow exfiltration that lists miss.
Every query passes through all three. They share one portal, one policy model and one audit trail.
Decides whether a destination is safe to reach.
Answers queries, recursive and authoritative.
Sends users to the healthiest, closest endpoint.
Each lookup is checked against threat intelligence, AI behaviour models and your own policy before an answer is returned. A blocked domain never resolves, so the connection is never made.
Behavioural models flag DNS tunnelling, DGA domains and slow exfiltration that lists miss.
Threat, web-filtering and application feeds are applied at resolution time.
Every domain gets a category and a threat score before your policy decides.
Cloud Policies activate on a schedule; Local Rulesets make explicit allow and block decisions.
Ingest external RPZ feeds on a sync schedule and export your own.
DNS Armor Protect™ resolves your users’ queries; DNS Armor Resolve™ answers for your own domains. Both are signed, validated and encrypted in transit.
User or device
Recursive resolver
DNS Armor Protect™
Authoritative DNS
DNS Armor Resolve™
Signed answer
DNSSEC-validated
Recursive resolution with DNSSEC validation against spoofing and cache poisoning.
Your zones hosted with automated DNSSEC signing.
KSK and ZSK lifecycle and rotation are managed for you.
DNS over HTTPS and DNS over TLS, enforced per tenant.
Bypass Domains keep internal namespaces resolving on-premises.
Resolve steers each answer by geography, source network, health and latency. Unhealthy endpoints leave the response set automatically.
Query for app.example.com
Resolve steering
Dubai endpoint
Healthy · closest
Frankfurt endpoint
Healthy · standby
Singapore endpoint
Failing health check · removed
Answer each query with the endpoint that suits where it came from.
HTTP, TCP, ICMP and custom probes decide which endpoints stay in answers.
Traffic moves to the next group automatically when a group fails.
Round-robin or latency-ordered answers across healthy endpoints.
Finer location for users behind large shared resolvers.
Cloud delivered, or on your own hardware.
Same policy, same portal.
Local Resolver appliances keep internal resolution on your premises while cloud policy follows every device.
The same platform and policy model in every option. Choose where enforcement happens and where data lives.
Networks & devices
DNS Armor cloud
Point your networks and devices at DNS Armor. Nothing to install on site; roaming devices use the Endpoint Agent.
Best for fast rollout and distributed teams.
Devices
Local Resolver
DNS Armor cloud
A virtual appliance (ESXi, Hyper-V or KVM, in high-availability pairs) in proxy mode or full local mode, with an Active Directory connector.
Best for per-user visibility and internal namespaces.
Your networks
Dedicated tenant
A dedicated tenant with dedicated storage, in the region you choose, operated by Secure Domains.
Best for regulated sectors that need isolation without running infrastructure.
Devices
Resolvers in your DC
Management portal
Resolvers and agents inside your own data centre, managed from the DNS Armor portal, licensed to your scale.
Best for government and critical infrastructure.
Two tracks, stated plainly. Frankfurt is the automatic service plane for online self-signup only; Enterprise keeps both planes in the region you choose.
| Plan | Self-service (online signup) | Enterprise |
|---|---|---|
| Products | DNS Armor Protect™ and DNS Armor Resolve™ | Same, licensed independently |
| Service plane | Frankfurt, Germany, for self-signup accounts only | In the region you choose |
| Logging plane / log archive | Region chosen at signup | Same region as the service plane |
| Storage | Shared service plane, per-account tenant | Dedicated per customer or tenant; private cloud or on-prem available |
DNS is the first dependency of every application, so the platform is designed around redundancy at each layer.
Each customer is assigned to a region and served by healthy nodes there, across 52 data centres in 32 countries.
Continuous probes drive priority-group failover, so traffic moves away from a failing endpoint without manual action.
Local Resolver appliances run in HA pairs on ESXi, Hyper-V or KVM, so on-site resolution survives a host failure.
A solutions engineer will walk through the deployment model and residency set-up that fits your network and regulator.