In-region logging on Enterprise.Details
Secure Domains
Threat intelligence

Intelligence applied at the moment of lookup.

DNS Armor™ classifies every domain, scores its risk and applies your policy while the query is still in flight, so a malicious destination is refused before any connection starts.

  • 20M+ active indicators
  • AI behaviour detection
  • RPZ in and out
Classification pipeline

From domain to decision in five steps.

Each step adds evidence. The final decision follows your policy, not a fixed vendor verdict.

  1. 01

    Domain

    The name requested by the device.

    Example

    x9-update-check[.]top

  2. 02

    Classification

    Matched against threat, web and application intelligence.

    Example

    Malicious

  3. 03

    Threat score

    Risk weighted by reputation, age and behaviour.

    Example

    High (97 / 100)

  4. 04

    Category

    The kind of threat or content it represents.

    Example

    Malware distribution

  5. 05

    Policy

    Your rules for this network, user and time of day.

    Example

    Block

In the portal

What the evidence looks like.

Real screens from the DNS Armor™ portal: detections, discovery and reporting your SOC can act on.

DNS Armor AI Threat Detection screen listing findings by detection type

AI threat detection

Tunnelling, fast-flux and DGA findings per customer and tenant, with CSV export.

DNS Armor Discovery Analytics screen summarising apps, web filters, threats and countries

Discovery analytics

Apps, web filters, threats and countries seen in DNS for each tenant.

DNS Armor reporting screen with daily activity and geographic breakdown

Reporting

Daily trends and geo views that feed audits and board reporting.

Intelligence

Intelligence that updates itself.

20M+ active indicators.

Scored at resolution time.

AI models watch for tunnelling, DGA and fast-flux behaviour that static lists miss.

AI detection

Catching what lists miss.

Machine-learning and behavioural models watch how DNS traffic behaves, not only which names appear, to surface covert channels that never match a signature.

DNS tunnelling

Data or commands encoded inside query names and responses, detected by pattern and volume.

Data exfiltration

Slow, low-volume leakage through DNS that perimeter firewalls were not built to see.

Domain generation algorithms

Machine-generated names malware uses to find its command-and-control servers.

Fast-flux infrastructure

Rapidly rotating hosting used to keep phishing and malware sites online.

Newly registered domains

Recently created domains, frequently used in phishing campaigns, flagged for policy.

Findings appear under Monitoring → AI Threat Detection in the portal.

Feeds

Bring your own intelligence, and share it.

Response Policy Zones work in both directions, so DNS Armor fits into an existing security stack.

External RPZ feeds

DNS Armor

BIND · Infoblox · third-party resolvers

Built-in feeds

Threat intelligence, web-filtering and application feeds are included with DNS Armor Protect™.

Ingest external RPZ

Subscribe to external RPZ feeds over HTTPS and keep them in sync on a schedule.

Export your own feeds

Publish your feeds in RPZ format for BIND, Infoblox and other third-party resolvers.

Continuously updated, applied instantly.Indicators are updated continuously and take effect at resolution time. There is no signature file to push to endpoints and no client update to wait for: the next lookup uses the latest intelligence.

Questions about threat intelligence

Does DNS Armor replace my firewall or EDR?

No. It works at a different control point: the moment a name is looked up, before any connection is attempted. It complements perimeter firewalls and endpoint tools, and it also covers roaming devices those tools may not see.

Can I use my own threat feeds?

Yes. DNS Armor Protect™ ingests external RPZ feeds over HTTPS on a sync schedule, and can export your feeds in RPZ format to BIND, Infoblox and other resolvers.

Can I override a block decision?

Yes. Local Rulesets give explicit allow and block decisions, and Cloud Policies can differ by network, user group and schedule.

Where do AI findings go?

They appear under Monitoring → AI Threat Detection in the portal and can be streamed to your SIEM over CEF.

See what DNS Armor finds in your traffic.

Book a walkthrough, or start a free trial and review your own AI findings.