Most of the controls we talk about with Perth clients - email security, endpoint protection, staff training - deal with a threat after it's already reached someone's inbox or device. DNS filtering works earlier than that. It stops the connection to a malicious website before it ever loads, which makes it one of the cheapest, least disruptive controls a business can add.
What DNS filtering actually does
Every time a device visits a website, it first performs a DNS lookup - translating a domain name like example.com into the IP address the browser then connects to. DNS filtering intercepts that lookup and checks it against a continuously updated threat intelligence database before letting it resolve.
If the domain is known to host phishing pages, malware, or command-and-control infrastructure for compromised devices, the lookup is blocked and the user sees a warning page instead of the malicious site. The browser never connects to the actual server.
Why it matters even with email filtering and antivirus in place
Email security stops most malicious links from ever reaching an inbox, but not all of them - and staff also click links from text messages, chat apps, social media, and search results that email filtering has no visibility into. DNS filtering catches that traffic regardless of where the link came from.
It also blocks a device that's already been compromised - by malware installed through some other means - from phoning home to its command-and-control server, which is often what turns a minor infection into a full ransomware incident. Cutting that communication channel can stop an attack from progressing even after the initial compromise has happened.
A typical scenario
A staff member receives a text message - not an email - with a link claiming to be from Australia Post about a missed delivery. It gets past every email control because it never touched email. They click it. With DNS filtering in place, the domain resolves to a block page instead of a credential-harvesting site, because the domain was already flagged in the threat database. Without it, they land on a convincing fake login page.
What else DNS filtering can do
Beyond security blocking, most platforms also support content category filtering - useful for businesses that want to restrict access to gambling, adult content, or social media on work devices, or that need it for compliance reasons (schools and NDIS providers in particular). This is a policy decision separate from the security case, and worth configuring deliberately rather than defaulting to either extreme.
Common DNS filtering platforms
- FortiGuard Web Filtering - built into FortiGate firewalls many Perth businesses already run for their firewall, often no extra licensing cost
- Microsoft Defender for Business - includes web protection for Microsoft 365 Business Premium customers, covering devices even off the office network
- Cisco Umbrella / DNSFilter - dedicated DNS filtering platforms with more granular reporting and policy control, better suited to larger or multi-site businesses
- Cloudflare Gateway - a lightweight, low-cost option that works well for smaller teams
Getting it configured properly
DNS filtering is only effective if it can't be bypassed. The common gaps we find in existing setups:
- Filtering only applied at the router - a device can bypass it entirely by manually changing its DNS settings unless enforcement happens at the firewall or via an endpoint agent
- DNS-over-HTTPS (DoH) left open - modern browsers can encrypt DNS lookups to a third-party resolver, sidestepping filtering unless DoH to unapproved resolvers is explicitly blocked
- Remote and laptop devices not covered - filtering configured only for the office network does nothing for a laptop working from a cafe or home, unless it's enforced via an agent on the device itself
- No visibility into what's being blocked - without reviewing logs occasionally, a business has no way to know whether the filtering is catching real attempts or just sitting there unused
What does DNS filtering cost?
- Included in existing licensing - many Perth businesses already have web filtering available through FortiGate or Microsoft 365 Business Premium at no extra cost, just not switched on
- Dedicated platforms - $2-$5 per user per month for standalone DNS filtering with reporting and category controls
- Setup and policy configuration - typically a few hours of one-off work to configure categories, exceptions, and enforcement across devices
Frequently Asked Questions
What is DNS filtering?
DNS filtering checks every website request against a threat intelligence database before your device connects to it. If the domain is known malicious - phishing, malware distribution, command-and-control - the request is blocked at the DNS lookup stage, before a browser ever loads a page or downloads content.
Does DNS filtering replace antivirus or a firewall?
No - it's one layer in a layered defence, not a replacement for endpoint protection or a firewall. DNS filtering stops a specific class of threat (malicious domains) before connection. It doesn't inspect files, detect malware already on a device, or replace email security. It's most valuable alongside those tools, not instead of them.
Can staff bypass DNS filtering?
Basic DNS filtering configured only at the router level can be bypassed by changing a device's DNS settings or using DNS-over-HTTPS (DoH) in a browser. Proper business deployments enforce filtering at the firewall or via an endpoint agent, and block DoH to third-party resolvers, so it can't be sidestepped by changing a setting.
What does DNS filtering cost for a Perth business?
Standalone DNS filtering platforms typically run $2-$5 per user per month. Many Perth businesses already have it available at no extra cost as part of existing FortiGate web filtering or Microsoft Defender for Business licensing - worth checking before buying a separate product.
Not sure if DNS filtering is switched on in your business?
We check this as part of every security review - it's often already available in your existing firewall or Microsoft 365 licensing and just needs configuring properly.
Talk to us about your security setup →For related reading, see our guides to Network Security for Perth Businesses and Common Phishing Email Tactics Targeting Perth Businesses.