Every time a device tries to reach a website, it first asks a question nobody sees: where does this domain actually live? That question, a DNS lookup, happens dozens of times a minute, for every page, every embedded ad, every background app checking for updates. DNS filtering sits in the middle of that question and, for a small slice of lookups, answers with a refusal instead of an address. It's one of the least disruptive, least expensive security controls a small business can turn on, and it's also one of the most skipped, mostly because nobody explains what it does in plain terms.
What DNS filtering actually does
A DNS filtering service routes a device's lookups through a resolver that checks each domain against constantly updated threat intelligence: known malware hosts, phishing pages, botnet command-and-control servers, and domains registered within the last few days, which skew heavily toward abuse since legitimate businesses rarely need a brand-new domain live within hours. When a lookup matches, the resolver returns a block page instead of the site's real address, and the connection never happens. The browser never loads the page, the malicious script never runs, and the download never starts.
That's a meaningfully different position than filtering at the browser or the firewall. A browser-level warning still requires the page to load enough to be evaluated. A firewall inspects traffic after a connection is already underway. DNS filtering intervenes a step earlier, at the address-lookup stage, so there's less for anything downstream to catch, and less for an employee to accidentally click through.
Why it catches attacks other tools miss
Most of what reaches an employee isn't a file, it's a link: a phishing email, a fake software ad, a QR code, a search result for a "free trial" that's actually a malware dropper. None of that triggers antivirus or EDR until something is already running on the machine. DNS filtering intercepts a large share of it earlier, purely based on where the link points.
- Malvertising and fake download pages. The infrastructure behind fake software ads and cracked-installer sites tends to reuse the same hosting, which threat intelligence tracks and blocks on sight, closing off the path our malvertising post covers in detail.
- Newly registered and lookalike domains. A domain registered yesterday impersonating your bank or vendor gets flagged by age and pattern alone, before it's even been reported as malicious anywhere.
- Fake verification and CAPTCHA pages. The kind of staged page used in ClickFix-style attacks, where a "prove you're human" prompt tricks someone into pasting a command, often gets caught before it ever renders.
- Command-and-control callbacks. If something does get onto a device, DNS filtering can still block the outbound call it makes to report home, cutting it off before it does more damage.
What to look for in a DNS filtering product
Not all DNS filtering is equal, and the differences matter more than the marketing suggests. Threat intelligence needs to update continuously, not on a weekly batch, since malicious domains often live for only hours. It needs a lightweight roaming client so laptops stay protected off the office network, the same gap that matters for business travel and public Wi-Fi. And it needs usable reporting: a log of what got blocked and why, so an IT provider can spot a pattern (one device repeatedly hitting phishing infrastructure is a strong signal that user needs a conversation, not just a blocked page).
Pricing runs roughly $1 to $3 per device per month at the business tier, which is why it's almost always bundled into a managed IT or cybersecurity package rather than sold on its own. There's no hardware to install and nothing for an employee to configure; it's a setting pushed to every managed device.
Turning it on without breaking anything
The one legitimate worry with DNS filtering is over-blocking: a legitimate business tool getting flagged and employees losing access with no clear reason why. The fix is a short monitor-only period before enforcement, where the filtering logs what it would have blocked without actually blocking it, so an IT provider can review the list and clear any false positives before anyone hits a wall. After that, a simple exception process (someone can request a domain get unblocked, reviewed, and added to an allowlist within the day) keeps the control from turning into a support ticket generator. Locking every managed device's DNS resolution to the filtering service, rather than whatever a router hands out by default, closes the gap that lets a device quietly bypass it.
Where this fits
- The malvertising post, for the fake-ad infrastructure DNS filtering blocks directly.
- The ClickFix attack post, for the staged verification pages this control is built to catch.
- The Wi-Fi segmentation post, for the network-layer controls that work alongside DNS filtering.
- The EDR vs. antivirus post, for what catches a threat that makes it past DNS filtering and onto a device.
- Our cybersecurity services, for where DNS filtering fits into a full managed security stack.
We roll DNS filtering into managed IT and cybersecurity packages for small businesses across Salinas, Monterey, Santa Cruz, Watsonville, and San Jose, and the rest of the Central Coast, tuned during onboarding so it blocks real threats without blocking real work.
FAQs about DNS filtering for small business
What is DNS filtering?
DNS filtering checks every website lookup a device makes against threat intelligence before the connection completes, and blocks the ones known to host malware, phishing, or command-and-control infrastructure. Because it works at the lookup stage, it stops a malicious page from ever loading rather than trying to clean up after it does.
How much does DNS filtering cost for a small business?
Business-grade DNS filtering typically runs $1 to $3 per device per month, and it's usually bundled into managed IT and cybersecurity packages rather than sold as a standalone line item. It requires no new hardware and no endpoint software beyond a lightweight roaming client for laptops that leave the office network.
Does DNS filtering replace antivirus or a firewall?
No. DNS filtering blocks a device from reaching known-bad destinations, but it can't inspect files already on a machine or traffic that doesn't rely on a domain lookup. It's a complementary layer that catches malicious links and malvertising before EDR or antivirus ever sees a file, not a substitute for either.
Not sure if your team's devices have DNS filtering turned on?
30 minutes with an engineer with DoD infrastructure experience. We'll check what's currently blocking malicious sites on your network, if anything, and what closing that gap actually costs.
Book your free security assessment