ClearSkies™ DNS Shield

The resolver is not plumbing anymore.

The blind spot you already own

Between your three controls sits one uninspected protocol

Your firewall inspects traffic only after a destination has been resolved and a connection attempted. Your web proxy sees HTTP and HTTPS, and nothing else. Your endpoint agent covers the devices it can be installed on. Between those three sits the one protocol present on every device, allowed out of almost every network, and inspected almost nowhere.

  • DELIVERY

    Phishing and malware-delivery domains are registered by the thousand and burned within hours. A blocklist alone will always be a step behind.

  • COMMAND AND CONTROL

    C2 channels beacon over DNS because the port is never closed and the traffic never looks unusual to a resolver that logs nothing.

  • EXFILTRATION

    Data leaves one query at a time through record types most tooling never inspects — TXT chief among them.

Why adversaries rely on DNS

What DNS Shield is

DNS Shield turns the resolver into a control point. It scores every query against threat intelligence and behavioral models before an answer is returned, refuses or redirects what is malicious, and records the whole transaction for detection and forensics.

Queries reach DNS Shield by two routes, and the same policies apply to both. On the corporate network, the organization’s own DNS server keeps answering internal names and forwards external lookups to DNS Shield. Nothing is installed on the device, so printers, cameras, sensors, controllers and contractor hardware are covered like everything else. Away from the corporate network, the ClearSkies DNS Agent on a managed Windows or macOS device detects that it is no longer on the corporate LAN and sends external lookups straight to DNS Shield over encrypted DNS-over-HTTPS.

Two routes into DNS Shield. On the corporate network, devices resolve through the organization’s DNS server, which forwards external lookups to DNS Shield. Away from the corporate network, the ClearSkies DNS Agent sends external lookups over encrypted DNS-over-HTTPS. The same policies apply to both.

Coverage reaches the devices a firewall subscription cannot. A DNS control delivered as a firewall feature protects what sits behind the firewall. Forwarding from the resolver protects anything that resolves through it, including hardware no agent can be installed on and no appliance sits in front of.

Why ClearSkies DNS Shield

  1. Detection ahead of the connection

    The verdict is reached at resolution time, ahead of the TCP connection, the TLS handshake and the payload transfer. Firewall, proxy, endpoint and mail controls all begin their work after the name has already been resolved.

  2. One policy set, whatever the device and wherever it is

    The Agent has no policies of its own and no reduced off-network mode, and the internal-resolver route covers the hardware no agent can be installed on, so a roaming laptop and a building printer are held to the same eleven policies and four confidence bands. Where a protective DNS service pairs a network resolver with a roaming client that applies a lighter policy set off-network, the organization keeps two policies and gets the weaker one at the moment the device is least protected.

  3. Weighted multi-signal scoring rather than a single-indicator block

    Independent detection sources are scored in parallel and combined, so no one signal produces a confirmed-malicious verdict alone. That is what makes refusing by default defensible: a service driven by a reputation feed has to either block on a single indicator, and carry the false positives, or alert and let the connection proceed.

  4. Data residency and sovereignty are built into the routing

    Split-DNS routing keeps internal name resolution off the service completely, on both routes in, and endpoint tokens are issued on-premises at the Customer Portal inside the organization’s own infrastructure. Residency is a property of the design, not a hosting region picked at sign-up.

Licensed on what is measured, not on what can be counted

DNS Shield is licensed on DNS queries analyzed per day, averaged across the billing period, rather than on a device count. An organization with 800 workstations and 6,000 other connected devices holds one license covering all of them, sized to the volume actually measured. Much of what DNS Shield protects cannot be counted as an endpoint at all: a per-seat model would price about 12% of the devices in that example. Under query volume every device is inspected on the same basis as a workstation, before it appears on the invoice. The Agent is included in the license rather than sold separately.

12%A per-seat model would price about 12% of the devices in that example.
  • 800 workstations
  • 6,000 other connected devices
  • 1 dot = 20 devices

Questions buyers ask first

What does a false refusal cost, and how fast is it reversed?

A false-positive mark suppresses the domain immediately and retrains the tenant baseline.

Why is an agent needed if the internal resolver already covers the network?

A managed device off the corporate network uses whatever DNS the local network provides unless the Agent forwards them back.

What does protective DNS miss that another control must catch?

Payload content, and direct-to-address connections that issue no lookup at all. Both are the work of the firewall and endpoint layers, which is why the correlated architecture matters more than the refusal itself.

See a verdict reach an incident

A working session on your own resolver scope, showing what a refusal looks like by the time it reaches an analyst.