CyberFOX DNS Filtering

CyberFOX DNS Filtering

Claimed

Claimed

See Pricing

Last Updated

Overview

CyberFOX DNS Filtering catches malicious domains, phishing attempts, and malware at the DNS layer, halting the connections before completion. While reporting takes configuration to get more from query logs and traffic data, its per-device DoH controls and granular policy management close gaps at the network level for IT teams.

Be the first one to leave a review!

No review found

vendorReviewSummaryStar icon
Starting Price
Custom

CyberFOX DNS Filtering Specifications

  • Security Measure
  • Threat Intelligence
  • Phishing Prevention
  • Security Audits And Reporting

CyberFOX DNS Filtering Features

Advanced Threat Detection

At the DNS layer, malicious sites, phishing domains, and malware are blocked before a request even resolves to an IP address. This means that malware, ransomware, and phishing domains are automatically blocked across all managed endpoints. Because the block is at resolution, a device never actually connects to the malicious domain in the first place.

See How It Works
AI Pattern Recognition

The platform uses AI-based pattern detection to identify and block threats. This includes emerging attack patterns that might not have explicit block list entries yet. The detection runs continuously in the background to identify malicious domain behavior based on suspicious patterns. It helps catch newer threats that haven't been flagged yet.

See How It Works
Device-Specific DNS-over-HTTPS (DoH) Configuration

Admins can approve or restrict DoH settings on a per-device basis. This closes a common loophole: users or apps setting up their own encrypted DNS resolver to route around the filter entirely. Instead, IT teams can manage how encrypted DNS queries are processed at the endpoint level.

See How It Works
Traffic Reports And Query Logs

The reports page breaks down permitted and blocked DNS activity by total query volume, alongside record type, and upstream server. It also shows which domains and locations are generating the most traffic. Beyond that, the query log gives a near-real-time list of individual DNS lookups. These can be filtered—by domain, location, or outcome—so you can trace a specific request. Anything on either screen can also be exported to CSV.

See How It Works
Custom Categories And Domain Overrides

Beyond CyberFOX's built-in filtering categories, admins can build their own domain groups. Admins can configure these categories to allow, block, proxy, or hold domains for review and attach them to multiple policies at once. This is useful for responding quickly to a newly discovered phishing domain for every client at once. Domain overrides handle the opposite case: a single site that needs to stay reachable despite what the broader policy would otherwise do.

See How It Works

Pros And Cons of CyberFOX DNS Filtering

Pros

  • Supports both network-based and roaming-device DNS filtering

  • Offers custom policies, categories, and domain exceptions

  • Provides DNS traffic reports, query logs, and audit logs

Cons

  • Reporting options may require further configuration

  • Advanced controls may require administrator involvement

CyberFOX DNS Filtering Reviews

no-reviews

No reviews yet!

Be the first to review this product

Frequently Asked Questions

What does CyberFOX DNS Filtering integrate with?

Current integrations Microsoft Intune for agent deployment. RMM platforms for scripted agent deployment. Network infrastructure via static DNS forwarding and DNS relay

Does this protect people working from home?

Yes. The roaming client agent enforces policy on the device regardless of the network it is on, updates policy automatically, and keeps enforcing when offline.

Can a user get around it with a browser setting?

Browser DNS-over-HTTPS can bypass DNS filtering if it is left enabled, so DoH should be disabled or controlled by policy during rollout. The troubleshooting guide treats this as the first thing to check when a block does not apply.

Do we need an agent on every device?

No. Static DNS forwarding or a DNS relay covers a network without agents, and the agent is added where policy needs to follow the device. Most environments use a combination.

Does it filter IPv6?

Yes. IPv6 filtering is supported, which is a gap in a number of longer-established DNS filtering products.

Why does a blocked site show browser security warning, not block page?

Why does a blocked site sometimes show a browser security warning instead of the block page? That is expected behavior on HTTPS sites, where the browser objects to the redirect before the block page can render. The proxy service for safe browsing and block page configuration reduce how often users see it.

Who are the typical users of CyberFOX DNS Filtering?

Typical users include IT departments in higher education, K-12 education, state and local government, and manufacturing sectors and industries. 

What level of support does CyberFOX DNS Filtering offer?

Support is offered via knowledge base and ticketing system. 

How much does CyberFOX DNS Filtering cost?

CyberFOX DNS Filtering pricing is customized based on the needs of organizations, deployment scopes, as well as the endpoint count. The vendor also offers a 14-day free trial. Get a personalized CyberFOX DNS Filtering cost estimate today.