DNS Firewall · Threat Blocking

Block malicious domains before malware can call home

Most attacks start with a domain lookup. Use the DNS Proxywall DNS firewall to block malware, phishing and command-and-control domains on Windows — and to stop the connection even when malware tries to dial a hard-coded IP address.

Step 1
a DNS lookup is the first move of nearly every malware callback
0 IP
block the lookup and the threat never gets an address to connect to
No bypass
optionally block direct-to-IP traffic that skips DNS entirely

Cut the threat off at the name

Ransomware, info-stealers and remote-access trojans need to reach infrastructure they control. Whether it is a command-and-control channel, an exfiltration endpoint or a phishing page, the first step is almost always resolving a domain name. A DNS firewall that blocks that name denies the connection before a single packet of payload moves.

DNS Proxywall enforces blocking on the Windows host itself with a kernel-mode driver, so the protection follows the machine on any network — office, home or a cloud VM — and layers cleanly on top of your existing antivirus.

Because that blocking runs locally rather than through an online DNS security service, your query stream stays private: no cloud filtering provider has to see, log or profile the domains your machines look up. You keep the threat protection and choose your own upstream DNS resolver.

How DNS Proxywall blocks malicious domains

Name-pattern block lists

Block known-bad domains and entire suspicious zones with wildcard rules like *.bad-tld. Organize them into category profiles you can enable per environment.

No hard-coded-IP escape

Switch on the IP firewall to block direct connections to addresses that were never resolved through DNS, closing the bypass malware uses when it ships with a baked-in server address.

Fast-fail refusal caching

Cache refused and non-existent responses so repeated callbacks to dead or blocked domains fail instantly, and let the log aggregate noisy blocked floods into a single line.

Evidence in the activity log

Every blocked lookup is recorded with its status, so you can prove what was stopped and spot a compromised host by the bad domains it keeps trying to reach.

Lock down a host in four steps

  1. Load your block rules

    Add malicious and unwanted domains as name-pattern rules, grouped into a reusable category profile.

  2. Whitelist what must stay reachable

    Add management addresses and trusted subnets to the IP whitelist so blocking never locks you out.

  3. Close the bypass

    Enable blocking of non-DNS direct-IP connections, and cache refusals so repeat callbacks fail fast.

  4. Watch for callbacks

    Use the activity log to see blocked attempts and identify hosts that are trying to reach bad infrastructure.

Defense at the DNS layer

Threat behavior DNS Proxywall response
Malware resolves a C2 domain Name-pattern rule blocks the lookup — no IP is ever returned
Payload dials a hard-coded IP IP firewall blocks non-DNS direct-IP connections
Repeated callbacks flood the host Refused-response caching and log aggregation absorb the noise
Attacker infrastructure sits abroad Geo DNS can block or de-prioritize results by country
You need proof for an incident review Persistent activity log records every blocked domain
You don’t want to hand queries to a vendor Blocking runs locally — no online DNS security provider logs your traffic

Questions about blocking malicious domains

How does a DNS firewall block malware?

Malware almost always resolves a domain name to find its command-and-control or drop server. A DNS firewall blocks that lookup, so the malicious connection never gets an address to dial. DNS Proxywall blocks domains by name pattern with wildcards, and can additionally block any direct-to-IP connection that tried to skip DNS.

Can it stop malware that connects straight to an IP address?

Yes. The optional IP firewall blocks non-DNS connections to addresses that were never resolved through DNS Proxywall, closing the hard-coded-IP escape route many threats rely on.

Does it speed up repeated blocks?

Yes. DNS Proxywall can cache refused and non-existent responses so repeated lookups to known-bad or dead domains fail fast without another round trip, and the activity log aggregates floods of blocked attempts into single lines.

Which edition do I need?

Name-pattern blocking works in every edition, including the free Basic edition. Pro and Ultimate raise the rule limits and add features such as blocking non-DNS IPs, cache-only mode and refused-request caching — see the edition comparison.

Stop callbacks at the DNS layer

Add a DNS firewall that blocks malicious domains and the connections that try to skip DNS entirely.

Explore DNS Proxywall use cases

Notes:
* Windows® is a registered trademark of the Microsoft Corporation.