DNS Firewall for Windows

Block bad domains before they ever resolve

DNS Proxywall is a host-based DNS firewall for Windows — DNS Firewall and DNS Proxy in one product. Filter domains by name pattern, block whole countries with Geo DNS, cache lookups for speed, and watch every query in a live activity log, on workstations and servers alike.

10,000
domain name-pattern rules in the Ultimate edition, with wildcards
1st hop
filtering happens at the DNS lookup, before any connection is opened
7 → 2025
Windows 7 through 11 and Server 2008 R2 through 2025

Why filter at the DNS layer?

Nearly every connection a computer makes — a web page, an update check, a piece of malware calling home — begins with a DNS lookup that turns a name into an IP address. A DNS firewall sits on that lookup and decides what is allowed to resolve. Blocking a domain here is cheaper and earlier than blocking packets later, and it works no matter which port or protocol the connection would have used.

DNS Proxywall enforces that policy directly on the Windows host through a kernel-mode driver, so the rules cover the whole machine rather than one browser or one app. It is designed to sit alongside the antivirus and endpoint tools you already run — another independent layer of defense.

It is also private by design. Online (cloud) DNS filtering services have to route every query you make through their own resolvers, where your lookups can be logged and profiled. DNS Proxywall does the opposite: the rules, the filtering decisions and the activity log all stay on your own machine, you pick the upstream DNS resolver you trust, and no filtering vendor ever sees your browsing history. There is no account to create.

What the DNS firewall does

Block domains by name pattern

Write allow and block rules against domain names with wildcards, such as *.example.com. Group them into category profiles so a single switch turns an entire policy on or off.

Filter by country with Geo DNS

Resolve the country behind every address and block, allow or re-prioritize results by territory. Steer connections toward nearby servers and shut out regions you never do business with.

Force traffic through DNS

Turn on the IP firewall to block direct-to-IP connections that skipped a DNS lookup, so malware can’t dodge your rules by dialing a hard-coded address.

Cache and see every query

A built-in DNS cache speeds up resolution, while the live activity log shows what was queried, resolved, cached or blocked — and why. The log can be persisted to disk for later analysis.

How to put a DNS firewall on a Windows machine

  1. Install and point DNS at it

    Install DNS Proxywall and let it pick up your DHCP-assigned upstream DNS servers, or set them by hand.

  2. Add your block and allow rules

    Block unwanted domains by name pattern, allow the ones you trust, and add country rules with Geo DNS.

  3. Tighten the perimeter

    Whitelist management addresses, then optionally block non-DNS direct-IP traffic so everything resolves first.

  4. Monitor and refine

    Watch the activity log, see what is being blocked, and adjust the rules as your environment changes.

What you get

Requirement DNS Proxywall
Runs on Windows desktops and servers Windows 7 – 11 and Windows Server 2008 R2 – 2025
Blocks by domain name, not just IP Name-pattern rules with wildcards and category profiles
Stops connections that skip DNS Optional IP firewall blocks non-DNS direct-IP traffic
Covers the whole machine Enforced by a kernel-mode network driver (IPv4 / IPv6, TCP / UDP)
Coexists with the current security stack Designed to layer alongside antivirus and endpoint protection
Keeps your DNS private Filters locally — no cloud middleman, no account, no query history sent to a vendor
Free to try Free Basic edition plus a full 30-day trial

DNS firewall questions

What is a DNS firewall?

A DNS firewall inspects the domain-name lookups a computer makes and decides which to allow, block or redirect before a connection is ever opened. Because almost every connection starts with a DNS query, filtering at the DNS layer stops traffic to unwanted or malicious domains early. DNS Proxywall is a host-based DNS firewall for Windows that enforces these rules on the machine itself.

Does it run on Windows Server as well as desktops?

Yes. DNS Proxywall runs on Windows 7, 8, 8.1, 10 and 11, and on Windows Server 2008 R2 through 2025. It uses a kernel-mode network driver, so the DNS firewall applies to the whole machine rather than a single browser.

How is a DNS firewall different from a normal firewall?

A traditional firewall filters by IP address and port. A DNS firewall filters by domain name, which is how people and malware actually address servers. DNS Proxywall does both: it blocks domains by name pattern and, with its IP firewall option, can also block any non-DNS direct-IP connection so traffic must resolve through DNS first.

Is a local DNS firewall more private than an online DNS filtering service?

Yes. Online (cloud) DNS filtering services work by routing all of your DNS queries through their own resolvers, where lookups can be logged and tied to your account or network. DNS Proxywall runs entirely on your Windows machine: the rules, the filtering decisions and the activity log stay local, you choose your own upstream DNS resolver, and no third-party filtering provider sees or stores your browsing history. No account is required.

Can I try it for free?

Yes. There is a free Basic edition activated with a free serial key, and a full-featured 30-day trial. Paid Pro and Ultimate editions add larger rule limits, encrypted DNS proxy tunnels, cache-only mode and more — see the edition comparison.

Put a DNS firewall on every Windows machine

Start with the free Basic edition or the 30-day trial, then scale up to Pro or Ultimate as your policy grows.

Explore DNS Proxywall use cases

Notes:
* Windows® is a registered trademark of the Microsoft Corporation.