DNS Proxy · DNS Firewall

A caching DNS proxy server with a firewall built in

DNS Proxywall is DNS Firewall and DNS Proxy in one. Run it as a DNS proxy server for other computers on Windows: serve them from a shared cache, build encrypted DNS tunnels between sites, balance upstream servers — and apply your DNS firewall rules to every client behind it.

1 tunnel
all DNS traffic wrapped into a single TCP or SSL/TLS connection
4 modes
first-server, round robin, round robin on timeout, or concurrent
IP + cert
optionally authenticate clients by address and certificate thumbprint

One policy, shared across the network

Point other computers at DNS Proxywall and it becomes their DNS proxy server: it answers from its own cache for speed, forwards what it must to upstream servers, and runs every request through the same DNS firewall rules. Filtering, geo policy and blocking that you configure once protect all of the clients behind it — not just the host machine.

For multiple locations, DNS Proxywall instances can be cascaded: branch resolvers aggregate their DNS traffic into a single encrypted tunnel and forward it to a central instance, where logging and policy live.

Running your own DNS proxy also keeps your network’s DNS private. Instead of pointing every device at an online DNS filtering provider that logs and profiles your traffic, you operate the resolver yourself: the filtering, the policy and the logs stay on your own infrastructure, and you decide which upstream servers — and whether to encrypt the path to them — you trust.

What the DNS proxy can do

Serve standard DNS clients

Listen for ordinary DNS over UDP and answer from cache or upstream servers, so anything from a PC to a phone can use it as its DNS server.

Encrypted DNS tunnels

Wrap all DNS traffic between two instances into a single TCP tunnel, optionally over SSL/TLS, with mutual certificate verification by SHA-1 thumbprint. SSL/TLS tunnel serving is an Ultimate feature.

Cascade & load balance

Chain instances to centralize DNS, and spread requests across upstream servers with first-server, round-robin, round-robin-on-timeout or concurrent strategies. Slow requests can be auto-blocked.

Authenticate clients when needed

Authentication is optional. When you need to lock the proxy down, restrict it to specific IP addresses and subnets, and verify tunnel clients by certificate thumbprint. An IP whitelist keeps trusted management addresses always reachable.

Stand up a DNS proxy in four steps

  1. Enable the proxy listener

    Turn on the standard DNS proxy server, and the tunnel listener if you need encrypted site-to-site DNS.

  2. Set upstream servers

    Add upstream DNS servers and choose a load-balancing strategy that fits your reliability needs.

  3. Lock down access

    Allow only trusted client IPs and subnets, and require certificate authentication on tunnels.

  4. Apply firewall rules

    Add name-pattern and Geo DNS rules once, and every client behind the proxy inherits the policy.

Proxy capabilities at a glance

Need DNS Proxywall
Serve DNS to other computers Standard DNS proxy over UDP, answered from cache or upstream
Encrypt DNS between sites TCP tunnel, optionally SSL/TLS, with certificate verification
Survive a slow or dead upstream Round-robin and concurrent load balancing, auto-block on timeout
Keep the proxy private IP and subnet authentication plus certificate thumbprints
Protect every client at once Name-pattern and Geo DNS firewall rules apply to proxied traffic
Keep your network’s DNS private You run the resolver — no online filtering provider logs your clients’ queries

DNS proxy server questions

What is the DNS proxy server in DNS Proxywall?

DNS Proxywall can act as a DNS server for other computers on the network. It answers their queries from its own cache or by forwarding to upstream servers, and the same DNS firewall rules apply to that traffic, so every client behind the proxy inherits your filtering policy.

Can it encrypt DNS between sites?

Yes. Two DNS Proxywall instances can connect over a TCP tunnel, optionally wrapped in SSL/TLS, that packages all DNS traffic into a single keep-alive connection. Both sides verify each other’s certificate by SHA-1 thumbprint. SSL/TLS tunnel serving is available in the Ultimate edition.

How does it choose between multiple upstream servers?

When several upstream DNS servers are configured, DNS Proxywall applies a load-balancing strategy: first-server-only, round robin, round robin on timeout, or concurrent, where the fastest response wins. Slow requests can be auto-blocked after a timeout.

Is the DNS proxy safe to expose to clients?

Authentication is optional and applied only when you turn it on. By default the proxy serves clients without authenticating them, which is fine on a trusted network. When you need to restrict access, it can authenticate proxy clients by IP address and subnet, and tunnel clients additionally by certificate thumbprint. An IP whitelist keeps trusted addresses reachable so rule changes never lock out remote management.

One DNS proxy, one firewall policy, every client

Cache, encrypt and balance DNS for your network — with filtering that protects everything behind it.

Explore DNS Proxywall use cases

Notes:
* Windows® is a registered trademark of the Microsoft Corporation.