Block DNS Attacks

Experimental protection against DNS exfiltration and payload delivery attacks.

Overview

Block DNS Attacks is an experimental Profile Option designed to block the most common forms of DNS exfiltration and payload delivery attacks. These attacks use DNS to send data out of a device or deliver malicious content to it.

With this setting enabled, certain query types, such as TXT, are blocked or their responses are rewritten. DNS patterns associated with exfiltration are also blocked.

🚧

Client devices only

This option is not recommended for web servers, mail servers, or other servers that rely on clean, unmodified DNS responses. Blocking or rewriting these responses can interfere with their normal operation.

Block DNS Attacks is intended for client devices only, which almost never need these query types during normal use.

How to Enable

  1. Go to Profiles and select the Profile you want to modify.
  2. Open Profile Options.
  3. Enable Block DNS Attacks, below AI Malware Filter.

The setting applies to Endpoints that enforce this Profile. Use a separate Profile for servers that need unmodified DNS responses.


Did this page help you?