The 3 Types of DNS Security

Cybersecurity professionals are starting to move beyond mere DNSSEC towards leveraging DNS data, as part of a layered protection strategy.

Set of metal keys on a yellow background symbolizing layered DNS security controls and access protection
Key takeawaysThis key takeaway was generated through LLMs crawling the page and coming up with an overview of the content.

The article explains three complementary layers of DNS security—DDoS mitigation, DNS firewalls, and threat intelligence—and how together they protect networks from high-traffic attacks, malicious queries, and known malicious domains. It highlights a survey finding that 69% of IT administrators lack visibility or tools to leverage DNS data for security, and argues that organizations are moving beyond DNSSEC toward layered DNS-based defenses. The piece introduces BlueCat DNS Edge as an evolution that provides client-facing, first-hop visibility and more sophisticated detection (e.g., DNS tunneling and domain generation algorithms) to protect both north-south and east-west traffic with faster response times.

What are the three distinct types of DNS security described in the article and how do they differ?

The article describes DDoS mitigation, DNS firewalls, and threat intelligence as three distinct DNS security types. DDoS mitigation defends against volumetric attacks that flood a server with DNS responses by routing traffic through high-capacity filtering services that strip attack traffic. DNS firewalls apply security policies to individual DNS queries—blocking or sinkholing requests that match threat profiles and often responding with NXDOMAIN to the client. Threat intelligence augments firewalls by feeding curated lists of known malicious domains into firewall policies (either third-party feeds or custom lists) so the firewall can block or log queries for those specific domains.

Why do cybersecurity professionals need more than DNSSEC according to the article?

According to the article, DNSSEC verifies the cryptographic legitimacy of DNS responses but does not leverage DNS data to detect or mitigate malicious activity. Cybersecurity professionals are moving beyond DNSSEC because they need layered protections that use DNS telemetry and policy enforcement to identify threats, block malicious queries, and mitigate attacks. The article notes a survey where 69% of administrators reported insufficient visibility or tooling to leverage DNS data, underscoring the need for solutions that provide operational DNS security—such as firewalls, threat feeds, and advanced analytics—not just response validation.

How does BlueCat DNS Edge extend traditional DNS firewall and threat intelligence capabilities?

BlueCat DNS Edge extends traditional approaches by being client-facing and located on the first hop inside the network, providing visibility into both north-south and east-west traffic and richer DNS data. This placement enables Edge to apply security policies to internal traffic and faster response times compared with boundary-only firewalls. Edge also applies more sophisticated intelligence capable of identifying complex malicious behaviors—examples cited include DNS tunneling and domain generation algorithms—allowing security teams to detect and block advanced threats that standard DNS firewalls and generic threat feeds often miss.

Key takeaways

DNS security comes in three flavors:

  1. DDoS mitigation
  2. DNS firewalls
  3. Threat-intelligence

Together, these three layers deliver comprehensive DNS-based security that defends against high-traffic attacks, filters out malicious DNS queries, and leverages threat intelligence to block known malicious domains.


In a previous post we covered the basic differences between DNSSEC (which verifies DNS response legitimacy through cryptography) and DNS security (leveraging DNS data to identify and mitigate threats).

It’s clear that cybersecurity professionals are starting to move beyond mere DNSSEC towards leveraging DNS data as part of a layered protection strategy. In a recent survey, we found that 69% of IT administrators responsible for cybersecurity are concerned about their lack of visibility into DNS data or feel that they don’t have the tools necessary to adequately leverage DNS data for security purposes.

In that same survey, however, we discovered that DNS security is actually a pretty broad category.  Cybersecurity professionals know that DNS is important and are concerned about their inability to properly use it, but there was also some disagreement about what DNS security really means.

So how can we distinguish between the different kinds of DNS security?  What makes them unique, and how do they apply to today’s network security frameworks?

1. DDoS

The first type of DNS security is deployed in response to a very specific type of threat: distributed denial of service attacks, or DDoS. In a DDoS attack, a server is inundated with DNS responses, often generated by bots or malware from hijacked computers around the world using a spoofed source address, the address of the target, and reflected off of public DNS servers. This tidal wave of DNS responses overwhelms a server’s bandwidth, causing a traffic jam of traffic that prevents normal TCP sessions from getting through – hence the term “denial of service”.

DDoS mitigation is designed to absorb the blow of this type of DNS attack. Usually, that means routing the traffic through a traffic filtering service that has enough bandwidth to handle the load and can strip out the attack traffic, forwarding the normal traffic through to the target server. Compliance standards such as NIST 800-53 provide basic guidance on constructing networks to cope with DDoS attacks; more advanced responses usually involve purchasing DDoS-specific services which provide additional capacity in the event of an attack.

2. Firewalls

DNS firewalls are the second type of DNS security. Where DDoS mitigation dealt mostly with quantitative threats (too many DNS responses), DNS firewalls deal with qualitative threats. In a nutshell, DNS firewalls apply security policies to queries, making a decision about whether each query should be allowed to resolve or not.

If the query meets a defined threat profile, a DNS firewall (usually deployed on the network boundary to intercept outbound traffic) will block the query and respond back with an “nxdomain” to the requesting client. In more sophisticated systems, the DNS query can be sidetracked or “sinkholed” into a security environment where the requested name and source computer can be logged for remediation steps.

3. Threat intelligence

Threat intelligence, the third type of DNS security, takes DNS firewalls to the next level.  Where DNS firewalls apply blanket-type protections to query types or other properties, threat intelligence takes a curated feed of known malicious domains and applies it as a security policy through a DNS firewall.  Usually these feeds are purchased from third-party vendors and simply “plugged in” to existing DNS firewalls, but it is also possible for users to create their own versions of threat intelligence feeds which customize policies for specific security use cases.

Towards the next generation of DNS security

Seeing the basic forms of DNS security on the market, we knew that something better was possible. That’s why we built BlueCat DNS Edge (Edge), a security tool which goes beyond firewalls and threat intelligence to provide a new form of DNS security. Edge adds new capabilities to the foundation of DNS firewalls and threat intelligence:

  • Edge is client-facing. Every other DNS firewall on the market sits on the network boundary, which is great for catching external (“north-south”) traffic but provides no visibility or ability to apply security policies into internal (“east-west”) traffic. However, Edge is able to provide valuable visibility into both, as it’s inside the network – this also brings about richer data.
  • Edge sits on the “first hop.” This allows Edge to apply security policies to all traffic, blocking not only malicious queries which are trying to connect with command and control servers on the outside internet, but also malware which is probing within the network in an attempt to discover sensitive information. As well, this assists with a significantly faster response time.
  • Edge applies more sophisticated intelligence. Standard DNS security tools use generic policies or threat feeds to apply policies. These provide basic-level protections but often can’t anticipate more sophisticated threat types. DNS Edge was built to identify more complex forms of malicious DNS activity such as DNS tunneling and domain generation algorithms. Using these smarter higher-level policies gives security teams the power to identify and block forms of malicious activity which standard DNS security products usually miss.

So maybe you’re one of those 69% of cybersecurity professionals who want to use DNS security, but need to learn more about the available options. Our DNS Edge page is a great place to start – it’s full of videos, analysis, and ideas for your DNS security project.


Published in:


An avatar of the author

BlueCat provides core services and solutions that help our customers and their teams deliver change-ready networks. With BlueCat, organizations can build reliable, secure, and agile mission-critical networks that can support transformation initiatives such as cloud adoption and automation. BlueCat’s growing portfolio includes services and solutions for automated and unified DDI management, network security, multicloud management, and network observability and health.

Related content

Close-up of interlocked metal chain links symbolizing connected network objects and relationships in IPAM

How to map your network with user-defined links in Integrity X

Map your network with user-defined links in Integrity X to define and manage custom relationships, such as dual-stack and NAT environments.

Read more
Flock of geese flying in formation across a blue sky, framed by a pink graphic border, symbolizing coordinated network migrat

Automate your DDI modernization path by migrating with Micetro

Automate cross-platform DNS and DHCP migration with Micetro to reduce risk, eliminate manual effort, and modernize infrastructure faster.

Read more
Three armored figures walking toward a futuristic Las Vegas skyline with pyramids, glowing orb, and "Welcome to Fabulous Las

Your journey to intelligent NetOps begins at Cisco Live

Visit BlueCat’s booth or book a meeting now to learn more about how our solutions can help you build a network that supports constant change.

Read more
Stacked colorful wooden directional arrows on a post by a calm seaside with distant hills and blue sky

Replace BIND and ISC with Micetro DNS/DHCP Server (MDDS)

Tired of patching and manually configuring BIND DNS and ISC DHCP? Discover how Micetro MDDS appliances can replace them for modern DDI.

Read more