Cybersecurity

What Is DNS Filtering and Why It’s One of the Cheapest Ways to Block Attacks

2 min read
What is DNS filtering, one of the cheapest defences

What Stops an Employee’s Device From Ever Reaching a Malicious Website?

A lot of security spending goes on tools that react once something has already gone wrong: detecting an infection, cleaning up after a breach, restoring from backup. DNS filtering sits earlier in that chain, stopping a device from ever connecting to a known malicious address in the first place.

What DNS Actually Is, in Plain Terms

Every time a device visits a website, it first looks up that website’s address through the Domain Name System, or DNS, essentially a directory that translates a web address you type into the numerical address computers actually use to connect. Every single web request goes through this lookup step, whether the person realises it or not.

How DNS Filtering Uses That Step

DNS filtering checks each of those lookups against lists of known malicious, compromised, or inappropriate websites, and blocks the connection before it ever completes. If an employee clicks a link in a phishing email pointing to a fake login page, DNS filtering can stop the connection at the lookup stage, before the fake page ever loads on screen.

Crucially, this works across the whole network at once, and does not depend on the employee spotting anything suspicious themselves. The protection happens silently, before the danger is ever visible.

Why It’s Considered Such Good Value

Compared to more involved security tools, DNS filtering is relatively inexpensive to deploy and requires very little ongoing management once configured. It does not slow devices down noticeably, does not require staff to change how they work day to day, and provides a layer of protection that operates continuously in the background. For the cost involved, it closes off a genuinely significant chunk of attack routes before they ever get close to causing damage.

What It Does Not Replace

DNS filtering is one layer, not a complete security strategy on its own. It will not stop every attack, particularly ones that do not rely on a malicious website at all, such as a booby-trapped attachment sent directly rather than via a link. It works best alongside other layers as part of a layered security approach, rather than as a standalone solution.

Why This Matters Given How Attacks Actually Arrive

The UK Government’s Cyber Security Breaches Survey 2025/2026 found phishing was the most commonly identified attack type, experienced by 38 percent of UK businesses. A large proportion of phishing attacks rely on directing someone to a malicious website. DNS filtering directly targets that specific mechanism, working alongside email security to close off the routes attackers rely on most, which is exactly why it punches above its cost for the protection it provides.

How AOIT Networks Approaches It

DNS filtering is included as standard across the networks we manage, providing a continuous layer of protection that does not depend on staff spotting anything themselves. It works alongside the rest of a layered security approach, not instead of it.

If you are not sure whether DNS filtering is currently protecting your network, we are happy to check and talk through what it would add.

Share

Got Questions About Your IT?

Questions about your setup? Wondering if there's a better way to do things? We're always happy to have a no-pressure conversation about your IT needs.

No sales pitch. No obligation. Just straightforward advice from people who genuinely care about getting it right.

More in Cybersecurity