GraceDNS
Log in Setup Now

Threat protection#

Threat protection blocks the infrastructure of active attacks: domains that distribute malware, phishing pages that imitate banks and login screens, and the command servers that infected devices report to. It is the core protection layer and the reason most customers use GraceDNS.

Where the data comes from#

Multiple independent intelligence sources, including European security agencies and abuse-tracking projects, feed our lists. Each source is fetched on its own schedule, cross-checked, and compiled into the lists your resolvers use. We only include sources whose data we may use for you cleanly, and we drop entries the moment a source retracts them. If a source is temporarily unreachable, its last good data stays active rather than leaving a gap.

Three layers of blocking#

Malicious domains are blocked by name: if a lookup matches a known-bad domain or any of its subdomains, it never resolves. Malicious addresses are blocked by answer: even if a fresh, clean-looking domain points at a known malware server, we refuse the answer. Criminal networks extends that to whole network ranges operated by or for criminals, so rotating single addresses inside them does not help the attacker.

What you control#

Each threat category can be switched on or off per configuration, and each can have its own block type. If a block ever hits something you need, your allowlist wins immediately. When you use the REFUSED block type, the response names the category that matched, so you can see why a lookup was blocked.

Freshness#

Sources are refreshed continuously, on cadences from minutes to hours depending on the source, and updated lists reach the resolvers automatically. No blocklist catches everything on day zero; see what DNS filtering cannot do for the honest limits.

Coming soon: blocking of newly registered domains and look-alike (typosquatting) domains.

Back to features.