ENTERPRISE DNS FILTERING

Enterprise DNS filtering with policy you can verify.

Manually contracted Enterprise organizations can centralize DNS filtering with role-based access, managed policy, audit history, API and webhook automation, privacy-aware reports, SCIM, and delegated child organizations. OIDC and signed roaming remain gated.

Review Team controls
HQ
Cloud
Remote
Servers
Architecture preview
DoHAvailable encrypted protocol
NBGCurrent primary origin
ManualEnterprise billing today
30 minAverage response target
TEAM CONTROL PLANE

One managed DNS security layer, with explicit boundaries.

Administration, DNS policy, automation, reporting, provisioning, and delegation are live for manually contracted organizations. Native and provider-dependent features stay visibly gated, and DNS filtering remains one layer of a wider security program.

Network deployment · technical preview

QueryWarden Relay now supports credential-bound Linux forwarding for networks whose routers cannot use a custom DoH URL.

Managed policy · available

Assign locked organization templates, services, categories, schedules, and domain rules without changing member privacy settings.

Roaming client · planned

Future signed clients will preserve policy away from the company network.

Illustrative policy UI
Company default142 users · 8 locations
Active
Engineering24 users · Developer tools allowed
Active
Production servers18 servers · Strict mode
Active
DNS FILTERING FOR SMALL BUSINESSES

Validate the security layer before you expand it.

A small business can test QueryWarden on one compatible device with the Free plan. Central administration for multiple people, policies, and locations is currently provided through manual Enterprise onboarding; self-service Team billing remains planned.

Consistent domain policy

Managed organization templates can apply threat sources, categories, services, schedules, and locked custom-domain decisions to assigned members.

Privacy-aware evidence

Query logs, reports, exports, and alerts reflect the active retention and anonymization settings instead of implying visibility that was never recorded.

A bounded security layer

DNS filtering does not inspect full URLs or content, guarantee that every threat is classified, or make an organization compliant by itself. Use it with endpoint, identity, email, and browser controls.

ENTERPRISE INTEGRATIONS

Controlled connections to your security stack.

Available now

SCIM provisioning

Available for bounded Enterprise member and directory-group lifecycle automation.

Requires launch setup

OIDC managed sign-in

Requires provider credentials and end-to-end validation before activation.

Available now

SIEM and REST API

Available scoped exports, signed webhooks, and privacy-aware reports.

Available now

Audit logs

Available immutable records for organization administrative actions.

ENTERPRISE

Plan enterprise DNS filtering around your architecture.

Manual Enterprise accounts can be configured after a direct review. Seat and device allowances plus delegated child organizations are live; custom SLA and regional data-residency terms remain separately scoped.