Managed threat-domain sources
Matching phishing and malware-domain sources can prevent the configured endpoint from reaching a known risky hostname.
QueryWarden evaluates DNS requests against managed phishing and malware-domain protection alongside the account’s current policy. When the privacy setting permits evidence, teams and individuals can inspect the recorded decision without treating a DNS signal as a complete incident verdict.
A protective decision is most useful when the operator can identify its source, the endpoint or scope involved when that data exists, and whether the event is an isolated block or part of a measured change in retained DNS activity.
Each capability below reflects the current public product, with beta and compatibility limits called out separately.
Matching phishing and malware-domain sources can prevent the configured endpoint from reaching a known risky hostname.
Eligible retained events can identify whether a custom rule, service policy, Safe Search, parental control, threat source, or resolver result decided the request.
Incident records present detector window, threshold, occurrence count, limitations, privacy coverage, and representative retained evidence where available.
Managed organizations can use privacy-aware reports, scoped API access, signed webhooks, and SIEM export without making domain detail mandatory.
A profile controls which protections apply to its endpoints. A later Query Log explanation can show retained evidence for a particular request, but neither view turns a DNS signal into a complete malware or incident diagnosis.
Open full-size screenshot A configured endpoint requests a hostname matching an active managed source or customer rule.
The resolver returns the configured blocking result before the destination connection begins.
If Full history is active and still retained, the event can show result, endpoint, and decision source.
The operator considers repetition, scope, endpoint context, and other security evidence before changing policy.
QueryWarden applies policy at the recursive DNS layer, before a supported client connects to the requested domain.
QueryWarden authenticates the private endpoint and resolves the profile and organization policy that apply to it.
Managed phishing and malware-domain sources are considered alongside custom rules and other applicable controls in the decision path.
The resolver returns the blocking response before the endpoint establishes its intended connection to that hostname.
The Query log, explanation, incident workflow, alert, or integration contains only the detail permitted by retention and privacy settings.
Threat-domain blocking reduces an important class of risk while leaving content, endpoint behavior, identity, and response ownership to other controls.
Published and reviewed by QueryWarden Engineering, Digiport OÜ. First-party review against the current public QueryWarden product, its documented deployment constraints, and the primary sources listed on this page. This is not an independent audit, certification, approval, or endorsement.
Product screenshots are deterministic captures of the current interface using synthetic accounts, devices, and reserved .test domains. External sources explain protocols and industry guidance; they do not verify QueryWarden implementation claims.
Last reviewed . Product availability can change; dashboard capability labels remain the source of truth. Review our Security & Trust disclosure.These primary sources support the general technical context. Citing them does not mean their publishers evaluated, approved, or endorsed QueryWarden.
No. It can stop a hostname that matches current managed sources or policy, but no DNS service can guarantee detection of every new, compromised, or same-host phishing page.
It means a documented detector threshold was met in the retained DNS evidence available for that tenant and window. Review its limitation and privacy coverage before drawing a conclusion about compromise.
It cannot guarantee that. DNS filtering can reduce exposure when a hostname matches an active managed source or customer policy, including after threat intelligence is updated. It does not detect an unknown exploit, inspect code or files, or stop malicious content served from an allowed hostname, so patching, endpoint, browser, email, identity, and other network controls still matter.
Start with one protected endpoint, generate fresh traffic, and use retained evidence only within the profile’s privacy boundary.