ThreatBook OneDNS
DNS-layer secure web gateway — block malicious destinations before a connection is ever made
The cheapest control point in the stack
Almost every outbound connection starts with a DNS lookup. Enforcing policy at that stage stops a threat earlier than a firewall and at a lower layer than an endpoint agent, which also means it covers devices that can't run an agent at all.
Malicious-domain blocking
Command-and-control, phishing and malware-distribution domains are refused at resolution time.
Enforced before connection
The block happens at the lookup, so no session is ever established with the destination.
Agentless coverage
Printers, cameras, appliances and BYOD hardware are protected without installing anything on them.
Outbound visibility
DNS logs show what your estate is trying to reach — often the first sign of a compromise.
Intelligence-backed
The blocklist is driven by ThreatBook's own threat intelligence rather than a generic feed.
Low operational cost
Deployment is a simple resolver change instead of a full agent rollout, which makes it one of the fastest controls to implement.
What happens on a lookup
Three ways to get it running
Point your resolvers
Change forwarders on your DNS servers or DHCP scope. Takes minutes to set up, not a full project.
- No endpoint agent
- Covers the whole estate
- Fast to trial
Roaming clients
Keep the same policy on laptops that leave the office network.
- Off-network enforcement
- Consistent policy
- Per-device visibility
With the wider stack
Pair DNS enforcement with endpoint and network detection for defence in depth.
- Works alongside OneSEC
- Complements TDP
- Shared intelligence
APAC offices & coverage
Same-jurisdiction threat-intel for ASEAN and East Asian compliance frameworks.
Common questions
How is DNS filtering different from a firewall rule?
While a firewall acts on the connection itself, DNS filtering prevents the connection from being attempted in the first place by refusing to resolve the malicious name. It's also much simpler to deploy: you change central resolvers instead of managing firewall rules across multiple network segments.
Does it work on devices that cannot run an agent?
Yes, and that's a key advantage. Any device using your network's DNS, from printers and IP cameras to building systems and contractor laptops, gets protected without an agent.
What about encrypted DNS (DoH/DoT)?
A device configured to use its own encrypted resolver will bypass your DNS policy. This is a known gap that can be addressed by blocking public DoH endpoints at the firewall or by enforcing resolver settings via device policy. Ask us how the deployment handles this in your environment.
How much does it cost?
ThreatBook does not publish OneDNS pricing. As an authorised reseller we can quote for your seat count and deployment model — use the enquiry form above.
Does RECATOOLS get paid to list OneDNS?
We earn no per-click fee for this listing and our editorial coverage is independent. For full disclosure: RECASYS is an authorised reseller of ThreatBook products under SAIBERGARD Pte. Ltd., ThreatBook's authorised distributor, so it earns revenue if you buy a commercial licence through us — the same relationship disclosed on our other ThreatBook listings.
Need pricing, a demo, or the full brochure?
Tell us about your environment and our team will get back to you with ThreatBook licensing, a guided demo, or the product brochure — usually within one business day.
Handled by RECASYS, an authorised reseller of ThreatBook products under SAIBERGARD Pte. Ltd., ThreatBook's authorised distributor for the region. Enquiries are copied to their sales desk. No obligation — your details are used only to answer you.
Interested in OneDNS?
We can quote for your estate and walk through the deployment.
See OneDNSExplore related tools & intelligence
Hand-picked RECATOOLS pages relevant to DNS and network defence.
Related News
You may be interested in these recent stories from our newsroom.
-
Five APAC Markets, Five AI Rulebooks — but They Agree on the One That Matters
Korea has a comprehensive AI law; Australia decided against one. On text and data mining, three of the five markets have quietly converged.
-
Three Maximum-Severity Ubiquiti UniFi OS Flaws Are Being Exploited — Patch via Bulletin 064 and Check for Compromise
CISA added three maximum-severity Ubiquiti UniFi OS vulnerabilities (CVE-2026-34908, -34909 and -34910) to its Known Exploited Vulnerabiliti...
-
Three Singapore-Based Operators Moved Into South Korea's Data-Centre Market in Two Weeks
STT GDC opened its first South Korea data centre this month, days after Keppel and Digital Edge each moved on Greater Seoul. Singapore-based...