DNS is the first request every session makes and the easiest layer to weaponise. Managed DNS Security runs your zones on Digiport OÜ anycast infrastructure across 100+ data centers, signs them with DNSSEC, and puts a protective resolver in front of your users that refuses malware, phishing and command-and-control domains at query time — with full query visibility instead of a black box.
Zones served from 100+ data centers so every lookup answers from the node closest to the user.
One-click signing and key rotation protect your domains against cache poisoning and spoofed answers.
Malware, phishing, botnet and command-and-control domains are blocked at query time, before connection.
Volumetric and amplification attacks are soaked up by the anycast network instead of reaching your zone.
Apply per-network or per-site policies for content categories, newly registered domains and risky TLDs.
Live logs and reporting show what resolved, what was blocked and why — per network, per domain.
Import existing records automatically and point your registrar at Digiport OÜ nameservers.
Enable DNSSEC and choose the threat and content policies each network should enforce.
Review blocked queries and resolution performance, then refine policy from real traffic.
Keep availability high with resilient authoritative DNS and a signed, monitored zone.
Protect users on any network without an agent — filtering happens at the resolver.
Manage many client zones and policies from one dashboard with per-tenant reporting.
No. Only DNS delegation changes — your records are imported and your servers and services stay exactly where they are.
Protection runs inside the resolver on the anycast edge, so blocked domains fail fast and clean lookups keep sub-20ms median response times.
Yes. Policies apply per network or site, so a guest Wi-Fi and an engineering subnet can enforce entirely different rules.