← All products
QW
DNS & Network Security
querywarden.com

QueryWarden

Every lookup, resolved and defended.

Managed DNS Security — Authoritative DNS on a global anycast network with protective resolution built in — DNSSEC signing, DDoS-absorbing capacity, and threat filtering that blocks malicious domains before a single packet reaches your users.

100+
Anycast locations
<20ms
Median resolve time
100%
Uptime SLA target
24/7
Monitored operations
// Overview

DNS is the first request every session makes and the easiest layer to weaponise. Managed DNS Security runs your zones on Digiport OÜ anycast infrastructure across 100+ data centers, signs them with DNSSEC, and puts a protective resolver in front of your users that refuses malware, phishing and command-and-control domains at query time — with full query visibility instead of a black box.

// Capabilities
01
Global anycast DNS

Zones served from 100+ data centers so every lookup answers from the node closest to the user.

02
DNSSEC signing

One-click signing and key rotation protect your domains against cache poisoning and spoofed answers.

03
Protective resolution

Malware, phishing, botnet and command-and-control domains are blocked at query time, before connection.

04
DDoS-absorbing capacity

Volumetric and amplification attacks are soaked up by the anycast network instead of reaching your zone.

05
Policy & category filtering

Apply per-network or per-site policies for content categories, newly registered domains and risky TLDs.

06
Query-level visibility

Live logs and reporting show what resolved, what was blocked and why — per network, per domain.

// How it works
01
Delegate your zone

Import existing records automatically and point your registrar at Digiport OÜ nameservers.

02
Turn on protection

Enable DNSSEC and choose the threat and content policies each network should enforce.

03
Watch and tune

Review blocked queries and resolution performance, then refine policy from real traffic.

// Built for
SaaS & platform teams

Keep availability high with resilient authoritative DNS and a signed, monitored zone.

Distributed workforces

Protect users on any network without an agent — filtering happens at the resolver.

MSPs & agencies

Manage many client zones and policies from one dashboard with per-tenant reporting.

// FAQ
Do I have to move my hosting?

No. Only DNS delegation changes — your records are imported and your servers and services stay exactly where they are.

Does filtering slow anything down?

Protection runs inside the resolver on the anycast edge, so blocked domains fail fast and clean lookups keep sub-20ms median response times.

Can I set different rules per network?

Yes. Policies apply per network or site, so a guest Wi-Fi and an engineering subnet can enforce entirely different rules.

More from the portfolio

View all →