DNS / Web protection
DNS / Web protection is part of meil Business and is used only in business workspaces. It filters DNS lookups against known malware, phishing, botnet, and cryptomining domains, as well as configured categories and custom exceptions.
This is network protection. It primarily identifies a public network point or office IP, not automatically every physical computer behind the same router.
Activate and connect
Open /enheter/dns from Admin.
- Select Activate DNS protection.
- Note the resolver addresses shown in Admin. They are currently:
- Primary:
217.170.206.225 - Secondary:
217.170.206.224
- Primary:
- Add the resolvers as DNS servers on the office router or firewall.
- Add the office’s public IP address under Office IPs. Give it a name such as
Kontor Oslo. - Save the filtering policy.
- Make a controlled lookup from the office and confirm that activity appears in Admin.
A resolver address does not protect traffic until clients actually use it. With a dynamic public IP, update the office IP when it changes. The interface also supports individual clients and states that device management (MDM) can auto-provision DNS on registered machines regardless of location.
If Admin says that device management must be active, activate it first. If the resolvers cannot be synchronized, try again and check the network point before creating exceptions.
Tabs
Overview
Overview is the situational view for DNS traffic. Choose 24 hours, 7 days, or 30 days.
It includes:
- status cards and a DNS Shield score from 0 to 100
- a recommendation and status for normal, warning, or critical activity
- Right now with a 1, 5, or 15 minute window
- lookup count, blocked lookups, lookups per second, active network points, and new domains
- most active network points, most-used services, and new countries in the last day
- Today, What’s new, Business internet, and an event timeline
- traffic map and destination countries with risk levels when data is available
Scores and patterns are indicators, not proof that a computer is compromised or healthy. Map and country information is approximate. In the map drilldown, clients normally mean office/IP or network point, not a unique physical computer.
Settings
Settings is where you configure the service:
- copy the primary and secondary resolver
- see lookups in the last 24 hours, blocked threats, protected office IPs, and latest activity
- add or remove public office IPs
- enable or disable malware, phishing, botnet, cryptomining, and SafeSearch filters
- add domains under Always allow or Always block
- read Alerts and insights grouped as Critical, Should be checked, and Information
- open the technical Query log when needed
Details
Details shows technical statistics for the selected period: time series, a time-of-day heatmap, most-blocked domains, destination countries, and map data. Use it when you need more than the compact status cards in Overview.
Policy and exceptions
Policy choices apply to traffic that goes through DNS protection:
| Choice | What it blocks |
|---|---|
| Malware | Known domains that spread viruses or malicious software. |
| Phishing | Fake sites that try to collect passwords or card details. |
| Botnet | Contact with command servers used by infected computers. |
| Cryptomining | Hidden cryptomining that consumes computer resources. |
| SafeSearch | Forces safer search in Google, Bing, and YouTube. |
A domain under Always allow overrides the filter for that domain. A domain under Always block overrides it and blocks the domain. Check the domain and the business need before creating a permanent exception.
Alerts and insights
The service can show patterns that should be investigated, such as:
- new traffic to countries not seen in the normal baseline
- randomly generated domain names that may resemble DGA or DNS tunneling
- unusually high block rates or lookup volume
- a client or network point with many blocked lookups
- new high-risk domains
- overnight activity toward unexpected countries
- lookups against infrastructure with a known abuse history
- a sharp increase in tracking or advertising
- domains changing to an IP with higher risk
These are signals to verify. A new country may be a legitimate cloud service or VPN. A high block rate may be caused by new software. Compare the time, domain, network point, and known work before escalating.
Query log
The technical log is hidden behind Show technical log to keep the page readable. When opened, you can:
- search for a domain
- filter by All, Blocked, or Allowed
- see domain, action, reason, and time
- see the latest 20 visible lookups from the log result
The log is a security and troubleshooting tool, not a full content log of what employees do online.
Coverage and limitations
- Protection applies to network points that are registered or use the resolvers.
- Multiple computers behind the same public IP may appear as one shared network point.
- Unique device links and data freshness are shown only when device management has reported enough information.
- DNS filtering is not the same as endpoint security, antivirus, or remote control.
- An allowed domain can reduce protection. Document why an exception is necessary.
Privacy
Admin can show domains, lookups, timestamps, public IP addresses, countries, and network services. Limit administrator access to people who need it and use the information according to the organization’s procedures and the WAYSCloud privacy notice.