DNS Security

Secure the protocol attackers hide in.

Cato's DNS Security inspects all DNS traffic, preventing malicious DNS activity hiding within the protocol's traffic, and blocking DNS requests to malicious destinations before a connection is made.

Block bad domains before they connect.

Cato uses timely, continuously optimized threat intelligence to identify malicious domains and C&C sites and block traffic in real time.

Catch phishing and tunneling inline.

AI and ML algorithms trained on Cato's global data lake identify domain squatting, website impersonation, and DNS tunneling in real time.

Today's Challenges

DNS is where attacks hide.

DNS is a security blind spot
Phishing and impersonation
Data exfiltration via tunneling
Resource leaching by crypto miners
01 / 04

DNS is a security blind spot

DNS traffic has to be allowed through, so attackers hide malicious activity inside the protocol where most controls never look.

02 / 04

Phishing & impersonation

Domain squatting and website impersonation harvest credentials and deliver malware before reputation-based tools catch up.

03 / 04

Data exfiltration via tunneling

DNS tunneling abuses permitted DNS traffic to smuggle data out of the network and reach command-and-control servers.

04 / 04

Resource leaching by crypto miners

Crypto miners hijack corporate endpoints for financial gain β€” degrading performance, user experience, and inflating costs.

Our approach

Inspect every request.
Block before connection.

DNS is one of the most abused paths for malware and exfiltration, and one of the least watched. Cato DNS Security inspects every query against real-time threat intelligence and AI analysis, blocking malicious and risky domains before a connection is ever made.

Security analyst reviewing code across multiple monitors

Inspect all DNS

Inspect every DNS request in real time β€” including malicious activity hiding inside permitted DNS traffic.

Detect with AI/ML

Models trained on Cato's global data lake identify phishing, impersonation, tunneling, and crypto-mining patterns.

Block before connection

Block DNS requests to malicious destinations before a connection is ever made β€” with near-zero false positives.

Solution Brief

Stop Threats Everywhere with Converged Zero Trust Security

How it works

DNS Security Capabilities

Real-time AI/ML inspection

AI-based DNS inspection for inline phishing protection

AI and ML trained on Cato's global data lake identify domain squatting and website impersonation in-line.

  • Analyze webpage components, domain age, and popularity
  • Spot patterns tied to known phishing toolkits
  • Prevent credential harvesting and malware delivery
Anomaly-based, threat-agnostic

Stop data loss over DNS tunneling

Cato analyzes DNS request properties to identify anomalies and indicators of DNS tunneling attacks.

  • Inspect packet size, record type, and subdomain ratios
  • AI/ML continuously trained to spot tunneling
  • Protection independent of threat actor or domain
Customer Stories

Customers love Cato

Industry photoJPG Β· PNG Β· SVG

I can't fault Cato when you connect a site. The level of automatic blocking for bad traffic is something you don't see with other setups, especially with DNS.

IT Operations ManagerGlobal Mining Equipment Manufacturer

Get a live demo

Secure every interaction across the enterprise, cloud, and AI with the only purpose-built SASE platform.

What to expect
  • 15–30 minute session with a SASE product expert
  • Discuss your use cases and how we can help
  • Live product demonstration where applicable
Get Started

See Cato in Action