DNS Security
Secure the protocol attackers hide in.
Cato's DNS Security inspects all DNS traffic, preventing malicious DNS activity hiding within the protocol's traffic, and blocking DNS requests to malicious destinations before a connection is made.
Block bad domains before they connect.
Cato uses timely, continuously optimized threat intelligence to identify malicious domains and C&C sites and block traffic in real time.
Catch phishing and tunneling inline.
AI and ML algorithms trained on Cato's global data lake identify domain squatting, website impersonation, and DNS tunneling in real time.
DNS is where attacks hide.




DNS is a security blind spot
DNS traffic has to be allowed through, so attackers hide malicious activity inside the protocol where most controls never look.
Phishing & impersonation
Domain squatting and website impersonation harvest credentials and deliver malware before reputation-based tools catch up.
Data exfiltration via tunneling
DNS tunneling abuses permitted DNS traffic to smuggle data out of the network and reach command-and-control servers.
Resource leaching by crypto miners
Crypto miners hijack corporate endpoints for financial gain β degrading performance, user experience, and inflating costs.
Inspect every request.
Block before connection.
DNS is one of the most abused paths for malware and exfiltration, and one of the least watched. Cato DNS Security inspects every query against real-time threat intelligence and AI analysis, blocking malicious and risky domains before a connection is ever made.
Inspect all DNS
Inspect every DNS request in real time β including malicious activity hiding inside permitted DNS traffic.
Detect with AI/ML
Models trained on Cato's global data lake identify phishing, impersonation, tunneling, and crypto-mining patterns.
Block before connection
Block DNS requests to malicious destinations before a connection is ever made β with near-zero false positives.
Stop Threats Everywhere with Converged Zero Trust Security
DNS Security Capabilities
AI-based DNS inspection for inline phishing protection
AI and ML trained on Cato's global data lake identify domain squatting and website impersonation in-line.
- Analyze webpage components, domain age, and popularity
- Spot patterns tied to known phishing toolkits
- Prevent credential harvesting and malware delivery

Stop data loss over DNS tunneling
Cato analyzes DNS request properties to identify anomalies and indicators of DNS tunneling attacks.
- Inspect packet size, record type, and subdomain ratios
- AI/ML continuously trained to spot tunneling
- Protection independent of threat actor or domain

Block malicious domains and C&C before connection
Cato's threat intelligence identifies malicious domains and C&C sites and blocks traffic in real time.
- Catch C&C servers that move to evade blacklists
- Block traffic to and from malicious domains in real time
- Reduce exposure with near-zero false positives

Prevent resource leaching from crypto miners
Cato uses dedicated rules and heuristics to identify crypto-mining domains and block DNS requests to them.
- Identify domains used for crypto-mining operations
- Block DNS requests to mining destinations
- Protect endpoint performance and reduce costs

Full visibility into DNS threats and events
All threat activity is logged in Cato's global data lake, surfaced in the security threats dashboard.
- Filter and drill down into all DNS protection events
- Evaluate DNS threats without aggregating sources
- No switching between multiple consoles

Customers love Cato
I can't fault Cato when you connect a site. The level of automatic blocking for bad traffic is something you don't see with other setups, especially with DNS.
Get a live demo
Secure every interaction across the enterprise, cloud, and AI with the only purpose-built SASE platform.
15β30 minute session with a SASE product expert
Discuss your use cases and how we can help
Live product demonstration where applicable
See Cato in Action
Request received
Thanks, there. A Cato specialist will reach out at to schedule your session.