Loading
DNSVault Neo
Loading...
Coming Soon

DNSVault
Neo.

Enterprise DNS appliance with hybrid deployment. Run on-premises for full control, in the cloud for flexibility, or both for maximum resilience.

On-Premises
Cloud-Managed
Hybrid
Common Criteria EAL2

Architecture

Hybrid DNS Architecture

Users & Clients

DNSVault Load Balancer

Geo-routing · Health checks · Failover

PRIMARY

On-Premises

Your Data Center

DNS Resolver
DNSSEC + HSM
RPZdb Firewall
SECONDARY

Cloud

Managed Infrastructure

DNS Resolver
Auto Failover
Global Anycast
TSIG Zone Transfer

Analytics

RPZdb

Threat Intel

Visibility

Real-Time Threat Dashboard

DNS Threat Overview

LiveLast 24h

2.4M

Total Queries

12,847

Blocked

342

Threats Detected

99.5%

Clean Traffic

Query Volume (24h)

00
03
06
09
12
15
18
21
Clean
Blocked

Blocked by Category

Malware47%
Phishing28%
C2 Botnet15%
DNS Tunnel7%
DGA3%
DomainCategoryActionTime
malware-c2.evil.ruMalwareBLOCKED2s ago
login-verify.phish.ccPhishingBLOCKED15s ago
xk3j2.dga-botnet.netC2/DGABLOCKED32s ago
exfil.tunnel.data.ioTunnelBLOCKED1m ago

Deployment Models

Your infrastructure,
your rules.

Choose the deployment model that fits your organization. Switch or combine at any time.

Local

On-Premises Appliance

Hardware appliance deployed in your data center. Full control over your DNS infrastructure with no external dependencies.

  • Air-gapped capable
  • Data never leaves your network
  • Secure web management interface
  • Common Criteria EAL2 certified
  • IPv4 & IPv6 dual-stack

Best for: Government, military, critical infrastructure

Remote

Cloud-Managed

Fully managed DNS appliance in the cloud. Zero hardware to maintain. Scale up or down with demand.

  • Zero hardware procurement
  • Managed updates & patches
  • Global anycast distribution
  • Elastic scaling on demand
  • 99.99% uptime SLA

Best for: SaaS companies, startups, distributed teams

RECOMMENDED

Hybrid

Local + Remote

On-premises appliance with cloud management and failover. Best of both worlds — data sovereignty with cloud resilience.

  • Primary on-prem, secondary in cloud
  • Automatic failover between sites
  • TSIG-authenticated zone transfers
  • Unified management console
  • Data sovereignty + cloud backup

Best for: Enterprise, finance, healthcare, telco

Capabilities

Enterprise DNS
hardened.

DNSSEC + HSM

One-click zone signing with automatic key rollover. Hardware Security Module storage for private keys.

DNS Firewall

Advanced DNS firewall with real-time blacklist filtering. RPZ-based malware prevention. Auto-blacklist DNS attacks.

Response Rate Limiting

Built-in RRL to mitigate DNS amplification and DDoS attacks. No external firewall needed for DNS-layer protection.

Multi-User Management

Secure web interface with role-based authentication. Multiple admins with audit trail for every action.

Secure Zone Transfer

TSIG-authenticated primary-secondary replication. DNS views for split-horizon resolution. Automated serial management.

Monitoring & Reporting

DNS query analytics, real-time monitoring, and compliance reporting. Integration with DNSVault Cloud dashboard.

Security

Certified. Hardened. Trusted.

Common Criteria EAL2

ISO/IEC 15408 certified security evaluation. Trusted for government and critical infrastructure.

DNSSEC + HSM

Hardware Security Module for private key storage. Auto key rollover. DS record management.

RPZ Blacklisting

Real-time DNS blacklist for malware, phishing, and C2 domains. Auto-block with threat intelligence feeds.

IPv4 & IPv6

Full dual-stack support. Native IPv6 resolution and transport. Future-proof your DNS infrastructure.

Neo Product Suite

Complete DNS
security ecosystem.

DNSVault Neo includes integrated modules for load balancing, threat intelligence, analytics, and RPZ-based blacklisting.

DNSVault RPZdb

Response Policy Zone Database

DNS blacklist system that takes control over network security. Stops malware at the DNS layer and prevents sensitive data exfiltration before it reaches the attacker.

Malware Blocking

Block known malware domains, C2 servers, and phishing sites at DNS resolution time

Data Exfiltration

Detect and block DNS tunneling attempts used to steal sensitive data

Auto Blacklist

Automatically blacklist domains involved in active DNS attacks in real-time

Threat Feeds

Integrate with external threat intelligence feeds for continuously updated protection

  • RPZ (Response Policy Zone) standard compliant
  • Custom whitelist and blacklist management
  • Millions of malicious domains blocked daily
  • Zero latency — blocks at DNS layer before connection

DNSVault Load Balancer

DNS-Based Traffic Distribution

Intelligent DNS-based load balancing that distributes traffic across multiple servers and data centers. Geo-aware routing with health-check failover.

Round Robin

Distribute queries equally across backend servers for even load

Geo Routing

Route users to nearest data center based on geographic location

Weighted

Assign traffic weights to servers based on capacity or priority

Health Checks

Automatic removal of unhealthy servers from the DNS pool

  • Multi-site active-active and active-passive
  • Sub-second failover on server failure
  • No client-side agent required
  • Works with any application or protocol

DNSVault Analytics

DNS Intelligence Dashboard

Deep visibility into your DNS traffic. Real-time dashboards, historical trends, query patterns, and anomaly detection to understand how your network uses DNS.

  • Real-time query volume and response code dashboards
  • Top queried domains, NXDOMAIN tracking, client analysis
  • Anomaly detection for unusual query patterns
  • Historical trends with hourly, daily, and monthly rollups
  • Compliance reporting with CSV/PDF export
  • Per-zone and per-client query breakdown

Intelligence Threat Protection

Proactive DNS Security

AI-powered threat intelligence that identifies and blocks emerging DNS threats before they impact your network. Combines global threat feeds with local behavioral analysis.

  • Global threat intelligence feed integration
  • DGA (Domain Generation Algorithm) detection
  • DNS tunneling and covert channel prevention
  • Botnet C2 communication blocking
  • Real-time threat scoring and risk assessment
  • Automated incident reporting and alerting

Ready for enterprise DNS?

Contact us for a demo, pricing, or technical consultation.