DNS Firewall
DNS Firewall

Block threats
before they connect.

RPZDB protects every device on your network from malware, phishing, and botnets — at the DNS layer. No software to install. No endpoints to manage. Just point your resolver and you're protected.

25+ Threat Feeds
Real-Time Updates
Zero Client Software
25+
Threat Intelligence Feeds
80+
Content Categories
<5 min
Threat-to-Block Time
99.95%
Platform Uptime SLA

Simple & Powerful

How DNS Firewall works

Every internet connection starts with a DNS lookup. RPZDB intercepts dangerous lookups before any connection is made — protecting your entire network in milliseconds.

User Device

Wants to visit a website

DNS Query

"Where is evil.com?"

RPZDB Check

Is it a known threat?

Threat? BLOCKED

User sees a block page

Safe? ALLOWED

Normal resolution

All of this happens in <1 millisecond — before any data leaves your network.

Enterprise Features

Not just a blocklist.
A threat intelligence platform.

RPZDB goes far beyond static domain blocking. It aggregates, scores, and distributes threat data in real time.

25+ Threat Feeds

Aggregates intelligence from global sources — malware trackers, phishing databases, botnet C&C lists, cryptojacking, and more. Automatically deduplicated and scored.

Real-Time CT Monitoring

Watches Certificate Transparency logs to detect phishing sites the moment they get an SSL certificate — often before the attack even starts.

AI Detection Engines

DGA detection catches algorithmically-generated botnet domains. Typosquatting engine protects your brand. NRD quarantine blocks newly registered suspicious domains.

80+ Content Categories

Filter by category: gambling, adult content, social media, streaming, crypto, and more. Perfect for schools, workplaces, and family networks.

Analytics Dashboard

See what's being blocked in real time. Top blocked domains, threat categories, query volume, and trends. Export to SIEM via API.

Custom Policies

Create your own allow/block lists. Set policies per organization, network, or location. Override any feed decision with one click.

REST API & DoH

Full API for lookups, bulk checks, and feed management. DNS-over-HTTPS endpoint for secure client configuration. Webhook notifications.

Zone Transfer Distribution

Receive threat data via standard zone transfers to your own resolvers. TSIG-authenticated. Incremental updates every 5 minutes. Your data stays yours.

Multi-Tenant

Managed service providers and ISPs can serve multiple customers from one platform. Each tenant gets their own policies, analytics, and API keys.

Built For Everyone

From families to
entire nations.

🏠

Families

Free tier blocks malware and adult content at home. Protect every phone, tablet, laptop, and IoT device — just change your router's DNS.

🏫

Schools & Universities

CIPA-compliant content filtering. Protect students from harmful content. Built-in reporting for auditors. Category-based policies per network.

🏢

Enterprises

Integrate into your security stack alongside SIEM, EDR, and firewalls. API-driven. Custom threat feeds. SLA-backed uptime. Dedicated support.

🌐

ISPs & Governments

Protect millions of subscribers. Multi-tenant isolation. Custom national policies. Regulatory compliance reporting. Dedicated infrastructure.

What We Block

Comprehensive threat coverage

🦠
Malware
🎣
Phishing
🤖
Botnets
💰
Ransomware
⛏️
Cryptojacking
📡
C&C Servers
🔞
Adult Content
🎰
Gambling
📱
Social Media
🎮
Gaming
📺
Streaming
70+ more

Architecture

Built for scale & speed

From a single home network to a national ISP protecting millions — RPZDB scales to any deployment.

Intelligence Layer

Threat feed aggregation
CT log monitoring
DGA / NRD / Typosquat engines
Scoring & deduplication

Policy Engine

Per-tenant policies
Category filtering rules
Custom allow/block lists
Zone generation & signing

Distribution

Zone transfer (TSIG-auth)
Incremental updates (IXFR)
DoH endpoint
REST API & webhooks
Collect Analyze & Decide Distribute & Protect

Why RPZDB

More than a blocklist service

Feature RPZDB Free Resolvers Feed Providers Enterprise DNS Security
Custom block/allow lists
80+ content categories
Zone transfer to your resolvers
Real-time CT log monitoringSome
DGA & typosquat detection
Multi-tenant / ISP supportLimited
Analytics dashboard
Data stays on your infra
Free tier
Threats are active right now

Your network is exposed
every second without DNS protection.

Start blocking malware, phishing, and botnets in under 5 minutes. No hardware. No software. Just DNS.