← Research

ENGINEERING NOTE · OCTOBER 2026 · 6 MIN READ

Understanding DNS as a control layer

Every connection starts with a name lookup. That makes DNS one of the most effective places to apply privacy and security policy, and one of the easiest to overestimate.

Every connection begins with a name

When an app wants to reach a service, it almost never knows a numeric address. It knows a name, such as a website, an ad server or an API. Before any data moves, the device asks the Domain Name System (DNS) to translate that name into an address. Only then does it connect.

That ordering is the whole story. DNS is a decision point that exists before the connection does, so a policy applied there can stop a request before a single byte of content has been exchanged.

Why DNS works well as a control point

There are four reasons it keeps showing up in privacy and security design.

What policy at this layer can do

A resolver that enforces policy can answer normally, refuse to answer, or answer with a harmless placeholder. Rules can be built from categories such as trackers, advertising domains and known malware or phishing hosts, and they can differ per profile, so a child's device and a parent's device behave differently.

Because the decision is made on the name alone, it is fast and it works the same on every network the device joins.

Where the approach runs out

DNS filtering is powerful but coarse, and it is honest to say where it stops.

How we think about it

We treat DNS as one layer, not the whole defense. It is the cheapest place to stop a lot of unwanted traffic early, and it needs to be backed by controls at the connection and device level for the cases it cannot see. We also keep decisions explainable and fast, with local caching so that a decision does not mean waiting on the network.

KEY TAKEAWAYS

  • DNS runs before the connection, so it is the earliest place to apply policy.
  • It is broad, light and explainable, which is why it is so widely used.
  • It cannot see apps that bypass system lookups, and a domain name is not the same as a purpose.
  • It works best as one layer among several.

Have a question or a correction?