Home NDR Monitoring DNS Shield UEBA Analytics RECON Scanner Blog Company Deutsch (DE) Contact

Stop malware
before it starts.

DNS Security from Switzerland: AI DNS Filter, OnPrem

DNS Shield is the invisible wall around your digital infrastructure: every DNS request is scored by our proprietary AI scoring engine in milliseconds, malicious domains are terminated. Over 95% detection rate. Swiss engineering, on-premises, compliant with the Swiss Data Protection Act (FADP), no cloud lock-in, no CLOUD Act.

>95%AI detection rate (validated)
100k+Test samples validated
<10msResponse time p99
99.99%Service uptime SLA
28,500+DNS requests/sec. (validated)

DNS Shield in action

See how DNS Shield blocks malware and phishing at the DNS level.

How it works

Multi-stage AI. One verdict. Milliseconds.

DNS Shield replaces simple blacklists with a proprietary, multi-stage AI pipeline that evaluates every DNS query simultaneously from multiple perspectives, before the first network packet is sent.

1
dns

DNS request hits DNS Shield

DNS Shield acts as a transparent DNS resolver. Every query from your devices, servers and applications passes through DNS Shield, with no agent installation, no hardware changes.

  • checkReal-time whitelist/blacklist fast matching
  • checkCached clean domains are resolved instantly
  • checkClient monitoring at the network level
2
psychology

Proprietary AI scoring engine

Unknown domains pass through our in-house scoring pipeline: threat intelligence signals are combined with behavioral analysis and an AI model trained on more than 60,000 manually curated Swiss and German domains.

  • checkProprietary AI, optimized specifically for CH/DE domains
  • checkBehavior-based botnet and tunnel detection
  • checkNewly registered domains (NRD) automatically scored higher
  • checkMultiple independent threat intelligence sources

Conventional blocklists fail against domains that are only a few hours old. DNS Shield evaluates structural features, not list entries.

3
gavel

Verdict & complete audit trail

Every decision is logged with risk score and client context. Malicious domains are terminated, or in MONITOR mode only logged, for risk-free onboarding.

  • checkBLOCK / SUSPICIOUS / ALLOW with risk score
  • checkSyslog forwarding to SIEM (TCP & UDP)
  • checkBlock portal with custom branding for end users
  • checkComplete audit trail for compliance
Proprietary AI engine

Trained for Swiss and German domains.

Generic DNS security models routinely fail on Swiss compound domains, producing masses of false positives that paralyze security teams and erode trust in automated protection.

Our Swiss development team manually curated and labeled more than 60,000 domains to train an AI that handles the specific characteristics of German-language domains. The result: over 95% detection rate at a fraction of the false positives of standard solutions, validated on more than 100,000 test samples.

>95%

AI detection rate, validated on more than 100,000 test samples

60k+

Manually curated CH/DE domains in the training corpus

85%

Fewer false positives on CH/DE domains vs. standard solutions

Swiss

Development, training and operations exclusively in Switzerland

warning

The problem with standard solutions

Generic AI models were trained on English-language domains. Swiss compound domains such as kantonalbank.ch, bundesamt.de or versicherungsbund.ch get flagged as suspicious, generating masses of false positives that overwhelm your security team.

check_circle

The DNS Shield solution

Our AI model was trained exclusively on manually curated Swiss and German domains. It understands the linguistic and structural characteristics of the DACH region, and reliably distinguishes legitimate corporate domains from attacker infrastructure.

science

Empirically validated, continuously improved

Detection performance is continuously evaluated on real production data and the model is iteratively retrained. What you buy keeps getting better, at no additional cost to you.

Why DNS security?

bug_report

Malware & Phishing

Dynamic blocking of known botnet C2s, ransomware hosts and phishing domains: complemented by AI detection for still unknown variants.

leak_add

DNS Tunneling Detection

Prevents data exfiltration over DNS protocols by analyzing anomalous request patterns: no signature lists, no configuration effort.

vpn_lock

DGA & Botnet Detection

Domain generation algorithms are detected in multiple stages using behavioural and structural analysis, including entirely new, never-seen variants, without blocking legitimate Swiss compound names.

new_releases

NRD Detector

Newly Registered Domains are the hallmark of phishing campaigns. DNS Shield detects and scores NRDs automatically. Attackers switch domains after every attack: a new registration costs cents. Blocklists lag hours to days behind.

api

API-First Integration

Automate policy management and reporting via the RESTful API: for SIEM/SOAR workflows, statistics and configuration management.

monitor_heart

Per-Client Behavioral Analysis

Unusual request patterns from individual clients are detected automatically: port scans, botnet activity and compromised endpoints become visible.

translate

Homoglyph/IDN Phishing Detection

Unicode lookalike domains (e.g. Cyrillic substitution in Swiss company domains) are blocked as phishing attempts: protecting against brand impersonation.

іronate.ch (Cyrillic) vs. ironate.ch (legitimate)

swap_horiz

Fast-Flux Infrastructure Detection

Short-lived DNS infrastructure (fast-flux, double-flux) is detected and blocked: a typical hallmark of professional botnet C2 infrastructure.

lightbulb

Explainable AI (Verdict Insights)

Every block shows the top factors behind the AI decision: transparent, traceable, auditable. No black-box blocking.

Phishing, real-world example

One attack. 6 hours old.
Not on a single list.

At 3:47 a.m., an attacker registers іronate-login-ch.com, with a Cyrillic "і" instead of the Latin "i". No threat feed in the world has this domain. Every blocklist: empty.

At 9:12 a.m., an employee clicks the phishing link. DNS Shield evaluates the request: domain registered 5 hours ago (NRD score critical), homoglyph of ironate.ch detected, entropy anomaly in the label. Risk score: 98/100. DNS resolution is terminated before the browser sends a single packet.

<3ms
Decision time
6h
Domain age at detection
0
List entries in existence
5 detection layers

What DNS Shield detects,
no other DNS filter sees.

DNS Shield combines five independent detection layers into a single risk score. Each layer picks up where the other leaves off, for maximum coverage with minimal false positives.

fiber_new
Layer 1

NRD Early Warning

Domains registered within the last 30 days automatically receive an elevated risk profile. Attackers register new domains daily, DNS Shield detects them from hour one.

ssid_chart
Layer 2

EWMA Client Baseline

Every client gets its own dynamic behavioral model. Recent requests are weighted more heavily, deviations are detected immediately, even when an attack starts slowly.

functions
Layer 3

Structure & Entropy Analysis

Algorithmically generated domains (DGA) and DNS tunnels leave characteristic entropy signatures. The multi-stage structural analysis detects algorithmically generated random domains while legitimate Swiss compound names pass.

crisis_alert
Layer 4

RAS: Retrieval-Augmented Signals

Every DNS request is evaluated in the context of the individual client history. What is normal for one client can be an anomaly here, DNS Shield knows the difference.

timer_off
Layer 5

TTL Anomaly & Fast-Flux

Professional botnet infrastructure rotates IP addresses within seconds. Suspiciously short DNS TTL values are an early indicator, fast-flux infrastructure is automatically flagged and blocked.

Why DNS Shield?

List-based. Cloud-only. No compliance.
DNS Shield is the answer to all three.

NextDNS, Cloudflare and Cisco are cloud services under US jurisdiction. Only DNS Shield combines real AI, a DACH-optimized model and full data sovereignty: on-premises, compliant with the Swiss Data Protection Act (FADP), no CLOUD Act risk.

Feature DNS Shield NextDNS Cloudflare Gateway Cisco Umbrella
Detection rate >95% (validated) Not published Not published Not published
DGA & botnet detection (without signatures) check_circle help check_circle check_circle
On-premises / no forced cloud check_circle cancel cancel cancel
FADP / GDPR / CLOUD-Act-free check_circle cancel cancel cancel
AI optimized for CH/DE domains check_circle cancel cancel cancel
REST API & SIEM integration check_circle check_circle check_circle check_circle
MONITOR mode (risk-free onboarding) check_circle cancel help check_circle
Per-client behavioral analysis check_circle cancel partial check_circle
(paid add-on)
Explainable AI (verdict insights) check_circle cancel cancel cancel
Swiss Made & local support check_circle cancel cancel cancel
Pricing model CHF 0.50–4.50
per entity / mo.
USD 1.99–19.90/mo.
(Business per 50 employees, US cloud)
USD 7 / user / mo.
(US data)
Enterprise license
(complex)

help = limited or configuration-dependent. Sources: public vendor product information, as of August 2026.

Business benefits

Your company deserves proactive protection

91% of all malware uses DNS for C2 communication. DNS Shield closes this gap before an attack does any damage.

block

Prevent attacks, don't just detect them

Unlike reactive solutions, DNS Shield blocks threats preventively at the DNS level. Malware, ransomware and phishing are stopped before a network connection is ever established, the most effective first line of defense.

rocket_launch

Deployment in minutes, without agents

DNS Shield requires no agents or hardware changes. Point your DNS resolver at DNS Shield, and your entire network is protected. MONITOR mode allows risk-free testing before going live.

visibility

Complete DNS visibility

See every DNS query in your company in real time. Identify shadow IT, unauthorized cloud services and suspicious communication patterns via the web dashboard with live query stream.

family_restroom

Employee and device protection

Protect all endpoints, servers and IoT devices centrally, without agents on every endpoint. Category filters for adult content, gambling and advertising additionally boost productivity.

Industries

DNS security for regulated industries

Swiss financial institutions, hospitals and industrial companies have special requirements for data sovereignty and compliance, DNS Shield is built for them.

account_balance

Finance & Banking

FINMA-compliant network logging and incident response straight out of DNS Shield. Blocks phishing against e-banking customers, even for newly registered lookalike domains only hours old.

  • checkFINMA-grade audit trail
  • checkNRD protection against e-banking phishing
  • checkNo US CLOUD Act access to customer queries
local_hospital

Healthcare

Hospitals and clinics are prime ransomware targets. DNS Shield blocks C2 communication and ransomware infrastructure before a single machine is encrypted, compliant with the Swiss Data Protection Act (FADP) and without cloud dependency.

  • checkReal-time ransomware C2 blocking
  • checkFADP-compliant for patient data
  • checkNIS2 requirements met
factory

Industry & SMB

Manufacturers and SMBs benefit from simple deployment without major IT effort. DNS Shield protects OT/IT networks alike, at SMB-friendly prices from CHF 0.50/entity.

  • checkOT/IT network protection at the DNS level
  • checkScalable from 1 entity
  • checkNo dedicated security team required
hub

MSSP & Managed Security

Manage multiple customer environments centrally from a single instance. Per-client tracking, separated log indexes, configurable policies per tenant and Azure AD/Entra SSO for operator access.

  • checkMulti-tenant management from one admin interface
  • checkPer-tenant policies, whitelists and reporting dashboards
  • checkAzure AD / Entra ID SSO (OIDC) for operator teams
Threat categories

What DNS Shield blocks

DNS Shield detects and blocks the most important DNS-borne threats as well as unwanted content categories, each category is independently configurable per tenant (BLOCK / MONITOR / ALLOW).

coronavirus

Malware

Known malware distribution, drive-by downloads and malware hosts.

phishing

Phishing

Credential and data theft domains, including newly registered variants. Incl. homoglyph/IDN lookalikes and domains that have been online for less than 24 hours.

satellite_alt

Command & Control

C2 infrastructure for botnets, RATs and implants is terminated.

shuffle

DGA & Botnets

Domain generation algorithms are detected behaviorally, without signatures.

leak_add

DNS Tunneling

Data exfiltration over the DNS protocol is detected through pattern analysis. Base64URL/Base32 payload detection and QTYPE distribution analysis (DNS TXT/NULL query dominance) complement the request pattern analysis for maximum tunneling coverage.

currency_bitcoin

Cryptomining

Block unauthorized mining pools and protect your resources.

no_adult_content

Adult Content

Compliance-grade content filtering by policy.

block

Ads & Tracking

Filter trackers and ad infrastructure network-wide.

casino

Gambling

Gambling domains are blocked or monitored as a configurable category, for compliance requirements in education, healthcare and finance.

tune

MONITOR mode for risk-free onboarding

Start in MONITOR mode, every block is only logged, traffic keeps flowing. This lets you test policies on your real traffic without any production risk. Switch to ACTIVE mode once your policies are dialed in, whitelist and blacklist can be adjusted at any time without downtime.

Deployment & Integration

Runs where your data lives.

DNS Shield integrates seamlessly into existing networks, SIEM/SOAR workflows and enterprise toolchains, without forced cloud, without external data dependency.

lan

DNS Resolver Architecture

DNS Shield fits seamlessly into existing networks, as a drop-in DNS resolver or as an additional protection layer in front of your current resolver:

  • checkStandards-compliant DNS resolver support (UDP/TCP)
  • checkFreely configurable upstream resolvers
  • checkHigh availability with failover support
  • checkMulti-site deployment for distributed locations
  • checkRegex and wildcard DNS rules
dashboard

Web Dashboard & Block Portal

A modern web UI for operators, and a customizable block portal for end users when a domain has been blocked:

  • checkLive query stream with color classification
  • checkFull rule engine with ALLOW/BLOCK/REDIRECT, regex and wildcard matching plus subnet-specific client overrides
  • checkMulti-user authentication with roles
  • checkCustom branding for the block portal
  • checkAnalytics dashboard with real-time statistics
api

REST API & SIEM Forwarding

Integrate DNS Shield into your existing toolchain, or use it as an additional telemetry source for your SIEM:

  • checkRESTful API for policy management and statistics
  • checkSyslog forwarding (TCP / UDP) to SIEM
  • checkLive statistics queryable via API
  • checkCompatible with common SIEM and SOAR tools
  • checkOpenSearch indexing for analytical log search and SIEM integration
deployed_code

OnPrem & Container

DNS Shield runs wherever you want, on your hardware, in your virtualization or as a container on your existing platform:

  • checkBare-metal or VM (Linux)
  • checkDocker / container deployment
  • checkHybrid models for multi-site
  • checkNo cloud dependency, no external telemetry
  • checkIPv4 and IPv6 dual stack, full dual-stack resolution and WHOIS enrichment
Compliance & Sovereignty

Swiss DNS security: your data, your sovereignty.

DNS requests are highly sensitive, they reveal which services your employees use, which partners you work with, which cloud services you are evaluating. This telemetry does not belong in foreign cloud backends.

flag

Swiss Made

Development, operations and support from Switzerland. No CLOUD Act, no US jurisdiction over your DNS data.

verified_user

FADP / revDSG / GDPR

Compliant with the revised Swiss Data Protection Act (revDSG) and the EU GDPR, through data minimization by architecture.

policy

NIS2 & FINMA-ready

Meets network logging and incident response requirements for regulated industries, with a complete audit trail.

cloud_off

No cloud lock-in

Full control over threat feeds, logs and configuration. DNS requests never leave your infrastructure.

Transparent pricing

DNS Shield price list

Fair, volume-based pricing. The more entities you protect, the lower the price per unit.

Number of entities Price in CHF
1 – 100CHF 4.50
101 – 300CHF 4.00
301 – 500CHF 3.00
501 – 1,000CHF 2.00
1,001 – 2,000CHF 1.50
2,001 – 4,000CHF 0.80
4,001 – 8,000CHF 0.60
8,001 – 12,000CHF 0.50

Prices per entity / month, excl. VAT. Custom terms available from 12,000 entities on request.

What is DNS Shield?

DNS Shield is a Swiss DNS security solution that acts as an invisible protective wall between your network and the internet. Every DNS request is evaluated by a proprietary, multi-stage AI scoring pipeline, malicious domains, phishing sites and command-and-control servers are blocked before a connection is established.

DNS is the phone book of the internet, and at the same time one of the most underestimated attack vectors. Over 91% of all malware uses DNS for its C2 communication. DNS Shield closes this critical security gap and forms the foundation of every modern Zero Trust architecture.

Unlike simple DNS filters that only work with static lists, or cloud-based solutions under US jurisdiction, DNS Shield combines threat intelligence feeds with an in-house AI engine trained on more than 60,000 manually curated Swiss and German domains, for over 95% detection rate at a fraction of the false positives.

IRONATE DNS Shield runs exclusively in your own infrastructure (on-premises or container), is FADP, GDPR and NIS2 compliant and achieves a response time of under 10 milliseconds (p99) at high throughput.

Frequently asked questions about DNS Shield

What is DNS Shield and how does it work?expand_more

DNS Shield operates as a secure DNS resolver in your network. Every DNS request is evaluated by a proprietary, multi-stage AI scoring pipeline that combines threat intelligence, behavioral analysis and an AI model trained on more than 60,000 manually curated Swiss and German domains. Malicious domains are blocked before a connection is established. Over 95% detection rate, validated on more than 100,000 test samples.

What is the difference between DNS Shield and Pi-hole?expand_more

Pi-hole is an open-source DNS filter that works exclusively with static blacklists. Static lists only detect known threats and fail completely against DGA botnets, DNS tunneling and newly registered phishing domains created just hours ago. DNS Shield combines threat feeds with a proprietary AI engine (over 95% detection rate), detects unknown threats without signature lists, provides a complete audit trail and SIEM integration, and was specifically optimized for Swiss and German domains to minimize false positives.

Why not Cloudflare Gateway or Cisco Umbrella?expand_more

Cloud-based DNS security processes every DNS query of your company in the cloud of a US provider, including information about which services your employees use, which partners you work with and which technologies you are evaluating. US providers are subject to the US CLOUD Act regardless of server location; data-residency options often cover log storage only. For companies subject to the revised Swiss Data Protection Act (revDSG), the GDPR, FINMA guidelines or NIS2, this is a critical compliance problem. DNS Shield runs exclusively in your own infrastructure, not a single DNS query leaves your network.

Why is DNS security important for Zero Trust?expand_more

Over 91% of all malware uses DNS for command-and-control communication. Without DNS control, a compromised endpoint can communicate with external C2 servers even with microsegmentation in place. DNS Shield closes this critical gap in Zero Trust architectures and forms the first line of defense, ahead of firewall and EDR.

Does DNS Shield protect against DNS tunneling and DGA botnets?expand_more

Yes. DNS tunneling, hiding data exfiltration inside the DNS protocol, is detected and blocked by analyzing anomalous request patterns. DGA botnets (domain generation algorithms) are detected behaviorally, without requiring signature lists. Both attack vectors are detected even in previously unknown variants.

How low-risk is the rollout of DNS Shield?expand_more

DNS Shield offers a MONITOR mode: in this phase, blocks are only logged, traffic keeps flowing. This lets you test your policies on real traffic without any production risk. Once your policies are dialed in, you switch to ACTIVE mode. Whitelist and blacklist can be adjusted at any time without downtime. Deployment requires no agents or hardware changes, just a change of DNS resolver.

Does DNS Shield also detect newly registered domains (NRD)?expand_more

Yes. DNS Shield includes a built-in NRD detector (Newly Registered Domains). Freshly registered domains are a hallmark of phishing campaigns: attackers register short-lived domains, launch an attack and move on. DNS Shield automatically detects and scores NRDs with an elevated risk score. The NRD check can be enabled in the dashboard.

How does DNS Shield integrate with my SIEM/SOAR?expand_more

DNS Shield offers syslog forwarding (TCP & UDP) for all block and monitor verdicts as well as a RESTful API for policy management, statistics and configuration changes. Every verdict includes risk score and client context for full contextualization in the SIEM. The solution is seamlessly compatible with common SIEM and SOAR platforms.

Where can DNS Shield be operated?expand_more

DNS Shield is on-premises first: bare-metal or VM deployment on Linux, alternatively as a container (Docker). Hybrid deployments across multiple sites are possible. DNS requests never leave your infrastructure, no external telemetry, no cloud dependency.

Is DNS Shield FADP, GDPR and NIS2 compliant?expand_more

Yes. DNS Shield is developed and operated exclusively from Switzerland, without CLOUD Act access, without US jurisdiction. The on-premises architecture means no external data processing takes place. The platform is compliant with the revised Swiss Data Protection Act (revDSG), the EU GDPR as well as NIS2 and FINMA requirements for network logging and incident response.

Which company sizes is DNS Shield suitable for?expand_more

DNS Shield scales from small SMBs (from 1 entity, CHF 4.50/month) to enterprise environments with more than 12,000 entities. The system processes tens of thousands of DNS requests per second with a response time under 10 milliseconds. The volume-based pricing makes DNS Shield economically attractive for companies of all sizes.