Stop malware
before it starts.
DNS Security from Switzerland: AI DNS Filter, OnPrem
DNS Shield is the invisible wall around your digital infrastructure: every DNS request is scored by our proprietary AI scoring engine in milliseconds, malicious domains are terminated. Over 95% detection rate. Swiss engineering, on-premises, compliant with the Swiss Data Protection Act (FADP), no cloud lock-in, no CLOUD Act.
DNS Shield in action
See how DNS Shield blocks malware and phishing at the DNS level.
Multi-stage AI. One verdict. Milliseconds.
DNS Shield replaces simple blacklists with a proprietary, multi-stage AI pipeline that evaluates every DNS query simultaneously from multiple perspectives, before the first network packet is sent.
DNS request hits DNS Shield
DNS Shield acts as a transparent DNS resolver. Every query from your devices, servers and applications passes through DNS Shield, with no agent installation, no hardware changes.
- checkReal-time whitelist/blacklist fast matching
- checkCached clean domains are resolved instantly
- checkClient monitoring at the network level
Proprietary AI scoring engine
Unknown domains pass through our in-house scoring pipeline: threat intelligence signals are combined with behavioral analysis and an AI model trained on more than 60,000 manually curated Swiss and German domains.
- checkProprietary AI, optimized specifically for CH/DE domains
- checkBehavior-based botnet and tunnel detection
- checkNewly registered domains (NRD) automatically scored higher
- checkMultiple independent threat intelligence sources
Conventional blocklists fail against domains that are only a few hours old. DNS Shield evaluates structural features, not list entries.
Verdict & complete audit trail
Every decision is logged with risk score and client context. Malicious domains are terminated, or in MONITOR mode only logged, for risk-free onboarding.
- checkBLOCK / SUSPICIOUS / ALLOW with risk score
- checkSyslog forwarding to SIEM (TCP & UDP)
- checkBlock portal with custom branding for end users
- checkComplete audit trail for compliance
Trained for Swiss and German domains.
Generic DNS security models routinely fail on Swiss compound domains, producing masses of false positives that paralyze security teams and erode trust in automated protection.
Our Swiss development team manually curated and labeled more than 60,000 domains to train an AI that handles the specific characteristics of German-language domains. The result: over 95% detection rate at a fraction of the false positives of standard solutions, validated on more than 100,000 test samples.
AI detection rate, validated on more than 100,000 test samples
Manually curated CH/DE domains in the training corpus
Fewer false positives on CH/DE domains vs. standard solutions
Development, training and operations exclusively in Switzerland
The problem with standard solutions
Generic AI models were trained on English-language domains. Swiss compound domains such as kantonalbank.ch, bundesamt.de or versicherungsbund.ch get flagged as suspicious, generating masses of false positives that overwhelm your security team.
The DNS Shield solution
Our AI model was trained exclusively on manually curated Swiss and German domains. It understands the linguistic and structural characteristics of the DACH region, and reliably distinguishes legitimate corporate domains from attacker infrastructure.
Empirically validated, continuously improved
Detection performance is continuously evaluated on real production data and the model is iteratively retrained. What you buy keeps getting better, at no additional cost to you.
Why DNS security?
Malware & Phishing
Dynamic blocking of known botnet C2s, ransomware hosts and phishing domains: complemented by AI detection for still unknown variants.
DNS Tunneling Detection
Prevents data exfiltration over DNS protocols by analyzing anomalous request patterns: no signature lists, no configuration effort.
DGA & Botnet Detection
Domain generation algorithms are detected in multiple stages using behavioural and structural analysis, including entirely new, never-seen variants, without blocking legitimate Swiss compound names.
NRD Detector
Newly Registered Domains are the hallmark of phishing campaigns. DNS Shield detects and scores NRDs automatically. Attackers switch domains after every attack: a new registration costs cents. Blocklists lag hours to days behind.
API-First Integration
Automate policy management and reporting via the RESTful API: for SIEM/SOAR workflows, statistics and configuration management.
Per-Client Behavioral Analysis
Unusual request patterns from individual clients are detected automatically: port scans, botnet activity and compromised endpoints become visible.
Homoglyph/IDN Phishing Detection
Unicode lookalike domains (e.g. Cyrillic substitution in Swiss company domains) are blocked as phishing attempts: protecting against brand impersonation.
іronate.ch (Cyrillic) vs. ironate.ch (legitimate)
Fast-Flux Infrastructure Detection
Short-lived DNS infrastructure (fast-flux, double-flux) is detected and blocked: a typical hallmark of professional botnet C2 infrastructure.
Explainable AI (Verdict Insights)
Every block shows the top factors behind the AI decision: transparent, traceable, auditable. No black-box blocking.
One attack. 6 hours old.
Not on a single list.
At 3:47 a.m., an attacker registers іronate-login-ch.com, with a Cyrillic "і" instead of the Latin "i". No threat feed in the world has this domain. Every blocklist: empty.
At 9:12 a.m., an employee clicks the phishing link. DNS Shield evaluates the request: domain registered 5 hours ago (NRD score critical), homoglyph of ironate.ch detected, entropy anomaly in the label. Risk score: 98/100. DNS resolution is terminated before the browser sends a single packet.
What DNS Shield detects,
no other DNS filter sees.
DNS Shield combines five independent detection layers into a single risk score. Each layer picks up where the other leaves off, for maximum coverage with minimal false positives.
NRD Early Warning
Domains registered within the last 30 days automatically receive an elevated risk profile. Attackers register new domains daily, DNS Shield detects them from hour one.
EWMA Client Baseline
Every client gets its own dynamic behavioral model. Recent requests are weighted more heavily, deviations are detected immediately, even when an attack starts slowly.
Structure & Entropy Analysis
Algorithmically generated domains (DGA) and DNS tunnels leave characteristic entropy signatures. The multi-stage structural analysis detects algorithmically generated random domains while legitimate Swiss compound names pass.
RAS: Retrieval-Augmented Signals
Every DNS request is evaluated in the context of the individual client history. What is normal for one client can be an anomaly here, DNS Shield knows the difference.
TTL Anomaly & Fast-Flux
Professional botnet infrastructure rotates IP addresses within seconds. Suspiciously short DNS TTL values are an early indicator, fast-flux infrastructure is automatically flagged and blocked.
List-based. Cloud-only. No compliance.
DNS Shield is the answer to all three.
NextDNS, Cloudflare and Cisco are cloud services under US jurisdiction. Only DNS Shield combines real AI, a DACH-optimized model and full data sovereignty: on-premises, compliant with the Swiss Data Protection Act (FADP), no CLOUD Act risk.
| Feature | DNS Shield | NextDNS | Cloudflare Gateway | Cisco Umbrella |
|---|---|---|---|---|
| Detection rate | >95% (validated) | Not published | Not published | Not published |
| DGA & botnet detection (without signatures) | check_circle | help | check_circle | check_circle |
| On-premises / no forced cloud | check_circle | cancel | cancel | cancel |
| FADP / GDPR / CLOUD-Act-free | check_circle | cancel | cancel | cancel |
| AI optimized for CH/DE domains | check_circle | cancel | cancel | cancel |
| REST API & SIEM integration | check_circle | check_circle | check_circle | check_circle |
| MONITOR mode (risk-free onboarding) | check_circle | cancel | help | check_circle |
| Per-client behavioral analysis | check_circle | cancel | partial | check_circle (paid add-on) |
| Explainable AI (verdict insights) | check_circle | cancel | cancel | cancel |
| Swiss Made & local support | check_circle | cancel | cancel | cancel |
| Pricing model | CHF 0.50–4.50 per entity / mo. |
USD 1.99–19.90/mo. (Business per 50 employees, US cloud) |
USD 7 / user / mo. (US data) |
Enterprise license (complex) |
help = limited or configuration-dependent. Sources: public vendor product information, as of August 2026.
Your company deserves proactive protection
91% of all malware uses DNS for C2 communication. DNS Shield closes this gap before an attack does any damage.
Prevent attacks, don't just detect them
Unlike reactive solutions, DNS Shield blocks threats preventively at the DNS level. Malware, ransomware and phishing are stopped before a network connection is ever established, the most effective first line of defense.
Deployment in minutes, without agents
DNS Shield requires no agents or hardware changes. Point your DNS resolver at DNS Shield, and your entire network is protected. MONITOR mode allows risk-free testing before going live.
Complete DNS visibility
See every DNS query in your company in real time. Identify shadow IT, unauthorized cloud services and suspicious communication patterns via the web dashboard with live query stream.
Employee and device protection
Protect all endpoints, servers and IoT devices centrally, without agents on every endpoint. Category filters for adult content, gambling and advertising additionally boost productivity.
DNS security for regulated industries
Swiss financial institutions, hospitals and industrial companies have special requirements for data sovereignty and compliance, DNS Shield is built for them.
Finance & Banking
FINMA-compliant network logging and incident response straight out of DNS Shield. Blocks phishing against e-banking customers, even for newly registered lookalike domains only hours old.
- checkFINMA-grade audit trail
- checkNRD protection against e-banking phishing
- checkNo US CLOUD Act access to customer queries
Healthcare
Hospitals and clinics are prime ransomware targets. DNS Shield blocks C2 communication and ransomware infrastructure before a single machine is encrypted, compliant with the Swiss Data Protection Act (FADP) and without cloud dependency.
- checkReal-time ransomware C2 blocking
- checkFADP-compliant for patient data
- checkNIS2 requirements met
Industry & SMB
Manufacturers and SMBs benefit from simple deployment without major IT effort. DNS Shield protects OT/IT networks alike, at SMB-friendly prices from CHF 0.50/entity.
- checkOT/IT network protection at the DNS level
- checkScalable from 1 entity
- checkNo dedicated security team required
MSSP & Managed Security
Manage multiple customer environments centrally from a single instance. Per-client tracking, separated log indexes, configurable policies per tenant and Azure AD/Entra SSO for operator access.
- checkMulti-tenant management from one admin interface
- checkPer-tenant policies, whitelists and reporting dashboards
- checkAzure AD / Entra ID SSO (OIDC) for operator teams
What DNS Shield blocks
DNS Shield detects and blocks the most important DNS-borne threats as well as unwanted content categories, each category is independently configurable per tenant (BLOCK / MONITOR / ALLOW).
Malware
Known malware distribution, drive-by downloads and malware hosts.
Phishing
Credential and data theft domains, including newly registered variants. Incl. homoglyph/IDN lookalikes and domains that have been online for less than 24 hours.
Command & Control
C2 infrastructure for botnets, RATs and implants is terminated.
DGA & Botnets
Domain generation algorithms are detected behaviorally, without signatures.
DNS Tunneling
Data exfiltration over the DNS protocol is detected through pattern analysis. Base64URL/Base32 payload detection and QTYPE distribution analysis (DNS TXT/NULL query dominance) complement the request pattern analysis for maximum tunneling coverage.
Cryptomining
Block unauthorized mining pools and protect your resources.
Adult Content
Compliance-grade content filtering by policy.
Ads & Tracking
Filter trackers and ad infrastructure network-wide.
Gambling
Gambling domains are blocked or monitored as a configurable category, for compliance requirements in education, healthcare and finance.
MONITOR mode for risk-free onboarding
Start in MONITOR mode, every block is only logged, traffic keeps flowing. This lets you test policies on your real traffic without any production risk. Switch to ACTIVE mode once your policies are dialed in, whitelist and blacklist can be adjusted at any time without downtime.
Runs where your data lives.
DNS Shield integrates seamlessly into existing networks, SIEM/SOAR workflows and enterprise toolchains, without forced cloud, without external data dependency.
DNS Resolver Architecture
DNS Shield fits seamlessly into existing networks, as a drop-in DNS resolver or as an additional protection layer in front of your current resolver:
- checkStandards-compliant DNS resolver support (UDP/TCP)
- checkFreely configurable upstream resolvers
- checkHigh availability with failover support
- checkMulti-site deployment for distributed locations
- checkRegex and wildcard DNS rules
Web Dashboard & Block Portal
A modern web UI for operators, and a customizable block portal for end users when a domain has been blocked:
- checkLive query stream with color classification
- checkFull rule engine with ALLOW/BLOCK/REDIRECT, regex and wildcard matching plus subnet-specific client overrides
- checkMulti-user authentication with roles
- checkCustom branding for the block portal
- checkAnalytics dashboard with real-time statistics
REST API & SIEM Forwarding
Integrate DNS Shield into your existing toolchain, or use it as an additional telemetry source for your SIEM:
- checkRESTful API for policy management and statistics
- checkSyslog forwarding (TCP / UDP) to SIEM
- checkLive statistics queryable via API
- checkCompatible with common SIEM and SOAR tools
- checkOpenSearch indexing for analytical log search and SIEM integration
OnPrem & Container
DNS Shield runs wherever you want, on your hardware, in your virtualization or as a container on your existing platform:
- checkBare-metal or VM (Linux)
- checkDocker / container deployment
- checkHybrid models for multi-site
- checkNo cloud dependency, no external telemetry
- checkIPv4 and IPv6 dual stack, full dual-stack resolution and WHOIS enrichment
Swiss DNS security: your data, your sovereignty.
DNS requests are highly sensitive, they reveal which services your employees use, which partners you work with, which cloud services you are evaluating. This telemetry does not belong in foreign cloud backends.
Swiss Made
Development, operations and support from Switzerland. No CLOUD Act, no US jurisdiction over your DNS data.
FADP / revDSG / GDPR
Compliant with the revised Swiss Data Protection Act (revDSG) and the EU GDPR, through data minimization by architecture.
NIS2 & FINMA-ready
Meets network logging and incident response requirements for regulated industries, with a complete audit trail.
No cloud lock-in
Full control over threat feeds, logs and configuration. DNS requests never leave your infrastructure.
DNS Shield price list
Fair, volume-based pricing. The more entities you protect, the lower the price per unit.
| Number of entities | Price in CHF |
|---|---|
| 1 – 100 | CHF 4.50 |
| 101 – 300 | CHF 4.00 |
| 301 – 500 | CHF 3.00 |
| 501 – 1,000 | CHF 2.00 |
| 1,001 – 2,000 | CHF 1.50 |
| 2,001 – 4,000 | CHF 0.80 |
| 4,001 – 8,000 | CHF 0.60 |
| 8,001 – 12,000 | CHF 0.50 |
Prices per entity / month, excl. VAT. Custom terms available from 12,000 entities on request.
What is DNS Shield?
DNS Shield is a Swiss DNS security solution that acts as an invisible protective wall between your network and the internet. Every DNS request is evaluated by a proprietary, multi-stage AI scoring pipeline, malicious domains, phishing sites and command-and-control servers are blocked before a connection is established.
DNS is the phone book of the internet, and at the same time one of the most underestimated attack vectors. Over 91% of all malware uses DNS for its C2 communication. DNS Shield closes this critical security gap and forms the foundation of every modern Zero Trust architecture.
Unlike simple DNS filters that only work with static lists, or cloud-based solutions under US jurisdiction, DNS Shield combines threat intelligence feeds with an in-house AI engine trained on more than 60,000 manually curated Swiss and German domains, for over 95% detection rate at a fraction of the false positives.
IRONATE DNS Shield runs exclusively in your own infrastructure (on-premises or container), is FADP, GDPR and NIS2 compliant and achieves a response time of under 10 milliseconds (p99) at high throughput.
Frequently asked questions about DNS Shield
What is DNS Shield and how does it work?expand_more
DNS Shield operates as a secure DNS resolver in your network. Every DNS request is evaluated by a proprietary, multi-stage AI scoring pipeline that combines threat intelligence, behavioral analysis and an AI model trained on more than 60,000 manually curated Swiss and German domains. Malicious domains are blocked before a connection is established. Over 95% detection rate, validated on more than 100,000 test samples.
What is the difference between DNS Shield and Pi-hole?expand_more
Pi-hole is an open-source DNS filter that works exclusively with static blacklists. Static lists only detect known threats and fail completely against DGA botnets, DNS tunneling and newly registered phishing domains created just hours ago. DNS Shield combines threat feeds with a proprietary AI engine (over 95% detection rate), detects unknown threats without signature lists, provides a complete audit trail and SIEM integration, and was specifically optimized for Swiss and German domains to minimize false positives.
Why not Cloudflare Gateway or Cisco Umbrella?expand_more
Cloud-based DNS security processes every DNS query of your company in the cloud of a US provider, including information about which services your employees use, which partners you work with and which technologies you are evaluating. US providers are subject to the US CLOUD Act regardless of server location; data-residency options often cover log storage only. For companies subject to the revised Swiss Data Protection Act (revDSG), the GDPR, FINMA guidelines or NIS2, this is a critical compliance problem. DNS Shield runs exclusively in your own infrastructure, not a single DNS query leaves your network.
Why is DNS security important for Zero Trust?expand_more
Over 91% of all malware uses DNS for command-and-control communication. Without DNS control, a compromised endpoint can communicate with external C2 servers even with microsegmentation in place. DNS Shield closes this critical gap in Zero Trust architectures and forms the first line of defense, ahead of firewall and EDR.
Does DNS Shield protect against DNS tunneling and DGA botnets?expand_more
Yes. DNS tunneling, hiding data exfiltration inside the DNS protocol, is detected and blocked by analyzing anomalous request patterns. DGA botnets (domain generation algorithms) are detected behaviorally, without requiring signature lists. Both attack vectors are detected even in previously unknown variants.
How low-risk is the rollout of DNS Shield?expand_more
DNS Shield offers a MONITOR mode: in this phase, blocks are only logged, traffic keeps flowing. This lets you test your policies on real traffic without any production risk. Once your policies are dialed in, you switch to ACTIVE mode. Whitelist and blacklist can be adjusted at any time without downtime. Deployment requires no agents or hardware changes, just a change of DNS resolver.
Does DNS Shield also detect newly registered domains (NRD)?expand_more
Yes. DNS Shield includes a built-in NRD detector (Newly Registered Domains). Freshly registered domains are a hallmark of phishing campaigns: attackers register short-lived domains, launch an attack and move on. DNS Shield automatically detects and scores NRDs with an elevated risk score. The NRD check can be enabled in the dashboard.
How does DNS Shield integrate with my SIEM/SOAR?expand_more
DNS Shield offers syslog forwarding (TCP & UDP) for all block and monitor verdicts as well as a RESTful API for policy management, statistics and configuration changes. Every verdict includes risk score and client context for full contextualization in the SIEM. The solution is seamlessly compatible with common SIEM and SOAR platforms.
Where can DNS Shield be operated?expand_more
DNS Shield is on-premises first: bare-metal or VM deployment on Linux, alternatively as a container (Docker). Hybrid deployments across multiple sites are possible. DNS requests never leave your infrastructure, no external telemetry, no cloud dependency.
Is DNS Shield FADP, GDPR and NIS2 compliant?expand_more
Yes. DNS Shield is developed and operated exclusively from Switzerland, without CLOUD Act access, without US jurisdiction. The on-premises architecture means no external data processing takes place. The platform is compliant with the revised Swiss Data Protection Act (revDSG), the EU GDPR as well as NIS2 and FINMA requirements for network logging and incident response.
Which company sizes is DNS Shield suitable for?expand_more
DNS Shield scales from small SMBs (from 1 entity, CHF 4.50/month) to enterprise environments with more than 12,000 entities. The system processes tens of thousands of DNS requests per second with a response time under 10 milliseconds. The volume-based pricing makes DNS Shield economically attractive for companies of all sizes.