Use Case

    Web Content Filtering
    & DNS

    Block malicious domains, enforce web usage policies, and filter content at the browser and endpoint levels, all powered by a custom DNS over HTTPS (DoH) infrastructure. No separate DNS tool required.

    The Challenge

    DNS for Today's Window of Work

    Modern workplaces require a filtering solution more fine-grained than conventional DNS-based products. Meanwhile, security teams want the bedrock protection for endpoints offered by traditional DNS filtering solutions. The Platform offers the best of both worlds, detailed in-browser protection and enhanced system-wide DNS.

    Browser
    In-browser content filtering
    DNS
    System-wide DNS protection
    DoH
    Encrypted DNS over HTTPS
    Anycast
    Nationwide low-latency network
    In-browser
    phishing, malware, and compliance filtering
    Newly-registered
    domains blocked by default
    Global → Tenant
    policy inheritance with local overrides
    Zero
    proxies, certificates, or VPN dependencies
    How Atakama solves this

    Three Steps From Click to Contained

    Phishing happens in the browser, so detection and response happen in the browser. No proxy, no certificate gymnastics.

    01

    Detect

    Catch lookalike domains, credential-harvesting forms, and OAuth abuse at page load, before any user input.

    02

    Block

    Stop the attempt in-session before credentials, files, or tokens leave the browser. No round-trip to a network appliance.

    03

    Log

    Every blocked event syncs to your SIEM and PSA with full context. Compliance-ready evidence by default.

    Architecture

    Two Layers of Protection

    The Platform delivers detailed in-browser protection and enhanced system-wide DNS, the best of both worlds.

    Layer 1, In-Browser Filtering
    Fine-grained content filtering at the browser level
    Threat
    Compliance
    ABW
    Links
    Files
    URL Path
    Layer 2, DNS Server Protection
    System-wide filtering for all apps, devices, and browsers
    Categories
    C2 Blocking
    IoT
    Mobile
    Anti-Spoof
    Capabilities

    In-Browser Filtering Features

    Fine-grained content filtering at the browser level, by threat category, compliance category, and individual URL path.

    Phishing, Malware, and Compliance Filtering

    Block known malicious domains, phishing kits, malware delivery, and category-based compliance violations in real time at the browser layer.

    Allow-Block-Warn with Approval Workflow

    Three-tier enforcement plus a client-managed unblock request flow, end users request approval, the client approves, the MSP stays out of the queue.

    Block Newly Registered Domains

    Automatically hold or block freshly registered domains commonly used in phishing campaigns before any user can land on them.

    Full Block and Warn Reporting

    Audit every block and warn decision with full user, URL, category, and policy context, ready for client reviews and compliance evidence.

    Global to Tenant Policy Inheritance

    Set baseline policies at the global MSP level, inherit down to each tenant, override per tenant or per group. Saves MSPs hours of repeat configuration.

    Split-Tunnel and VPN Support

    Works alongside split-tunnel configurations and existing VPN deployments, so filtering follows the user without re-architecting the network.

    What gets caught

    Real Phishing, Blocked in Real Time

    A sample of detections from MSP tenants.

    Blocked at the URL layer

    Microsoft 365 lookalike domain (login.micr0soft.support) reached via an email link.

    Blocked, first-time-login warning shown

    Reverse-proxy phishing site attempting to capture session cookies.

    Blocked at DNS

    Newly-registered domain in a malware C2 category resolved by an endpoint.

    Logged for review

    OAuth login event to a new app from a non-typical user.

    DNS Server

    DNS Server Features

    System-wide DNS protection for every browser, application, and device on the endpoint and network.

    Foundational block-by-category and block-all-malware-domains capabilities
    Block access to malicious websites for non-Atakama secured browsers on endpoints
    Block malware on endpoints from accessing command and control domains
    Control access to prohibited websites for Atakama and non-Atakama secured browsers
    Control internet access for applications on endpoints (e.g., Dropbox, Slack)
    Block IoT and other network devices from connecting to malicious and prohibited domains
    Protect against DNS cache poisoning (DNS spoofing)
    Protect against DNS tunneling attacks
    Control internet access for managed (MDM-enabled) iOS devices
    Control internet access for unmanaged and BYOD devices on corporate LAN or WiFi
    dns-server-overview
    Domains Blocked
    12,847
    +18% vs. last month
    Protected Devices
    1,204
    Endpoints + IoT
    DNS Uptime
    99.99%
    Multi-AZ AWS
    Blocked by Category
    Malware / C2
    34%
    Phishing
    28%
    Policy Violations
    22%
    IoT Blocks
    16%
    Infrastructure

    Why DNS over HTTPS

    DoH strengthens privacy and security by preventing eavesdropping and tampering with DNS queries. The Platform's custom DoH infrastructure delivers fast, stable, and reliable protection.

    DoH request flow
    User's Browser
    DNS query initiated
    01
    HTTPS Encryption
    Query encrypted end-to-end
    02
    Anycast Network
    Routed to nearest PoP
    03
    Policy Engine
    Filtered against threat + compliance rules
    04
    Safe Response
    Clean result returned to browser
    05
    Multi-AZ
    AWS Redundancy
    Anycast
    Global Routing

    Encrypted DNS Queries

    All DNS queries are encrypted over HTTPS, preventing ISPs, attackers, and anyone on the network from eavesdropping on or tampering with DNS traffic.

    Nationwide Anycast Network

    An extensive Anycast network routes traffic to the nearest server, minimizing latency, balancing load, enhancing availability, and mitigating DDoS attacks.

    AWS Multi-AZ Redundancy

    DNS servers are hosted on AWS across multiple redundant availability zones, providing enterprise-grade infrastructure and reliability.

    Why It Matters

    One Platform, Complete Filtering

    Stop managing separate DNS tools alongside your browser security. Atakama combines in-browser filtering with a robust DNS server infrastructure, powered by DoH and an extensive Anycast network, so you get granular browser-level control and system-wide endpoint protection from a single console.

    • In-browser filtering and system-wide DNS in one platform
    • No separate DNS tool or proxy to deploy and manage
    • Granular URL path-level policies, not just domain blocking
    • Protect every device, including endpoints, IoT, mobile, and BYOD
    • Allow-Block-Warn enforcement for flexible user controls
    • DoH infrastructure with Anycast for fast, reliable protection
    dns-filtering-dashboard
    Browser Policies
    Active
    Per group
    DNS Categories
    Enforced
    System-wide
    Devices Covered
    All
    Endpoints + IoT
    Filtering Layers Active
    Threat Category Blocking
    Active
    Compliance Category Filtering
    Active
    C2 and Tunneling Defense
    Active
    Trusted by Leading Partners

    Trusted by Security Leaders

    "It is a rare and special thing to find a company with a truly innovative and disruptive solution to urgent cybersecurity challenges in a vastly underserved segment."

    Ryan Weeks
    Ryan Weeks
    Executive CISO, Educator & Keynote Speaker

    "Protecting your business starts with a secure browser, safeguarding your data, your clients' trust, and your peace of mind."

    Eric Woodard
    Eric Woodard
    CEO, Protek Solutions
    CEO, Protek Solutions logo

    FAQ

    Common Questions About Web Filtering and DNS

    Ready for Complete DNS and Content Filtering?

    In-browser protection and system-wide DNS from a single platform. No extra tools required.