Start Date
July 7, 2026
Overview
Block Non-Trusted DNS Resolvers helps prevent users or malware from bypassing Infoblox Threat Defense on roaming and off-network devices.
When enabled, the Infoblox endpoint agent:
- Enforces DNS policy at the host before traffic leaves the device.
- Allows DNS queries only to trusted resolvers, including Infoblox Threat Defense Anycast, network-provided DNS, and customer-defined internal or fallback resolvers.
- Blocks other DNS traffic over UDP/TCP 53 and DNS over TLS (DoT) on TCP 853.
The feature is configured per endpoint group, enabling a controlled rollout. Enforcement is designed to lift when secure policy enforcement cannot be maintained or when the endpoint is in on-premises protection mode. This EAP is available for selected IBTD Cloud customers with Windows and macOS endpoints.
What's In It For Me?
- Reduce DNS bypass risk by blocking public or rogue resolvers.
- Extend Infoblox Threat Defense policy enforcement to roaming and off-network endpoints.
- Use trusted resolver controls across Infoblox Anycast, network-provided, internal, and fallback DNS.
- Roll out protection per endpoint group to pilot, validate, and expand safely.
- Preserve DNS availability by lifting restrictions when secure enforcement cannot be maintained.
Who Should Apply?
- Infoblox Threat Defense Cloud customers with Windows or macOS endpoints.
- Organizations with hybrid, remote, or roaming users.
- Security teams concerned about DNS bypass, shadow DNS, phishing, malware, or DNS-based attacks.
- Enterprises with strict compliance or data protection requirements and distributed endpoints.