Sophos DNS Protection
Secure, high-performance DNS protection using AI-powered threat intelligence across all ports, protocols, and apps
Overview:
Sophos DNS Protection blocks malicious, risky, and unwanted domains across all ports, protocols, and applications at the time of DNS lookup using real-time AI-powered threat intelligence from Sophos X-Ops and SophosLabs. DNS functions as the internet's address book, making DNS lookups a critical security control point. Sophos DNS Protection intercepts at that point, stopping threats before users can access them.
The service provides protection for both networks and Windows endpoints ensuring consistent security whether users are on or off the corporate network. On Sophos Firewall it is included with the Xstream Protection licence and covers all managed and unmanaged devices behind the firewall. On Windows endpoints it is included with Sophos Workspace Protection and uses HTTPS encryption to protect DNS traffic privacy and integrity. Over 500 billion DNS requests have been processed since service launch in 2024.
- Blocks high-risk domains used in web attacks and phishing using real-time AI threat intelligence from SophosLabs.
- Deploys on Sophos Firewall (included with Xstream Protection) to protect all network devices including unmanaged endpoints.
- Windows endpoint deployment included with Sophos Workspace Protection at no extra charge.
- HTTPS encryption protects DNS traffic from spoofing, tampering, and cache poisoning attacks.
- Global DNS infrastructure with distributed points-of-presence for low latency worldwide.
- Real-time threat intelligence updates new malicious domains propagate to all servers instantly.
- Policy controls in Sophos Central for custom domain lists and blocking of unwanted categories.
- DNS lookup data feeds into Sophos Data Lake for XDR and MDR threat hunting.
AI-Powered Threat Intelligence
Sophos DNS Protection leverages continuous real-time threat intelligence from Sophos X-Ops and SophosLabs AI to identify and block malicious domains before they can be accessed. New threat intelligence propagates to all DNS Protection servers immediately all protected devices benefit from newly discovered threats without requiring device updates or policy changes.
- Real-time AI threat intelligence from SophosLabs blocks newly discovered malicious domains immediately.
- Phishing domains blocked before users can be redirected to credential harvesting sites.
- All managed and unmanaged devices receive instant protection from emerging threats.
- No device updates or policy changes required to benefit from new intelligence.
Protect All Network Devices
Sophos DNS Protection on Sophos Firewall provides DNS security for all devices on the network including unmanaged endpoints, IoT devices, and guest devices that lack security agents. It configures in minutes through the firewall management interface and is included with the Xstream Protection licence at no additional cost.
- Included with Xstream Protection licence for Sophos Firewall.
- Protects managed and unmanaged devices behind the firewall without agent deployment.
- Blocks domains used in phishing attacks before users can access them.
- Configures in minutes through the Sophos Firewall management interface.
- DNS lookup data integrates into Sophos Data Lake for XDR and MDR threat hunting.
Protect Windows Endpoints On and Off Network
Sophos DNS Protection for Windows endpoints ensures remote and hybrid workers receive the same DNS security whether connected to the corporate network or working remotely. It installs standalone or alongside Sophos Endpoint, and is included with Sophos Workspace Protection at no extra charge.
- Included with Sophos Workspace Protection no additional licence required.
- Installs standalone or alongside Sophos Endpoint for layered protection.
- HTTPS encryption protects DNS traffic privacy and integrity on untrusted networks.
- Policy controls in Sophos Central for custom domain lists and category blocking.
- Protection enforced regardless of whether the device is on or off the corporate network.
Global Infrastructure for Low Latency
Sophos DNS Protection operates a global network of cloud DNS servers to ensure high performance and minimal latency regardless of user location. Distributed points-of-presence across all operational regions maintain low response times for geographically distributed workforces, with high availability architecture ensuring continuous protection.
- Distributed points-of-presence across all operational regions.
- Over 500 billion DNS requests processed since service launch in 2024.
- Low latency maintained for geographically distributed workforces.
- High availability architecture ensures continuous protection with no single point of failure.
Deployment on Sophos Firewall
Sophos DNS Protection on Sophos Firewall is included with the Xstream Protection licence and activates through the Sophos Firewall management interface. Once enabled, all DNS queries from devices on the network including unmanaged and IoT devices are resolved through Sophos DNS Protection servers where AI threat intelligence is applied at lookup time.
- Included with Xstream Protection no separate licence or subscription required.
- Enabled through the Sophos Firewall management interface in minutes.
- Covers all devices on the network without agent deployment.
- DNS lookup data feeds into Sophos Data Lake for XDR and MDR investigation.
Deployment on Windows Endpoints
Sophos DNS Protection for Windows endpoints deploys as part of Sophos Workspace Protection. It can be installed standalone or alongside Sophos Endpoint, and is managed through Sophos Central alongside the rest of the Sophos portfolio. Policy controls allow administrators to define custom domain blocklists and configure category-based filtering per user group or device.
- Included with Sophos Workspace Protection subscription.
- Deploys via standard software distribution tools (Intune, SCCM, GPO).
- Managed through Sophos Central alongside all other Sophos products.
- Custom domain lists support organisation-specific requirements.
- HTTPS encryption for all DNS traffic prevents spoofing, tampering, and cache poisoning.
Sophos Central Management
Both deployment options are managed through Sophos Central, providing a unified view of DNS protection activity, policy configuration, and domain blocking across the entire organisation. Administrators can configure policies, review blocked domain reports, and adjust category filters without leaving the Sophos Central console.
XDR and MDR Integration
DNS lookup data from Sophos DNS Protection is ingested into the Sophos Data Lake, making it available for threat hunting in Sophos XDR and for Sophos MDR analysts investigating suspicious activity. DNS-based indicators of compromise such as connections to known C2 infrastructure or newly registered domains can be correlated with endpoint and network telemetry in a single investigation view.
Sophos DNS Protection Specifications:
Table 1. DNS Protection Deployment Options |
||
|---|---|---|
| Capability | Firewall Deployment | Windows Endpoint Deployment |
| Included with | Sophos Firewall Xstream Protection licence | Sophos Workspace Protection |
| Devices covered | All devices on network (managed and unmanaged) | Windows 10 and later endpoints |
| Agent required | No applied at firewall DNS resolver | Yes lightweight endpoint agent |
| HTTPS encryption | Via Sophos Firewall | Yes DNS over HTTPS on endpoint |
| Off-network protection | No firewall coverage only | Yes enforced on and off network |
| Sophos Central management | ||
| Data Lake integration | ||
| Table 2. Service Capabilities |
|---|
| Threat Intelligence |
| Real-time AI threat intelligence from Sophos X-Ops and SophosLabs. Continuous updates propagated to all DNS servers instantly. |
| Domain Blocking |
| Malicious domains, phishing sites, high-risk domains, and administrator-defined custom domain blocklists. Category-based filtering for unwanted content. |
| DNS Security |
| HTTPS encryption for endpoint DNS traffic. Protection against spoofing, tampering, and DNS cache poisoning attacks. |
| Infrastructure |
| Global cloud DNS infrastructure with distributed points-of-presence. High availability with no single point of failure. Over 500 billion DNS requests processed since launch in 2024. |
| XDR/MDR Integration |
| DNS lookup data ingested into Sophos Data Lake. Available for XDR threat hunting and MDR analyst investigation. |
| Table 3. System Requirements |
|---|
| Firewall Requirements |
| Sophos Firewall with active Xstream Protection licence. Managed through Sophos Central or local firewall console. |
| Endpoint Requirements |
| Windows 10 (version 1903 or later) and Windows 11. Sophos Workspace Protection subscription required. |
| Management |
| Sophos Central cloud management console. Policy configuration, custom domain lists, category filtering, and activity reporting. |
| Deployment Tools |
| Windows endpoint agent deploys via Microsoft Intune, SCCM, GPO, or manual installation. No infrastructure changes required. |
| Additional Cost |
| Firewall deployment: included with Xstream Protection. Endpoint deployment: included with Sophos Workspace Protection. No additional licence required for either deployment. |
Documentation:
Download the Sophos Workspace Protection Solution Brochure (PDF).
