DNS Firewall secures DNS resolution across Public Zone, Private Zone, HTTPDNS, and self-managed DNS—from public internet to private intranet, cloud to on-premises.
Features
Private Zone DNS Firewall
Private Zone DNS Firewall secures Private Zone. When a VPC application queries external domains through Private Zone, integrated threat intelligence identifies and blocks malicious domains—phishing, ransomware, and trojans—in real time.
Public Recursive DNS Firewall
Public Recursive DNS Firewall protects queries sent to Recursive Gateway and HTTPDNS. Once enabled, integrated threat intelligence identifies and blocks malicious domains—phishing, ransomware, and trojans—in real time.
Public Zone DNS Firewall
Alibaba Cloud DNS provides DDoS mitigation for Public Zone. Self-managed authoritative services can use an authoritative proxy for enhanced security, faster resolution, disaster recovery, and high availability.
Benefits
-
High-precision threat intelligence
The Private Zone DNS Firewall and Public Recursive DNS Firewall integrate 600,000+ threat intelligence entries across 60+ threat types—phishing, trojans, ransomware, and more—to block malicious access.
-
Visual protection analytics
The Private Zone DNS Firewall and Public Recursive DNS Firewall provide real-time visual analytics on malicious domain detection and blocking, including trends, flagged domains, and threat categories.
-
Unified, full-link protection
Combine the Private Zone DNS Firewall, Public Recursive DNS Firewall, and Public Zone DNS Firewall for end-to-end DNS query protection across internal and external networks with centralized management.
Scenarios
|
Component |
Application Scenario |
Scenario Description |
|
Private Zone DNS Firewall |
Internal endpoint security |
Blocks malicious domains at the DNS layer for corporate intranet devices, preventing risks from user errors like clicking phishing links. |
|
Unified protection for cloud VPCs and self-managed data centers |
For hybrid cloud or multi-data-center enterprises, the Alibaba Cloud Private Zone DNS Firewall covers cloud VPCs and on-premises environments with consistent security policies. |
|
|
Sensitive data protection |
Prevents data theft and leakage in high-security industries (finance, healthcare) by blocking access to malicious domains. |
|
|
Custom security policies |
Create custom mitigation policies and integrate third-party threat intelligence for industry-specific security needs. |
|
|
Public Recursive DNS Firewall |
Malicious domain name blocking |
Blocks malicious domain queries in real time, preventing access to phishing sites and malware distribution points. |
|
Internet access security |
Secures daily internet access for enterprises, reducing incidents from employee errors like clicking unknown links. |
|
|
Compliance support |
Helps enterprises meet network security compliance requirements and strengthen protection. |
|
|
Security enhancement for open source DNS |
Enterprises using open-source DNS can connect to the Alibaba Cloud Public Recursive DNS Firewall for malicious domain detection and blocking. |
|
|
Public Zone DNS Firewall |
Public DDoS attack mitigation |
Provides DDoS mitigation for domain names hosted on Public Zone. |
|
Security for self-managed DNS |
Protects self-managed DNS from DDoS attacks and accelerates resolution through an authoritative proxy. |
Billing
Billing for DNS Firewall varies by feature and usage. Billable features include the Private Zone DNS Firewall and Public Recursive DNS Firewall. Usage is metered by query count or number of protected VPCs/domain names. Pay-as-you-go and subscription billing are both supported. Product billing.
FAQ
Find answers in the DNS Security FAQ.