System Architecture

How DNS Patrol protects organizations from DNS threats — secure resolution, traffic monitoring, and advanced threat detection.

01 End Device

End Device

Phone / Laptop sit amet consectetur. Malesuada ornare sed lectus sed morbi

02 Client Agent

Client Agent

Available for Android, iOS, and Windows. Automatically configures DNS resolver and provides optional DNS-over-HTTPS encryption. Protects users outside the organization network.

03 DNS Resolver

DNS Resolver

Built on Knot Resolver with high availability and DNSSEC support. Deploys using Anycast technology as on-premise or virtual appliance. Responds only to queries from authorized networks.

04 Threat Intel

Threat Intel

Combines commercial and public threat databases with Czech legislation-compliant domain blacklists. Regularly updated feeds from CSIRT.CZ and other sources for malicious domain detection.

05 Admin Portal

Admin Portal

Detailed traffic overview, security policy configuration, event logging and analysis. Display and filter DNS queries, manage connected device inventory.

Deployment Modes

Flexible deployment options to match your organization's security posture.

Blocking Mode

Detected malicious domains are blocked immediately, preventing access to threats in real time.

Audit Mode

Logging only with no interventions. Perfect for evaluating threats before enabling enforcement.

Custom Policies

Administrator-defined protection levels by threat type. Fine-tune blocking rules to your organization's needs.

System Integration

DNS Patrol connects to your existing security monitoring tools with alert and notification support.

CSIRT.CZ

National threat intelligence feed

Security Monitoring

SIEM and SOC integration

Alerts & Notifications

Real-time incident alerts

DNS Log Export

Analysis and long-term monitoring

Custom Blocklists

Organizational block/allow lists

Knot Resolver

High-performance DNS backbone