Skip to main content
Nodes Unlimited
IT Managed Services

Bad domains never resolve. That is the whole idea.

Most malware never needs a clever exploit if it can look up a domain. We put a filtered DNS resolver in front of your network by default — Pi-hole, enrolled through our remote management under a Dome global policy — so phishing, malware, and known-bad destinations fail at lookup, before a browser, mailbox, or gadget ever connects.

What's included

Every line below is quoted to your environment. We scope it during the assessment.

Default-On Dome Policy

Filtered DNS is a global setting, not an optional add-on you forget to enable. New sites and endpoints inherit the Dome policy unless we deliberately carve out an exception.

Malware & Phishing Domain Blocking

Lookups for known-bad, newly registered, and phishing domains are refused at the resolver, so the payload never downloads and the fake login page never loads.

Advertising & Tracker Filtering

Ad and tracker domains that add nothing but delay and tracking are blocked at DNS, which usually makes browsing feel faster rather than slower.

Allow and Block Lists for Real Work

A vendor portal, line-of-business app, or marketing pixel that has to work gets an explicit allow. Everything else stays under the default deny-the-junk policy.

Encrypted Resolver Path

Devices are pointed at the protected resolver rather than at whatever DNS the ISP or a coffee-shop router hands out, so filtering still applies off-site when the endpoint is enrolled.

IoT and Guest Network Coverage

Printers, cameras, TVs, and guest Wi-Fi have no patch cadence worth trusting. They still have to resolve names — and that is where we stop them reaching command-and-control.

Query Visibility & Tuning

Blocked and allowed lookups are visible, so a 'the internet is broken' ticket becomes a specific domain we can allow, explain, or keep blocked with a reason.

RMM Enrollment, Not a Separate Appliance Hunt

The resolver is part of the same remote-management stack that already watches your fleet. You do not buy a second console or a box that only one person knows how to reboot.

Two decades in enterprise ITMCSE · MCP · AWS Certified Cloud Practitioner · Fortinet NSE1/NSE2The stack you already run7,000+ field cases closedInsured and licensed in Massachusetts

Common questions

Is this Cisco Umbrella?
No. Umbrella DNS Protection is our DNS-layer filtering — Pi-hole under a Dome global policy — not a Cisco product and not a Cisco partnership. It does the same job people mean when they ask for umbrella DNS: stop malicious and unwanted names from resolving, on by default.
Is it on by default, or do we have to remember to turn it on?
On by default. Dome is a global setting in the management stack, so new endpoints and sites inherit filtered DNS unless we document an exception. That is the point of putting it here instead of leaving DNS as whatever the ISP assigned.
Will this break a vendor site or a line-of-business app?
Sometimes a legitimate domain sits on a list that also catches junk. When that happens we add an explicit allow, confirm the app works, and keep the rest of the policy in place. You are not stuck choosing between 'filter everything' and 'filter nothing'.
Does filtered DNS replace antivirus or multi-factor authentication?
No. It is one control: names that should not resolve, do not. Endpoints, identity, email, and backups still matter. DNS filtering is the layer that stops a lot of drive-by junk before those other controls ever have to work.

Request an assessment

Tell us roughly what you run. We will come back within one business day to arrange a look at your environment.

Rough numbers are fine — the assessment is where we get precise.