Service · Cloud DNS · Add-on to Sign In Enterprise

Choose what your network
is allowed to resolve.

Cloud DNS turns a Sign In Enterprise network into a managed, filtering resolver. Block the domains you don't want, always allow the ones you do, and shape it with rulesets you apply to the whole network or a single site, on a schedule. Delivered through your Service Gateway, with nothing to run on site.

Filtering Blocklists and allowlists
Policy Rulesets, global or per site
Timing Weekly schedules, your timezone
Delivery Add-on to Sign In Enterprise, via Service Gateway
resolver · guest-wifi live
Ruleset: Student Wi-Fi Applies to 3 sites Mon–Fri 08:00–17:00
payments.klarna.com resolved allowlist
doubleclick.net blocked Ads & trackers
tiktok.com blocked Schedule 08:00–17:00
login.microsoft.com resolved not listed
account-verify.example blocked Phishing list
Effective list · 84,213 domains Download
At a glance

A resolver you run policy on, not one you run.

0
Resolvers to run
Managed and deployed for you
0
Agents on devices
Filtering happens at the resolver
1
Add-on to Sign In
Enterprise tier, via Service Gateway
24/7
Lists kept current
Subscribed blocklists refresh on their own
The idea

Plain DNS forwards everything.
Cloud DNS decides.

Every network on Sign In Enterprise already sends its DNS somewhere. Cloud DNS replaces that plain forwarding with a resolver you control. Instead of every lookup passing straight through, each one is checked against the policy you set. Is this domain on a list you block? Is it one you always allow? Does a ruleset cover this part of the network, at this time of day? Then it resolves, or it does not.

You compose that policy from a few simple parts: blocklists you subscribe to, blocklists you build yourself, and allowlists that always take precedence. Rulesets tie them together and decide who they apply to and when.

A blocklist is just a list of domains, so it can carry any policy you can name, not only malware and adult content. Subscribe to a published list, write your own, or generate one with AI for exactly what you want off the network: the streaming and social domains that turn a parking or transit network into a hangout, say. The policy is yours to define.

The building block

A ruleset is a policy
you can read.

A ruleset takes the lists you chose, subtracts the domains you always allow, and lands on one clear result: the effective list, the exact set of domains this policy blocks. Add who it applies to and when, and the whole policy fits on a card.

No guesswork about what a rule really does. You can download the effective list a ruleset resolves to and see every domain in it.

Blocklists Ads & trackers · Security · Streaming
Allowlists Payments · Booking · Your services
Effective list 84,213 domains Download the exact list
Applies to 3 selected sites
Active Mon–Fri, 08:00–17:00 · Europe/Stockholm
The controls

What you control.

01

Subscribed blocklists

Point Cloud DNS at any published blocklist by its URL. The platform fetches it and keeps it refreshed, so a list you trust stays current without anyone re-uploading it.

02

Your own blocklists

Build named lists of the domains you want gone, by hand or by bulk import. A blocklist is just domains, so it can hold any policy you can name, not only security categories. Wildcards cover a domain and everything under it.

03

Allowlists that win

Some domains must always resolve: your payment provider, your booking system, your own services. Allowlisted domains override every blocklist.

04

Custom DNS records

Point an internal hostname straight at an IP. Handy for on-site services that never make it into public DNS.

05

Whole network or per site

Apply a ruleset across the entire network, or scope it to the sites you choose. One network, different policy where it needs to differ.

06

Weekly schedules

Give a ruleset a weekly schedule when you only want it active during certain hours, in your own timezone. Leave the schedule off and it applies around the clock.

Where it fits

Where it earns its place.

Safer browsing

Cut malware, phishing and ads at the source

A bad domain that never resolves can never load. Subscribe to security and tracker lists and every device on the network is covered, with nothing to install.

Purpose-built access

A network that does its job, and nothing else

Free Wi-Fi at a parking garage, a charging point or a transit stop should let people pay, verify with their bank app and be on their way, not become somewhere to stream and scroll all day. Allow the domains the network exists for; block the ones that turn it into a hangout.

Time-based policy

Different rules at different hours

Filter distractions during school or work hours and lift the policy after. One ruleset, a weekly schedule, no switch to flip by hand.

Per-site control

One network, local exceptions

Run a tighter policy at one site and a looser one at another from the same place, by scoping rulesets to the sites they belong to.

Straight about the edges

What Cloud DNS is, and is not.

DNS filtering is a sharp, low-cost layer. Knowing exactly where it stops is part of using it well.

How you turn it on

Three steps, on the network you already run.

01

Add it to Sign In Enterprise

Cloud DNS is an add-on to Sign In Enterprise, not a standalone product. It uses the same organizations, sites and roles you already manage.

02

Route DNS through your Service Gateway

Your Service Gateway points the network at Cloud DNS. Cisco router as Service Gateway and Cisco SD-WAN are both supported.

03

Set the policy, switch it on

Pick your lists, build a ruleset, choose where and when it applies, and turn the network from plain DNS to Cloud DNS. Changes take effect on the network as you make them.

Pairs with

DNS filtering · per network · scheduled

Put the DNS layer under your control.

Cloud DNS is an add-on to Sign In Enterprise, delivered through your Service Gateway. See it filtering a live network in a 30-minute demo.

Book a demoRead the docs