CortexDNS is a cluster-native DNS security platform built on one purpose-built engine. Filtering, encrypted DNS, rate limiting and replicated failover are delivered in a single binary — measured at 20,000 queries per second with sub-millisecond latency.
Over 90% of malware uses DNS for command and control. Traditional firewalls can't see it. Your security stack has a massive blind spot, and attackers know it.
A single high-performance engine delivers filtering, encrypted DNS, rate limiting and replicated failover. Optional modules add authoritative DNS, observability and incident response without enlarging the attack surface.
A single purpose-built engine handles every query path: filtering, allowlists, regex matching, cache, rate limiting, encrypted DNS (DoT & DoH), and replicated failover. Measured at 20,000 queries per second per node with sub-millisecond average latency.
Network-wide ad blocking and threat filtering. Manage blocklists, allowlists, and client groups through a unified dashboard.
Deep visibility into DNS traffic patterns. Identify anomalies, track trends, and generate compliance reports.
Complete audit trail for compliance and forensics. Track every configuration change with user attribution and timestamps.
Isolate environments for different teams, departments, or customers. Role-based access control with granular permissions.
Every console action is also an API call. Automate zone changes, policy updates, intelligence sync, and audit export — wire CortexDNS into the rest of your platform without compromise.
Secure your DNS management with TOTP-based two-factor authentication. Protect admin accounts from unauthorized access.
Generate detailed compliance and audit reports for regulatory requirements. Export in multiple formats for stakeholders.
Activate the optional authority module to run CortexDNS as your primary authoritative DNS. Manage zones and records, automate DNSSEC, and migrate from legacy DNS servers — all through the same console.
New deployments are walked through a three-step wizard: welcome, intelligence configuration, and confirmation. Existing installs upgrade safely — the wizard auto-marks completed and never reappears.
Full DNSSEC key lifecycle management through an intuitive UI. Create, rotate, and manage cryptographic keys with ease.
Import DNS records from industry-standard zone files with drag-and-drop simplicity. Preview and validate every record before applying changes — no surprises in production.
Continuously updated domain classification, algorithmically generated domain (DGA) detection, and per-query risk scoring. Every query decision carries category and confidence — surfaced in the dashboard, Query Log and block page.
Stay informed with configurable alerts and notifications. Get notified via email or webhook when threats are detected.
Forward DNS logs to your SIEM platform for centralized security monitoring. Syslog and webhook formats supported.
Custom block pages with category information. Users see why a domain was blocked instead of a generic error.
Every resolved query is classified as SECURE, INSECURE or UNKNOWN and surfaced in the dashboard donut and Query Log chip column. Engine-side validation with trust-anchor configuration ships in the same release.
Every node serves both DNS and management traffic in parallel — no idle standby. Embedded consensus runs in-process for primary election and automatic failover; an upstream load balancer fronts the cluster with SSL offload or own-certificate modes.
A lean security-first core boots in minutes. Optional capabilities — DNS authority, observability, incident response, reporting — activate on demand without rebuilding.
Stay protected even when your internet connection drops. CortexDNS syncs threat intelligence locally for uninterrupted DNS security.
Latest features and improvements in CortexDNS
Install CortexDNS on-premises or use our cloud offering. Docker, Kubernetes, or bare metal supported.
$ docker compose up -d
Creating nizam ... done
Creating nizam-follower ... done
Creating cortexdns-api ... done
Creating cortexdns-console ... done
✓ CortexDNS ready — 20,000 QPS, sub-ms latency
Point your clients to CortexDNS. Connect to your existing DNS infrastructure or deploy our managed solution.
Set up blocklists, create zones, define client groups, and configure alerts based on your security requirements.
Watch your DNS traffic in real-time. Investigate incidents, tune policies, and generate reports.
Organizations across industries rely on CortexDNS to secure their DNS infrastructure.
Protect corporate networks from phishing, malware, and data exfiltration. Enforce acceptable use policies and gain visibility into shadow IT.
Learn moreMeet HIPAA compliance requirements with comprehensive audit logging. Protect patient data and medical devices from DNS-based threats.
Learn moreDefend against financial malware and fraudulent domains. Satisfy regulatory requirements with immutable audit trails.
Learn moreContent filtering for K-12 and higher education. Protect students while maintaining compliance with CIPA and other regulations.
Learn moreSecure OT/IT convergence with DNS-layer protection. Prevent lateral movement and protect industrial control systems.
Learn moreMulti-tenant architecture designed for service providers. Manage hundreds of customers from a single pane of glass.
Learn moreNo hidden fees. No query limits. Pay for the features you need.
For small teams and home labs
For growing businesses
For large organizations
Get in touch with our team to learn how CortexDNS can protect your network.
On-premises deployment available. Enterprise support included.