Changelog

Follow up on the latest improvements and updates.

RSS

What's New
DNS Query Log Filter Navigation Updates
– Query Log filters have been consolidated into a single top-level panel, bringing grid-level filters up to the top filter bar. All filters apply together with a single Apply button, so nothing runs until you're ready and there's no need to set filters across multiple places.
🛠️
Improvements
Customizable Dashboard Updates
– Several refinements to the dashboard experience: newly added widgets now land in the next available grid slot without overlapping or displacing existing ones; a persistent time range indicator now stays visible while scrolling or switching views; and the destructive "Reset to Default" option has been removed from the Dashboard Actions menu.
🪲
Bug Fixes
Site Dropdown Capped at 20 Entries
– Resolved an issue where the Site dropdown when editing a Roaming Client's assigned Site was limited to 20 results, making additional Sites unreachable for larger accounts. All Sites now appear in the dropdown.
Top Domains Widget Sort Order
– Resolved an issue where the Overview page's Top Domains widget displayed domains out of order, causing some high-traffic domains to be pushed off the visible list.
CyberSight Reports Returning No Data Across Midnight
– Resolved an issue where CyberSight reports covering a time window that spanned midnight — such as an overnight "last few hours" query — incorrectly returned empty results. These time windows now return data correctly.
Plus general performance and stability improvements across the dashboard.
Version 3.7.11 of the Windows Roaming Client is now available on the
Beta channel
. To install, download the latest beta installer from the dashboard under
Deployments → Roaming Clients → Beta Channel
.
What's New
SecureTransit — Digital Privacy, Enforced as Policy
DNSFilter's DNS-layer protection already follows users onto any network, but being covered is not the same as being private. On hotel Wi-Fi, in airport lounges, and on the home connections where hybrid work actually happens, the destinations a device reaches stay visible to whoever runs the network — and to the ad networks, location trackers, and data brokers collecting alongside. SecureTransit closes that gap by making privacy a policy the organization enforces, not a choice each user has to remember to switch on.
  • Encrypted in transit
    – Traffic is encrypted before it leaves the device, through a DNSFilter-managed secure gateway with a choice of WireGuard or IKEv2.
  • Trackers blocked at the source
    – Location trackers, mail trackers, data brokers, and ad networks are cut off on the path, before data leaves — on any network, including your own.
  • Set by policy
    – Admins choose
    Always On
    ,
    Manual
    , or
    Disabled
    , per organization or per device, from the same dashboard they already use for DNS filtering.
  • Nothing for users to install
    – Credentials and connections are managed server-side, so there is nothing for employees to set up or misconfigure.
  • Available as a per-device add-on
    – License only the devices that need it, with a 14-day free trial for existing customers.
DNSFilter One Agent Preview
The Windows agent replaces the right-click tray menu with a full DNSFilter One window, themed to match your system's light or dark mode.
  • Filtering
    – Protection state, filtering mode, and last sync, with an activity view showing blocked and allowed queries over the past hour.
  • SecureTransit
    – Connection status, the connected server on a map, region, protocol, session uptime, and data transferred, with Connect and Disconnect controls. Appears when SecureTransit is enabled.
  • Settings
    – Version, hostname, diagnostics, and logs in one place.
🪲
Bug Fixes
  • Block Page on IPv6 and Dual-Stack Networks
    – Resolved an issue where blocked domains did not return the block page on IPv6 and dual-stack networks. Requests for blocked domains were refused rather than resolved to the block page, so users saw a connection error instead of the block page.
🛠️
Improvements
Policy Dropdown Organization Header
– The Policy/Schedule dropdown now groups your organization's own policies under an "Organization" header, with sections ordered Organization, Global, then Scheduled — making it easier to find the right policy when assigning across Sites, Roaming Clients, Relays, Subnets, Users, and Collections.
🪲
Bug Fixes
Blank User Fields in Query Log Exports
– Resolved an issue where DNS Query Log CSV exports were missing user attribution fields when a sub-organization inherited its PII setting from a parent MSP. Exports now correctly include this data.
Overuse Banner Incorrectly Shown During Trial
– Resolved an issue where new trial signups were seeing the license overuse banner before becoming paying customers. The banner now only appears for genuine overuse by existing customers.
AppAware Upsell Banner for Core Plan Users
– Resolved an issue where self-serve MSP sub-organizations on the Core plan were shown an upsell banner blocking AppAware reporting, despite AppAware being included in the Core plan. AppAware reporting now loads correctly regardless of plan.
Plus general performance and stability improvements across the dashboard.

new

Windows Roaming Client

RC Release Channels

08/10 August 10 – Windows Roaming Client v3.6.10

Version 3.6.10 of the Windows Roaming Client is now available on the
Production channel
. The latest installer is available in the dashboard under
Deployments → Roaming Clients
.
What's New
DNS PreCheck v2
– DNS PreCheck now maintains policy enforcement even on networks that hijack or redirect DNS traffic — closing a gap where certain network conditions could allow content through that should have been blocked. PreCheck v2 is being rolled out gradually and is not automatically enabled with this agent update. Once enabled, the tray will update to show "DNS PreCheck v2" to confirm the active mode.
Automatic Tray Process Recovery
– The system tray process now automatically restarts if it stops unexpectedly, keeping tray status and controls available without requiring a manual restart of the client or machine.
🛠️
Improvements
Network Adapter DNS Restoration on Service Stop
– The agent now correctly restores DNS settings on all network adapters when the service stops, including on machines with multiple adapters such as a VPN or virtual adapter alongside Wi-Fi.
DNS Filtering Recovery After Network Interruption
– The agent now reliably resumes filtering through PreCheck and Transparent Proxy modes after a network interruption or sleep/resume cycle without requiring a service restart.
Loopback Proxy Isolation in Transparent Proxy and PreCheck Modes
– The loopback proxy no longer starts when the client is running in Transparent Proxy or PreCheck mode, preventing the two filtering paths from conflicting.
🪲
Bug Fixes
Agent Stability on Wake from Sleep
– Resolved an issue where the agent could crash or enter repeated service restart cycles after waking from sleep, causing intermittent DNS resolution failures until the service recovered.
DNS Delay in Classic Filtering Mode
– Resolved an issue where the agent returned SERVFAIL instead of NXDOMAIN for non-existent records in Classic (Loopback) mode, causing browser retry behavior and extended DNS delays on page loads.
Tray Last Sync Timestamp
– Resolved an issue where the Last Sync timestamp in the system tray froze after agent startup and never updated, even while the device was online and actively filtering.
GlobalProtect VPN Compatibility
– Resolved a conflict between the Roaming Client and GlobalProtect VPN that could cause DNS resolution failures and in some cases an agent crash.
Dashboard Config Not Delivered When Browser Extension Field Is Null
– Resolved an issue where a null value for the browser extension setting in the API response caused the agent's configuration sync to fail on every cycle, preventing local domains and other dashboard settings from reaching the agent.

new

Mac Roaming Client

RC Release Channels

Beta

08/06 August 6 – macOS Roaming Client v2.4.5 Beta

Version 2.4.5 of the macOS Roaming Client is now available on the
Beta channel
. To install, download the latest beta installer from the dashboard under
Deployments → Roaming Clients → Beta Channel
.
⚠️
Minimum macOS Version Update
– Starting with v2.4.4, the macOS Roaming Client requires macOS 13 Ventura or later. macOS 12 Monterey is no longer supported.
🪲 Stability & Connectivity Fixes
  • Fixed a DNS failover issue introduced in the 2.4 series that could cause intermittent resolution failures. When a lookup fell back to a backup server or protocol, the retry could be rejected or dropped — most pronounced with secure DNS (DNS-over-TLS) as the primary protocol, where affected devices could see a large share of queries fail and, with fail-close enabled, lose connectivity until the agent recovered.
What's New
  • Investigate Mode in Query Log
    – A new one-click Investigate Mode lets admins scope the Query Log to a specific query's timestamp and deployment context, with ±5s, ±10s, and ±15s time windows for tracing activity around a specific event without manually rebuilding filters.
  • Policies Filter in Query Log
    – A new Policies filter lets admins scope the Query Log to traffic matching one or more active policies, making it faster to isolate policy-specific activity alongside existing filters.
  • Preview: Customizable Dashboards
    – The redesigned dashboard experience is now available to all customers to preview. Build and rearrange your own widget layout, apply dashboard-wide filters, save named views with personal defaults, and share views publicly or across an MSP's organizations. Enhancements coming soon.
🛠️
Improvements
  • Filtering Policy Conflict Validation
    – Conflict validation between Universal and Policy Allow/Block lists now consistently reflects the documented priority order, with clear messaging explaining where a domain already exists, which list takes precedence, and what will happen.
  • Error Messaging for Legacy Collections
    – Collections created before the November 2025 schema update that fail to load now display a clear error explaining the issue and guide admins to delete and recreate the collection to restore access.
  • MSP Client Admin Site Creation Setting Relocated
    – The "Client admins can create sites" toggle has moved from the Whitelabel page to MSP Settings for a more discoverable home. The setting itself is unchanged.
  • Splashtop Added to AppAware Remote Desktop Library
    – Splashtop is now available in the AppAware application library for policy and reporting.
🪲
Bug Fixes
  • Top Websites Widget Missing Domains
    – Resolved a sorting issue where high-traffic domains like ChatGPT could disappear from the Top Websites widget on longer date ranges. Top Websites now reflects total time consistently across all date ranges.
  • Current-Day Traffic Showing as Zero on Multi-Day Reports
    – Resolved a timezone mismatch that caused today's traffic to show as zero when viewing Last 7/30/60/90 day presets. These ranges now correctly include today's traffic.
Plus general performance and stability improvements across the dashboard.

new

Windows Roaming Client

RC Release Channels

Beta

07/29 July 29 – Windows Roaming Client v3.6.10 Beta

Version 3.6.10 of the Windows Roaming Client is now available on the
Beta channel
. To install, download the latest beta installer from the dashboard under
Deployments → Roaming Clients → Beta Channel
.
What's New
  • DNS PreCheck v2
    – DNS PreCheck now maintains policy enforcement even on networks that hijack or redirect DNS traffic — closing a gap where certain network conditions could allow content through that should have been blocked. PreCheck v2 is being rolled out gradually and is not automatically enabled with this agent update. Once enabled for your organization, the tray will update to show "DNS PreCheck v2" to confirm the active mode.
  • Automatic Tray Process Recovery
    – The system tray process now automatically restarts if it stops unexpectedly, keeping tray status and controls available without requiring a manual restart of the client or machine.
🛠️ Improvements
  • Network Adapter DNS Restoration on Service Stop
    – The agent now correctly restores DNS settings on all network adapters when the service stops, including on machines with multiple adapters such as a VPN or virtual adapter alongside Wi-Fi.
  • DNS Filtering Recovery After Network Interruption
    – The agent now reliably resumes filtering through PreCheck and Transparent Proxy modes after a network interruption or sleep/resume cycle without requiring a service restart.
  • Loopback Proxy Isolation in Transparent Proxy and PreCheck Modes
    – The loopback proxy no longer starts when the client is running in Transparent Proxy or PreCheck mode, preventing the two filtering paths from conflicting.
🪲
Bug Fixes
  • Agent Stability on Wake from Sleep
    – Resolved an issue where the agent could crash or enter repeated service restart cycles after waking from sleep, causing intermittent DNS resolution failures until the service recovered.
  • DNS Delay in Classic Filtering Mode
    – Resolved an issue where the agent returned SERVFAIL instead of NXDOMAIN for non-existent records in Classic (Loopback) mode, causing browser retry behavior and extended DNS delays on page loads.
  • Tray Last Sync Timestamp
    – Resolved an issue where the Last Sync timestamp in the system tray froze after agent startup and never updated, even while the device was online and actively filtering.
  • GlobalProtect VPN Compatibility
    – Resolved a conflict between the Roaming Client and GlobalProtect VPN that could cause DNS resolution failures and in some cases an agent crash.
  • Dashboard Config Not Delivered When Browser Extension Field Is Null
    – Resolved an issue where a null value for the browser extension setting in the API response caused the agent's configuration sync to fail on every cycle, preventing local domains and other dashboard settings from reaching the agent.
What's New
  • Sites Filter in AppAware Reporting
    – AppAware now includes a Sites filter alongside the existing Roaming Client filter, giving Core plan customers and mixed Core/Pro environments meaningful data scoped to their sites.
  • Brave SafeSearch Enforcement
    – Filtering Policies now support SafeSearch enforcement on Brave, joining Google, Bing, DuckDuckGo, Ecosia, and Yandex. Enable it from the Privacy tab of any policy.
🛠️
Improvements
  • Redesigned SafeSearch Policy Controls
    – The SafeSearch section of the policy editor has been redesigned for clarity. Enforcement toggles are no longer nested under Block all search engines, and a new Enforce All shortcut lets admins enable every SafeSearch engine at once.
  • DNS Query Log Usability Updates
    – Several improvements to the Query Log: admins can now filter by "Uncategorized" to find unclassified queries, legacy Blacklist/Whitelist terminology has been replaced with Block/Allow language throughout, and column view presets have been reorganized so related fields appear together with extraneous columns removed from views where they didn't belong.
  • MSP Overview Widgets Now Clickable
    – The Collections and Users widgets on the MSP Overview page now link directly to their respective management pages, cutting a navigation step.
  • Consistent Data Grid Action Icons
    – Action icons across data tables throughout the app — including CyberSight, Relays, Roaming Clients, Users, Collections, and Query Log — are now visually consistent in style, spacing, and alignment.
🪲
Bug Fixes
  • Insights Sorting When Grouped by Category
    – Resolved an issue where Insights Reporting results appeared in a randomized order when grouped by Category. Results now consistently sort by request count.
  • Data Export Access During MSP Trials
    – Resolved an issue where MSP trial accounts could not access Data Export. Trial accounts can now access and test the feature as expected.
  • Identity Connection Sync Status
    – Resolved an issue where the Edit Identity Connection page displayed a false "Syncing with Errors" status during a healthy, in-progress Entra sync.
  • Missing Browser Tab Titles
    – Resolved an issue where Identities pages and several Deployments pages displayed a generic or blank browser tab title instead of the correct page name.
Plus general performance and stability improvements across the dashboard.

new

Mac Roaming Client

RC Release Channels

Beta

07/22 July 22 – macOS Roaming Client v2.4.4 Beta

Version 2.4.4 of the macOS Roaming Client is now available on the
Beta channel
. To install, download the latest beta installer from the dashboard under
Deployments → Roaming Clients → Beta Channel
.
⚠️
Minimum macOS Version Update
– Starting with v2.4.4, the macOS Roaming Client requires macOS 13 Ventura or later. macOS 12 Monterey is no longer supported.
🛠️ Improvements
Live Local Domain and Resolver Sync
– Local domain and resolver configuration changes made in the dashboard now apply without requiring a daemon restart, keeping filtering current as your environment changes.
🪲 Stability & Connectivity Fixes
  • Fixed an issue where large DNS records (such as TXT, SPF, DKIM, and DNSSEC records) could not be resolved while the agent was active, as truncated UDP responses were not being retried over TCP
  • Fixed an issue where local domains defined in the configuration file lost their assigned resolvers, causing matching queries to fall through to public resolvers instead
  • Fixed an issue where the menu bar icon could become unresponsive, particularly when no network connection was available
We've released Relay Manager v0.2.1 with an improvement to the default installation path for binary deployments on Linux.
🛠️
Improvement
Improved Linux Binary Installation Path
– The default relay home directory has been updated to
/opt/dnsfilter/relay
for binary installations on Linux. This resolves an issue where the relay service could get stuck in a restart loop on certain enterprise Linux distributions due to system permission restrictions on the previous default location.
Load More