Changelog

Follow up on the latest improvements and updates.

RSS

What's New
Unblock Request Management — Now Generally Available
– Admins can now manage user-submitted unblock requests directly from the dashboard. The new Unblock Requests page provides a full request queue with tools to Allow or Deny submissions, threat-category warnings on risky domains, an Investigate Mode row action for quick Query Log scoping, and CSV export of active and historical requests.
Redesigned Branding Experience for MSPs
– The Whitelabel settings page has been redesigned as a dedicated Branding page, with Logo, Favicon, Dashboard Name, and Subdomain URL now managed as individual, first-class branding objects. Net-new MSPs onboarded after September 15 configure a branded subdomain (yourdomain.dnsfilter.com) and are set up with current branding defaults without legacy Whitelabel configuration.
🛠️
Improvements
Local Domains Copy Clarification
– In-app copy in the Local Domains and Resolvers section now clearly notes that Local Domains and Resolvers only apply in Classic DNS Filtering Mode — Roaming Clients configured in Custom or PreCheck mode do not require local domain configuration.
Roaming Client Installer Access by Role
– Read-only and policy-only users now see the Roaming Client installer as disabled with a clear tooltip explaining that elevated permissions are required, rather than having full access to the installer download.
🪲
Bug Fixes
Dashboard Deployment Widgets Now Respond to Site Filter
– Resolved an issue where the Roaming Clients Protected and Relays widgets on organization-level dashboards did not update when filtering by Site.
MSP Custom Dashboard Filter Scope
– Resolved an issue where an organization filter applied on the MSP-level Custom Dashboard could carry over when navigating into an organization's dashboard, causing it to display filtered data rather than data scoped to that organization. Navigating to any organization dashboard now correctly scopes data to that organization.
Plus general performance and stability improvements across the dashboard.
A new version of the iOS Roaming Client is now available in the App Store and will begin rolling out to devices via Apple auto-updates today.
This release includes improvements to MDM configuration handling and device registration.
🛠️
Improvements
  • Root certificates in the MDM profile
    The
    .mobileconfig
    file now includes the DNSFilter root certificates alongside the iOS Roaming Client configuration, so a single profile push installs both. Download the current file from the iOS Roaming Client deployment guide
  • Reduced Background Sync
    Registered devices now sync with the DNSFilter dashboard only when device state changes, rather than every 60 seconds
🪲
Bug Fixes
  • Reinstalling no longer creates a duplicate record
    Reinstalling the iOS Roaming Client on a device now reuses that device's existing Roaming Client record instead of registering a new one. Records created before this release are not affected
  • DNS over TLS (DoT) setting from MDM
    A
    dns_over_tls_enabled
    value of
    false
    is now honored from first registration and persists across DNS extension restarts
  • Live search domain updates
    Changes to
    dhcp_dns_search_domains
    now take effect within one configuration refresh, with no DNS extension restart required
  • Last Logged in User on initial registration
    The value supplied in
    userName
    now populates the
    Last Logged in User
    field as soon as a device registers
What's New
DNSFilter MCP Server — Now Generally Available
– Connect an AI assistant to DNSFilter through the Model Context Protocol and work with your DNS data in natural language. A connected client can query DNS activity and threat data, manage policies and allow/block lists, and automate reports and investigations, without navigating the dashboard. Claude, ChatGPT, and Codex are all supported.
Find it under
Integrations → AI Connectors
. Open the DNSFilter MCP Server card, copy the server URL, and follow the MCP Server setup guide to connect your client. Setup is admin-only, and once connected, the assistant sees exactly what the connecting user's permissions allow, nothing more. A connected client stays authorized for seven days before prompting to reconnect.
Available on eligible plans. Check the setup guide for package eligibility.
🛠️
Improvements
  • Sites Grid Edit Streamlined
    – Inline column editing has been removed from the Sites grid. All edits are made through the row Actions menu, keeping the editing experience consistent and intentional.
  • CyberSight Top Applications Widget Clarification
    – A tooltip has been added to the Top Applications widget clarifying that usage time reflects only active foreground use, not background activity. This provides helpful context when comparing figures across CyberSight widgets.
  • CyberSight Agent Stability and Data Accuracy
    – Several fixes to the Windows CyberSight agent addressing long-running issues: activity from administrator-level processes is now correctly recorded instead of being silently dropped; timestamps are no longer corrupted by malformed NTP responses; enabling CyberSight no longer overwrites Chrome or Edge managed extension policies; activity events are now correctly finalized on service shutdown instead of misattributing the entire offline period as active time; and the file parser no longer holds locks that blocked file deletion and app updates.
🪲
Bug Fixes
  • Custom Dashboard Bookmarks Now Land on the Right Page
    – Resolved an issue where bookmarking a Custom Dashboard and logging in from that bookmark redirected to the Overview page instead. Custom Dashboard URLs now include the dashboard ID, making them fully bookmarkable as a login landing page.
  • Roaming Client Export Row Limit
    – Resolved an issue where exporting Roaming Clients from the MSP level was capped at 999 rows, even when the account had thousands of endpoints. Exports now include all records as expected.
  • Relay Row Selection
    – Resolved an issue where selecting any relay row crashed the Relays screen, replacing the grid with an error state. Row selection and bulk actions now work correctly.
  • Users Page Policy Inheritance Text
    – Resolved an issue where the Policy/Schedule and Block Page columns on the Users page always showed "Inherit from Roaming Client," even for users in a Collection with its own applied policy. The columns now correctly show "Inherit from Collection" when applicable.
  • Domain Report Long Policy Name Display
    – Resolved an issue where long policy names on the Domain Report's Categorization Summary and Policy Summary cards overflowed and became unreadable at standard screen widths. Policy names now truncate cleanly with an ellipsis.
Plus general performance and stability improvements across the dashboard.
What's New
Customizable Dashboards Now the Default Experience
– The legacy Overview page has been retired and Dashboards is now the default landing view for all users. Existing links and bookmarks to the Overview page redirect to Dashboards automatically.
🛠️
Improvements
Customizable Dashboard Filter Improvements
– The dashboard Filters drawer has been simplified and reorganized. Quick Filters and Advanced Filters have been merged into a single Filters experience, with filters now grouped by Source (Organizations, Sites, Roaming Clients/Relays, Users) and Traffic (Result). The time range control remains on the main dashboard view.
Live Status Indicators on Deployment Widgets
– Dashboard widgets showing current deployment counts — Roaming Clients Protected, Sites Protected, Relays, Users, and Collections — now display a pulsating green dot to indicate they reflect live data and are not affected by the dashboard time range filter. Hovering the dot shows a tooltip confirming this.
Top Level Domain Category Label
– Bare TLD entries (e.g. .ru, .xyz) in Allow/Block lists and the Query Log now display as "Top Level Domain" instead of "Uncategorized," making it easier to distinguish intentional TLD-level rules from genuinely uncategorized domains.
🪲
Bug Fixes
Top Domains Widget Search Now Searches All Traffic
– Resolved an issue where the search box on the Top Domains dashboard widget only filtered the domains already loaded on screen, returning "No results" for any domain outside the top 20 even when traffic existed. The search now queries all traffic in the selected time range.
Plus general performance and stability improvements across the dashboard.

new

Windows Roaming Client

RC Release Channels

08/26 August 26 – Windows Roaming Client v3.7.11 Production

Version 3.7.11 of the Windows Roaming Client is now available on the
Production channel
. The latest installer is available in the dashboard under
Deployments → Roaming Clients
.
What's New
SecureTransit — Digital Privacy, Enforced as Policy
DNSFilter's DNS-layer protection already follows users onto any network, but being covered is not the same as being private. On hotel Wi-Fi, in airport lounges, and on the home connections where hybrid work actually happens, the destinations a device reaches stay visible to whoever runs the network — and to the ad networks, location trackers, and data brokers collecting alongside. SecureTransit closes that gap by making privacy a policy the organization enforces, not a choice each user has to remember to switch on.
  • Encrypted in transit
    – Traffic is encrypted before it leaves the device, through a DNSFilter-managed secure gateway with a choice of WireGuard or IKEv2.
  • Trackers blocked at the source
    – Location trackers, mail trackers, data brokers, and ad networks are cut off on the path, before data leaves — on any network, including your own.
  • Set by policy
    – Admins choose
    Always On
    ,
    Manual
    , or
    Disabled
    , per organization or per device, from the same dashboard they already use for DNS filtering.
  • Nothing for users to install
    – Credentials and connections are managed server-side, so there is nothing for employees to set up or misconfigure.
  • Available as a per-device add-on
    – License only the devices that need it, with a 14-day free trial for existing customers.
DNSFilter One Agent Preview
The Windows agent replaces the right-click tray menu with a full DNSFilter One window, themed to match your system's light or dark mode.
  • Filtering
    – Protection state, filtering mode, and last sync, with an activity view showing blocked and allowed queries over the past hour.
  • SecureTransit
    – Connection status, the connected server on a map, region, protocol, session uptime, and data transferred, with Connect and Disconnect controls. Appears when SecureTransit is enabled.
  • Settings
    – Version, hostname, diagnostics, and logs in one place.
DNS PreCheck v2 — Filtering That Holds on Networks That Hijack DNS
Some networks don't leave DNS alone. Hotel Wi-Fi, captive portals, and ISPs that quietly intercept resolvers can redirect DNS traffic before it ever reaches DNSFilter — and on those networks, blocked domains could resolve anyway, with neither the admin nor the end user aware the gap existed. DNS PreCheck v2 detects that interference and keeps policy enforced regardless of what the local network does with DNS.
  • Rollout complete — now the default
    – Introduced in v3.6.10, PreCheck v2 has finished rolling out and is the default for all Windows Roaming Clients on 3.6 and later.
  • No action required
    – The transition was handled automatically. Nothing to enable, configure, or reinstall.
  • Confirm it's active
    – Devices display
    DNS PreCheck v2
    as the filtering mode in the system tray, and PreCheck v2 queries appear with the
    HTTP/2.0
    protocol in your DNS query log. See Manage Connection and Filtering Modes for details.
🪲
Bug Fixes
  • Block Page on IPv6 and Dual-Stack Networks
    – Resolved an issue where blocked domains did not return the block page on IPv6 and dual-stack networks. Requests for blocked domains were refused rather than resolved to the block page, so users saw a connection error instead of the block page.
🛠️
Improvements
Does Not Include Operator for Query Log Categories Filter
– The Categories filter in the Query Log now supports a Does Not Include operator, allowing admins to exclude specific categories from their view during investigations.
Customizable Dashboard Improvements
– Several usability updates to the dashboard experience: dashboards in the Manage Dashboards view now show Private or Shared visibility status and can be updated directly from the quick actions menu; dashboards are now clickable directly from the grid; and clicking the Total Requests widget now opens Insights with Allowed Requests already toggled on.
Relay Manager v0.2.2 – Default Config Path Updated
– The Relay Manager now defaults the config file installation to a shared system location for Windows deployments rather than the installing user's profile folder, preventing configuration loss when user profiles are removed and reducing manual setup steps in managed and multi-user environments.
Improved Trial Messaging
– The trial banner now reflects each customer's actual situation. Paid customers finishing their free trial days no longer see an interruption warning, customers with time remaining see a calm reminder, and customers in the final days of an unpaid trial see a clear, honest at-risk message. MSP trial accounts see equivalent messaging tailored to their experience.
🪲
Bug Fixes
Connection Mode Toggle Restored
– Resolved an issue where the Connection Mode toggle was no longer visible at the organization or MSP level. The toggle is now accessible as expected without requiring per-endpoint configuration.
Plus general performance and stability improvements across the dashboard.
What's New
DNS Query Log Filter Navigation Updates
– Query Log filters have been consolidated into a single top-level panel, bringing grid-level filters up to the top filter bar. All filters apply together with a single Apply button, so nothing runs until you're ready and there's no need to set filters across multiple places.
🛠️
Improvements
Customizable Dashboard Updates
– Several refinements to the dashboard experience: newly added widgets now land in the next available grid slot without overlapping or displacing existing ones; a persistent time range indicator now stays visible while scrolling or switching views; and the destructive "Reset to Default" option has been removed from the Dashboard Actions menu.
🪲
Bug Fixes
Site Dropdown Capped at 20 Entries
– Resolved an issue where the Site dropdown when editing a Roaming Client's assigned Site was limited to 20 results, making additional Sites unreachable for larger accounts. All Sites now appear in the dropdown.
Top Domains Widget Sort Order
– Resolved an issue where the Overview page's Top Domains widget displayed domains out of order, causing some high-traffic domains to be pushed off the visible list.
CyberSight Reports Returning No Data Across Midnight
– Resolved an issue where CyberSight reports covering a time window that spanned midnight — such as an overnight "last few hours" query — incorrectly returned empty results. These time windows now return data correctly.
Plus general performance and stability improvements across the dashboard.

new

Windows Roaming Client

RC Release Channels

Beta

08/17 August 17 – Windows Roaming Client v3.7.11 Beta

Version 3.7.11 of the Windows Roaming Client is now available on the
Beta channel
. To install, download the latest beta installer from the dashboard under
Deployments → Roaming Clients → Beta Channel
.
What's New
SecureTransit — Digital Privacy, Enforced as Policy
DNSFilter's DNS-layer protection already follows users onto any network, but being covered is not the same as being private. On hotel Wi-Fi, in airport lounges, and on the home connections where hybrid work actually happens, the destinations a device reaches stay visible to whoever runs the network — and to the ad networks, location trackers, and data brokers collecting alongside. SecureTransit closes that gap by making privacy a policy the organization enforces, not a choice each user has to remember to switch on.
  • Encrypted in transit
    – Traffic is encrypted before it leaves the device, through a DNSFilter-managed secure gateway with a choice of WireGuard or IKEv2.
  • Trackers blocked at the source
    – Location trackers, mail trackers, data brokers, and ad networks are cut off on the path, before data leaves — on any network, including your own.
  • Set by policy
    – Admins choose
    Always On
    ,
    Manual
    , or
    Disabled
    , per organization or per device, from the same dashboard they already use for DNS filtering.
  • Nothing for users to install
    – Credentials and connections are managed server-side, so there is nothing for employees to set up or misconfigure.
  • Available as a per-device add-on
    – License only the devices that need it, with a 14-day free trial for existing customers.
DNSFilter One Agent Preview
The Windows agent replaces the right-click tray menu with a full DNSFilter One window, themed to match your system's light or dark mode.
  • Filtering
    – Protection state, filtering mode, and last sync, with an activity view showing blocked and allowed queries over the past hour.
  • SecureTransit
    – Connection status, the connected server on a map, region, protocol, session uptime, and data transferred, with Connect and Disconnect controls. Appears when SecureTransit is enabled.
  • Settings
    – Version, hostname, diagnostics, and logs in one place.
🪲
Bug Fixes
  • Block Page on IPv6 and Dual-Stack Networks
    – Resolved an issue where blocked domains did not return the block page on IPv6 and dual-stack networks. Requests for blocked domains were refused rather than resolved to the block page, so users saw a connection error instead of the block page.
🛠️
Improvements
Policy Dropdown Organization Header
– The Policy/Schedule dropdown now groups your organization's own policies under an "Organization" header, with sections ordered Organization, Global, then Scheduled — making it easier to find the right policy when assigning across Sites, Roaming Clients, Relays, Subnets, Users, and Collections.
🪲
Bug Fixes
Blank User Fields in Query Log Exports
– Resolved an issue where DNS Query Log CSV exports were missing user attribution fields when a sub-organization inherited its PII setting from a parent MSP. Exports now correctly include this data.
Overuse Banner Incorrectly Shown During Trial
– Resolved an issue where new trial signups were seeing the license overuse banner before becoming paying customers. The banner now only appears for genuine overuse by existing customers.
AppAware Upsell Banner for Core Plan Users
– Resolved an issue where self-serve MSP sub-organizations on the Core plan were shown an upsell banner blocking AppAware reporting, despite AppAware being included in the Core plan. AppAware reporting now loads correctly regardless of plan.
Plus general performance and stability improvements across the dashboard.
Load More