Classic DNS filtering on roaming devices often depended on changing DNS settings. On networks the user doesn’t own—such as hotels, public Wi-Fi, or shared corporate environments—this could cause conflicts with other software and reduce reliability.
The new DNS Pre-Check capability modernizes protection by introducing a transparent DNS proxy that validates and filters queries locally before they leave the device. This eliminates the need to modify DNS settings, ensures filtering works across untrusted networks, and helps preserve connectivity wherever users connect.
To support this capability, the Windows Agent will include a Filtering & Connection Mode framework. Instead of the agent deciding behavior automatically, administrators can configure three dimensions directly from the Dashboard:
  • Connection Mode: Transparent Proxy or DNS Loopback (how queries are intercepted).
  • Filtering Mode: Classic DNS or DNS Pre-Check (how queries are evaluated).
  • Failover Mode: Fail Open or Fail Closed (what happens if filtering cannot be reached).
For ease of deployment, these are also available as presets:
  • Standard (Recommended): Balanced filtering and connectivity.
  • Strict (High Security): Always enforce filtering, blocking access if filtering is unavailable.
  • Custom (Advanced): Mix and match connection, filtering, and failover modes as needed.