Security has become an essential part of the connectivity experience. Subscribers expect their internet providers to deliver a connection that is fast and reliable, but also secure and protected. For operators, this creates an important challenge: How do you add security without compromising the performance your subscribers expect, and that you have worked hard to optimize?
For years, PowerDNS has advocated for network-based security using threat intelligence and DNS filtering as an effective answer to this challenge. DNS is already part of virtually every online interaction, making it an ideal control point for security. DNS-based protection allows operators to identify and act on malicious destinations before a device establishes a connection. Known malware domains can be blocked. Phishing destinations can be filtered. Communication with botnet command-and-control infrastructure can be prevented.
And importantly, this protection doesn't depend on installing an agent on every endpoint. That matters because today's subscriber networks are no longer limited to laptops and smartphones. They include smart TVs, cameras, gaming consoles, smart speakers, home appliances and a growing number of IoT devices. Installing endpoint security software on all of them simply isn't practical. They do, however, use DNS. And DNS-based security is highly scalable, flexible and therefore cost-efficient.
But there is another challenge: Operators invest heavily in building highly available, low-latency networks. Adding a third-party security solution on top, even a DNS-based one, can introduce a security detour into an infrastructure that has been optimized for performance. Instead, security should be built directly into the DNS stack.
The PowerDNS team will be at Network X 2026 at VIECON in Vienna, Austria, from 13–15 October (Meeting Room MRA73) to discuss exactly this challenge.
At PowerDNS, built-in security means multiple layers of protection within one DNS stack. It starts with network-wide DNS filtering, providing a scalable first layer of protection across the subscriber base. Using threat intelligence and Response Policy Zones, operators can block, redirect or modify responses associated with malicious destinations such as malware, phishing and botnet infrastructure across their subscriber network.
However, not every subscriber has the same security needs. A family may want parental controls and content filtering. A home office user may primarily need malware and phishing protection. And different devices can have different requirements, too.
PowerDNS’ Protective DNS takes DNS filtering to the subscriber level, allowing operators to apply different filtering policies and integrate threat intelligence and content categorization. PowerDNS Protect for Families, for example, supports filtering based on content categories. This turns DNS security from a network feature into a personalized subscriber service.
Finally, DNS-based security can help protect millions of subscribers and connected devices. But who makes sure the DNS infrastructure itself remains resilient against malicious traffic and attacks?
That's why our security approach also includes a powerful, dynamic security layer built into the DNS infrastructure. It defends against threats including DNS tunneling, data exfiltration, pseudo-random subdomain attacks and reflection/amplification attacks. By detecting and mitigating sophisticated DNS-based attacks, it helps keep the underlying infrastructure secure and resilient.
So, performance or security shouldn't be a choice operators have to make. They are not opposing goals. The objective should be a fast, secure internet experience for subscribers, and built-in DNS-based security can help operators deliver exactly that. Meet the PowerDNS team at Network X 2026 and let's continue the conversation in Meeting Room MRA73.
See you in Vienna!