DNS, DHCP & IP Address Management appliances
For Microsoft DNS & DHCP servers
For open source DNS & DHCP servers
Cloud-based visualization of analytics across DDI architecture
Manage multi-vendor cloud DNS servers centrally
RIR Declaration Management and Automation
Automated network device configuration and management
Centralized visibility over all your clouds
A single source of truth for your network automation
Why DDI is an Obvious Starting Point
DNS Threat Intelligence for proactive defense
Intelligence Insights for Threat Detection and Investigation
Adaptive DNS security for service continuity and data protection
Improve Application Access Control to prevent spread of attacks
Protect users and block DNS-based malware activity
Carrier-grade DNS DDoS attack protection
Optimize application delivery performance from the edge
for Proactive Network Security
Visibility, analytics and micro segmentation for effective Zero Trust strategy
Enable work from anywhere by controlling access, security and data privacy
Simplify management and control costs across AWS, Azure and GCP environments
Policy enforcement, risk management, and automation for simplifying compliance
Risk-free migration to reduce DDI complexity and cost
Move risk-free to improve performance, security and costs
Automate management, unify control and strengthen security of connected devices
Protect your network against all DNS attacks, data exfiltration and ransomware
Enable zero touch operations for network management and security
Improve resiliency, deployment velocity and user experience for SD-WAN projects
Integrated DNS, DHCP, IPAM services to simplify, automate and secure your network.
Simplify design, deployment and management of critical DDI services for telcos
Optimize administration and security of critical DDI services for healthcare
Simplify and automate management of critical DDI services for finance
Simplify and automate management of critical DDI services for higher education
Simplify and automate management of critical DDI services for retail
Simplify Management and Automation for Network Operations Teams
Elevate SecOps Efficiency by Simplifying Threat Response
Enable DevOps practices to deliver consistent network operations.
Open architecture for DDI integration
Technology partnerships for network security & management ecosystems
Extend security perimeters and strengthen network defenses
Submit requests for temporary licenses
Submit access requests for EfficientIP knowledge platforms
Submit membership requests for EfficientIP Community
Strengthen your network security with insights from the Forrester 2025 Study on DNS Security.
Customer-centric DDI project delivery and training
Acquire the skills needed to manage EfficientIP SOLIDserverâ„¢
Identify vulnerabilities with an assessment of your DNS traffic
Test your protection against data breaches via DNS
Dedicated representation for your organization inside EfficientIP
Explore content which helps manage and automate your network and cloud operations
Read content which strengthens protection of your network, apps, users and data
Learn how to enhance your app delivery performance to improve resilience and UX
See all your assets in one place
This enterprise-grade cloud platform allows you to improve visibility, enhance operational efficiency, and optimize network performance effortlessly.
Who we are and what we do
Meet the team of leaders guiding our global growth
Technology partnerships for network security and management ecosystems
Make your cloud projects successful with insights from the 2025 EMA Hybrid Multi-cloud Report.
Discover the benefits of the SmartPartner global channel program
Become a part of the innovation
The latest updates, release information, and global events
These NIST DNS Security Insights from the webinar, featuring Scott Rose, Yaelle Harel, and Andreas Taudte, show why DNS is a vital control point that can help stop attacks before they happen.
September 3, 2026 | Written by: Yaëlle Harel | DNS Security
Summary
Tags
DNS SecurityDNS over TLSDNSSECDoHEnterprise Network SecurityObservabilitySecOpsZero Trust
The most important insights are to treat DNS as an active part of enterprise security, understand how it is currently used, apply protective controls, use DNS telemetry to inform policy, and validate the environment continuously.
NIST SP 800-81 provides guidance for securing and operating DNS services. Its latest revision moves beyond securing individual servers and looks at DNS as an enterprise service spanning authoritative DNS, recursive resolution, endpoint stub resolvers, telemetry, governance, and policy enforcement.
Scott Rose is a NIST computer scientist working on core internet technologies, a co-author of SP 800-81, and a contributor to NIST’s zero trust guidance. In EfficientIP’s webinar, he joined Andreas Taudte, Senior Technical Marketing Manager at EfficientIP, who added practical enterprise experience to Rose’s explanation of the guide.
Cloud computing and IPv6 deployment are increasing organizations’ reliance on DNS and named services. That reliance is especially visible in service-based and microservice architectures running on virtualized platforms, where IP addresses can be ephemeral and change frequently. Rose pointed to 5G and 6G mobile telecom architectures as one example: services are discovered by name rather than tied to fixed addresses.
Rose also noted that DNS already carries policy information, for example for email, while emerging work is exploring how security and other information about AI agents could be associated with DNS. This reinforces DNS’s role as a central lookup and discovery mechanism.
That also raises the security stakes. Compromising DNS can redirect users or alter information before protections such as HTTPS take effect. As Rose put it, “If you can subvert them at the DNS layer, you stop them before they even make the connection.”
Simplify & Secure Your Network
Our goal is to help companies face the challenges of modern infrastructures and digital transformation.
Protective DNS uses the DNS layer to monitor or block suspicious connections before they become larger incidents. Rose explained that enterprises can “take action using that DNS layer to prevent a lot of attacks before they get severe or propagate.”
Andreas added that DNS security also depends on access control, patching, logging, governance, and DNS hygiene—not only DNSSEC or encrypted DNS.
Rose said DNS plays two roles in zero trust: it is a data source and a policy enforcement point.
DNS activity can reveal unauthorized behavior and help refine security policy. It can also prevent connections, disrupt command and control, and help stop data exfiltration. Endpoint stub resolvers must be controlled as well, or they may bypass enterprise policy.
Rose’s first recommendation was discovery: “map, or find out how you’re actually using your DNS infrastructure today.”
Teams should identify authoritative and recursive services, endpoint stubs, cloud DNS, owners, resolution paths, controls, and logging. He called the DNS query stream “a vital data feed.”
Scott also stressed the need for buy-in and communication between DNS administration and cybersecurity teams, bringing DNS operations into the wider security program rather than treating DNS as an isolated infrastructure service.
Andreas made the recommendation practical: DNS resolution should be predictable. Teams should select a user, server, or cloud workload and trace a query from source to answer, identifying the resolvers and policies involved, what is logged, and who owns each part of the path. The exercise can also reveal protective DNS or DNSSEC capabilities that are already available but not configured. Comparing the findings with SP 800-81 provides the basis for a prioritized roadmap.
When the enterprise controls its DNS infrastructure and resolution path, DNS can provide valuable visibility even when application traffic is encrypted. As Rose put it, “You always look up a DNS name first.”
Query data can expose tunneling, data exfiltration, command-and-control activity, and affected assets. His warning was clear: “If you’re missing DNS data and telemetry, you’re missing real key insights into what’s going on in your infrastructure.”
Andreas recommended sharing this intelligence with other security tools.
DNSSEC protects the integrity and authenticity of DNS data through digital signatures. DoH, DoT, and DoQ protect the confidentiality of query-response traffic.
Enterprises may need both, but unmanaged encrypted DNS can reduce visibility or send internal queries to external resolvers. The goal is to improve privacy without losing necessary enterprise control.
Authoritative DNS, recursive DNS, and stub resolvers have different trust boundaries and attack surfaces. Separating them helps assign controls and ownership.
One team may manage authoritative zones and DNSSEC signing, while another handles validation, protective DNS, and traffic analysis. The guide’s role-based structure also helps administrators focus on the guidance most relevant to them.
Not every DNS security improvement requires an architectural overhaul. Organizations can immediately review administrator access, patching and monitoring, logging, audit trails, workflows, and DNS hygiene. These checks can be performed on the existing infrastructure and used to assess risk and set priorities. Where the current platform already supports automated DNSSEC, a pilot in a low-risk-zone can provide another practical starting point.
Longer term work begins where the DNS service itself must change, such as separating authoritative and recursive roles, establishing hybrid resolution across on-premises and cloud environments, or expanding enterprise controlled encrypted DNS and protective DNS coverage.
The objective is to strengthen current controls now while planning the architectural changes that require broader design and deployment work.
DNS security cannot be completed once and forgotten. Andreas recommended regular reviews of resolution paths, ownership, records, controls, and policies.
Rose connected this to zero trust: organizations should keep “reevaluating and making changes to the posture in response to things.” Continuous validation turns DNS security from a static deployment into an adaptive control.
Rose identified post-quantum cryptography as an emerging issue. Algorithms have not yet been defined for use with DNSSEC, and UDP message-size limits make post-quantum cryptography more difficult to deploy.
Future guidance may need to address post-quantum algorithms for DNSSEC and encrypted DNS transports as standards and deployments mature.
Rose closed with the webinar’s clearest takeaway: “Don’t forget about DNS.”
DNS can show what is happening across the organization, map data flows, and enforce policy before connections are established. As he explained, it can help enterprises “stop some attacks before they even happen.”
EfficientIP helps organizations apply SP 800-81 across DNS governance, architecture, protection, and observability:
Together, these capabilities help organizations strengthen existing controls, improve visibility, and continuously validate their DNS security posture.
Scott Rose is a NIST computer scientist focused on core internet technologies. He co-wrote SP 800-81 and contributed to NIST’s zero trust architecture work.
The Cybersecurity Framework supports enterprise-wide risk management. SP 800-81 provides DNS-specific guidance that helps infrastructure teams contribute to those broader outcomes.
DNS is both a security data source and a policy enforcement point. It can inform policy with query data and act before connections occur.
DNSSEC protects DNS data integrity and authenticity. Encrypted DNS protects the confidentiality of query-response traffic.
Hear directly from NIST SP 800-81 co-author Scott Rose and EfficientIP’s Andreas as they discuss protective DNS, zero trust, DNS telemetry, encrypted DNS, and practical implementation priorities.
Talk to an expert
Summarize
Networks
Explore content highlighting the value EfficientIP solutions bring to your network