Safely connect users and IoT devices to the internet with a cloud-based DNS firewall that proactively blocks malware, ransomware, phishing, and low-throughput DNS data exfiltration. Secure Internet Access Enterprise reduces security complexity — no appliances to deploy or manage — and offers fast, intuitive policy control for on- and off-network users and devices.
Add a proactive DNS firewall layer that deploys globally in minutes via a simple DNS configuration change.
Rapid deployment, no hardware to manage
Zero user friction, minimal latency
Blocks threats earlier and offloads endpoints
Detects DNS-only threats (e.g., botnets, DNS data exfiltration)
Shadow IT discovery and control across ports and protocols
Secure direct-to-internet branch traffic
Protect SD‑WAN/DIA branches without replicating a data center stack at each site.
Lower cost and complexity versus on-prem stacks
Quick, simple SD‑WAN integration — often in minutes
Low-latency security via optimal resolver routing
High reliability with globally distributed resolvers on Akamai Connected Cloud
Data center/IaaS visibility and protection
Control and monitor outbound DNS from workloads that access external resources.
Improved security and compliance
OS-agnostic, fast deployment
100% visibility and logging for external DNS requests
Real-time blocking of malicious domains and websites
Granular control over outbound DNS
Proactively control guest Wi‑Fi content
Enforce acceptable use policies to protect brand reputation and user experience.
Reduce reputational risk with category-based content controls
Optimize bandwidth by blocking streaming/media categories
Simplify operations and improve DNS resilience
IoT protection and agentless policy enforcement
Secure Internet Access Enterprise protects IoT and other headless devices by enforcing policy at the network layer — no agent required on each device. You can onboard device traffic via:
DNS server IP changes at the network level
A DNS proxy virtual machine
IPsec tunnels from your network edges
SD‑WAN integrations to steer DNS to Akamai resolvers
These on-ramps apply consistent DNS security and acceptable use policies to large fleets of IoT devices where agents are impractical.
SD‑WAN alignment and zero trust policy enforcement
Rapid SD‑WAN integrations: steer branch DNS to Akamai in minutes to secure DIA traffic at scale.
Identity-aware, granular policies: apply different controls by user, group, site, or subnet.
Selective inspection: enforce DNS-only controls by default, and proxy risky web traffic for additional protection when needed.
Distributed workforce protection: block DNS-based threats and detect low-throughput data exfiltration for remote and on-site users alike.
FAQs
How is the threat intelligence created?
It is built from Akamai Connected Cloud telemetry (up to 30% of global web traffic and up to 11 trillion recursive DNS queries daily), enriched with data from other Akamai security services and hundreds of external feeds. Advanced analytics, ML, and human researchers continuously curate malicious domains and URLs in real time.
How often are threat lists updated?
Approximately every 60 minutes, with new domains added and benign ones removed.
Can I create different policies for regions or business units?
Yes. Build policies by locations, business units, and network subnets.
How do I onboard DNS traffic?
Options include a DNS resolver IP change, Akamai’s DNS proxy VM, IPsec tunnels, lightweight clients, and SD‑WAN device integrations. Use any combination to match your use cases.
Can this run alongside my firewall or secure web gateway?
Yes. It adds a proactive DNS enforcement layer that many network firewalls and SWGs don’t cover, including blocking DNS data exfiltration.
Is this a DNS nameserver?
It is a recursive DNS resolver. It caches recent lookups for performance and forwards requests to authoritative nameservers as needed.
How is the DNS infrastructure protected from DDoS?
Akamai deploys Prolexic for DDoS mitigation, WAAP protections, and rate limiting/load balancing to keep resolvers available under attack.
Get started
See it in action with a free 60‑day DNS firewall trial. You’ll:
Improve your security posture without impacting performance.
Configure and manage policies in Akamai Control Center or via API.
Discover hidden threats in your DNS traffic (e.g., data exfiltration, botnets).
Gain insights to accelerate SecOps and threat hunting.
Trial setup steps:
1) Submit the form 2) Confirm your email 3) Pass Akamai validation and vetting 4) Receive login instructions 5) Log in and configure your instance