to save the Anti-Spyware
profile.
Alternatively, if you want to exempt only specific trusted domains rather than bypassing all DNS Security inspection, you can use the bypass action on domain EDLs (PAN-OS 12.2.2 and later). In the DNS Policies tab, add a domain EDL under External Dynamic Lists and set the Policy Action to bypass. This skips DNS Security inspection for matching domains without generating log entries, while maintaining inspection for all other traffic.