.
Why Use Palo Alto Networks Advanced DNS Security?
DNS is the first step in every web connection — every page load, API call,
and resource fetch begins with a DNS query. Palo Alto Networks Advanced DNS
Security adds threat protection at this earliest point in the network kill
chain, blocking threats before a connection is ever established.
Key benefits:- Earliest-in-chain protection — Malicious domains are blocked
at the DNS layer, before any TCP connection, TLS handshake, or
content is loaded. This reduces attack surface and saves bandwidth
by stopping threats at the first possible checkpoint.
- Threat categories blocked — Domain Generation Algorithms
(DGA), DNS tunneling, command-and-control (C2) domains, newly
registered domains (NRDs), and known phishing/malware domains.
- Device-independent security — Protection is enforced by the
browser itself, regardless of the device's local DNS settings,
endpoint agents, or network configuration. This is particularly
valuable on unmanaged and BYOD devices where no other security stack
is present.
- Complements existing protections — DNS Security operates
alongside URL Filtering and Live Page Scanning, adding a distinct
detection layer that inspects both DNS requests and responses. Some
threat categories (DGA, DNS tunneling) are detected exclusively at
the DNS layer.
- Powered by Palo Alto Networks threat intelligence — The
Advanced DNS Resolver leverages machine learning models and threat
telemetry from Palo Alto Networks' global customer base, providing
continuously updated verdicts without requiring manual policy
updates.
Chromium Built-in DNS Resolver
The Disable Chromium built-in DNS resolver checkbox
controls whether the browser's built-in DNS client is active. When checked,
the browser's built-in DNS client is disabled and the OS default DNS
resolver is used instead.
The Chromium built-in DNS resolver is required when DNS-over-HTTPS is
enabled. It replaces the OS default DNS client (not the resolution service)
to handle DoH queries. This setting is automatically enforced and cannot be
disabled while a DoH provider is selected.
When the OS Default mode is selected, this checkbox is available for manual
control by the administrator.
Private Application DNS Exclusion
Private applications are excluded from Palo Alto Networks DNS resolution by
default. DNS queries for private applications are resolved using the
endpoint's system DNS resolver.
Internal domains can be configured in either of the following locations:
- Private Applications in Prisma Browser configuration.
- Internal Domains in the ADNSR configuration in Strata Cloud Manager.
Prisma Browser checks both lists before resolution. If a domain is found
in either list, the browser bypasses DoH and resolves the request using the
system DNS.
Multi-Profile Limitation
The DNS Resolution configuration is global and shared between all browser
profiles. When multiple profiles are active:
- User attribution of DNS queries may not work as expected — all profiles
appear as the same user in ADNS logs.
- Multiple tenants or mixed ADNS configurations on the same device may
cause unexpected DNS resolution errors.
Interaction with Explicit Proxy
When Explicit Proxy (EP) is configured for Prisma Browser, the proxy
handles all DNS resolution. Palo Alto Networks Advanced DNS Security
Resolver is not queried for proxy-routed traffic.
DNS is the first step in every web connection — every page load, API call,
and resource fetch begins with a DNS query. Palo Alto Networks Advanced DNS
Security adds threat protection at this earliest point in the network kill
chain, blocking threats before a connection is ever established.
Palo Alto Networks DNS Security applies only to traffic not routed through
the proxy:
- DIRECT traffic — Domains not routed through the proxy.
- Proxy hostname resolution — The DNS lookup for the proxy
server address itself.
Interaction with Prisma Access Agent
When the Prisma Access Agent (PAA) is installed on the same device, all
endpoint traffic is routed through the Prisma Access tunnel by default
unless specifically configured otherwise in the PAA forwarding profile.
This includes Prisma Browser's DoH traffic to the Advanced DNS Resolver.
DNS Security protection remains active — the resolver destination is still
ADNSR, only the network path traverses Prisma Access. Prisma Browser
does not perform any special routing to bypass PAA.
If Explicit Proxy is enabled on the Prisma Access Agent, EP takes precedence
and handles DNS resolution directly. In this case, ADNSR is not queried by
Prisma Browser.
DNS Security Events
When Palo Alto Networks Advanced DNS Security Resolver is selected, the
following events are generated:
| Event Type | Location | Details |
| Web access events (DNS block) | Prisma Browser admin console, Events tab | Web Scan Engine column displays "Advanced DNS
Resolver" |
| Web access events (Hosts file block) | Prisma Browser admin console, Events tab | Web Scan Engine column displays "Hosts file
protection" |
| Block events | Prisma Browser admin console, Events tab | Indicates the domain was blocked by DNS Security with
threat verdict |
| DNS query logs | Strata Cloud Manager Log Viewer > Network > DNS
Security | All ADNSR logs (PB and traditional) appear here. Filter
by rule labeled "Prisma Browser" to view PB-specific
entries |
Strata Logging Service (SLS) is required for all Prisma Browser
deployments. For standalone Prisma Browser, SLS is provisioned
automatically with the license. ADNSR includes SLS with 1-year log retention
for resolver logs.
User Quota
Each licensed user has a daily DNS request allocation included with their Prisma Browser Pro license. If your organization expects to exceed this
allocation, contact your Palo Alto Networks account team to discuss options.
Regional Availability
The Palo Alto Networks Advanced DNS Resolver is available in 19 regions
worldwide:
| Region | Code |
| Americas | americas |
| Europe (EU) | eu |
| United Kingdom | uk |
| Australia | au |
| Singapore | sg |
| Canada | ca |
| Japan | jp |
| Germany | de |
| India | in |
| France | fr |
| Poland | pl |
| China | cn |
| Israel | il |
| Indonesia | id |
| Taiwan | tw |
| Qatar | qa |
| South Korea | kr |
| Saudi Arabia | sa |
| South Africa | za |
The resolver automatically selects the nearest optimal point of presence. No
manual region configuration is required. Prisma Browser users in regions
without a dedicated ADNSR PoP (e.g., Italy, Spain, Switzerland) are
automatically routed to the nearest available region.