Protective DNS

UK

The PDNS was first launched in 2017 and protects against Domain Name System (DNS) misuse and cyber threats like malware. It has been freely available to organisations like central government, local authorities, and devolved administrations for several years. Organisations that can now sign up to PDNS for Schools are local authorities or eligible public sector networks from the devolved administrations of the UK that provide DNS to their schools and local authorities in England that provide DNS to their maintained schools.

It should be noted that when the UK PDNS service blocks an A or AAAA query it considers to be malicious, it returns the IP of the PDNS resolver used rather than the more traditional NXDOMAIN response. This means your on-prem DNS server can look for responses pointing at 25.25.25.25, 25.26.27.28, or 2a06:98c1:54::16:f838 to detect queries that PDNS blocked. TXT, NS, etc records blocked will be done using NXDOMAIN.

It should be noted that UK PDNS does not block MX, DPF, DMARC queries.