.
Why Use Palo Alto Networks Advanced DNS Security?
DNS is the first step in every web connection — every page load, API
call, and resource fetch begins with a DNS query. Palo Alto Networks
Advanced DNS Security adds threat protection at this earliest point in
the network kill chain, blocking threats before a connection is ever
established.
Key benefits:- Earliest-in-chain protection — Malicious domains are
blocked at the DNS layer, before any TCP connection, TLS
handshake, or content is loaded. This reduces attack surface and
saves bandwidth by stopping threats at the first possible
checkpoint.
- Threat categories blocked — Domain Generation Algorithms
(DGA), DNS tunneling, command-and-control (C2) domains, newly
registered domains (NRDs), and known phishing/malware
domains.
- Device-independent security — Protection is enforced by
the browser itself, regardless of the device's local DNS
settings, endpoint agents, or network configuration. This is
particularly valuable on unmanaged and BYOD devices where no
other security stack is present.
- Complements existing protections — DNS Security operates
alongside URL Filtering and Live Page Scanning, adding a
distinct detection layer that inspects both DNS requests and
responses. Some threat categories (DGA, DNS tunneling) are
detected exclusively at the DNS layer.
- Powered by Palo Alto Networks threat intelligence — The
Advanced DNS Resolver leverages machine learning models and
threat telemetry from Palo Alto Networks' global customer base,
providing continuously updated verdicts without requiring manual
policy updates.
Chromium Built-in DNS Resolver
The Disable Chromium built-in DNS resolver
checkbox controls whether the browser's built-in DNS client is active.
When checked, the browser's built-in DNS client is disabled and the OS
default DNS resolver is used instead.
The Chromium built-in DNS resolver is required when DNS-over-HTTPS is
enabled. It replaces the OS default DNS client (not the resolution
service) to handle DoH queries. This setting is automatically enforced
and cannot be disabled while a DoH provider is selected.
When the OS Default mode is selected, this checkbox is available for
manual control by the administrator.
Private Application DNS Exclusion
Private applications are excluded from Palo Alto Networks DNS resolution
by default. DNS queries for private applications are resolved using the
endpoint's system DNS resolver.
Internal domains can be configured in either of the following
locations:
- Private Applications in Prisma Browser
configuration.
- Internal Domains in the ADNSR configuration in Strata Cloud Manager.
Prisma Browser checks both lists before resolution. If a domain is
found in either list, the browser bypasses DoH and resolves the request
using the system DNS.
Multi-Profile Limitation
The DNS Resolution configuration is global and shared between all browser
profiles. When multiple profiles are active:
- User attribution of DNS queries may not work as expected — all
profiles appear as the same user in ADNS logs.
- Multiple tenants or mixed ADNS configurations on the same device may
cause unexpected DNS resolution errors.
Interaction with Explicit Proxy
When Explicit Proxy (EP) is configured for Prisma Browser, the proxy
handles all DNS resolution. Palo Alto Networks Advanced DNS Security
Resolver is not queried for proxy-routed traffic.
DNS is the first step in every web connection — every page load, API
call, and resource fetch begins with a DNS query. Palo Alto Networks
Advanced DNS Security adds threat protection at this earliest point in
the network kill chain, blocking threats before a connection is ever
established.
Palo Alto Networks DNS Security applies only to traffic not routed
through the proxy:
- DIRECT traffic — Domains not routed through the
proxy.
- Proxy hostname resolution — The DNS lookup for the proxy
server address itself.
Interaction with Prisma Access Agent
When the Prisma Access Agent (PAA) is installed on the same device, all
endpoint traffic is routed through the Prisma Access tunnel by default
unless specifically configured otherwise in the PAA forwarding
profile.
This includes Prisma Browser's DoH traffic to the Advanced DNS
Resolver. DNS Security protection remains active — the resolver
destination is still ADNSR, only the network path traverses Prisma
Access. Prisma Browser does not perform any special routing to
bypass PAA.
If Explicit Proxy is enabled on the Prisma Access Agent, EP takes
precedence and handles DNS resolution directly. In this case, ADNSR is
not queried by Prisma Browser.
DNS Security Events
When Palo Alto Networks Advanced DNS Security Resolver is selected, the
following events are generated:
| Event Type | Location | Details |
| Web access events (DNS block) | Prisma Browser admin console, Events tab | Web Scan Engine column displays "Advanced DNS
Resolver" |
| Web access events (Hosts file block) | Prisma Browser admin console, Events tab | Web Scan Engine column displays "Hosts file
protection" |
| Block events | Prisma Browser admin console, Events tab | Indicates the domain was blocked by DNS Security with
threat verdict |
| DNS query logs | Strata Cloud Manager Log Viewer > Network > DNS
Security | All ADNSR logs (PB and traditional) appear here.
Filter by rule labeled "Prisma Browser" to view
PB-specific entries |
Strata Logging Service (SLS) is required for all Prisma Browser
deployments. For standalone Prisma Browser, SLS is provisioned
automatically with the license. ADNSR includes SLS with 1-year log
retention for resolver logs.
User Quota
Each licensed user has a daily DNS request allocation included with their
Prisma Browser Pro license. If your organization expects to
exceed this allocation, contact your Palo Alto Networks account team to
discuss options.
Regional Availability
The Palo Alto Networks Advanced DNS Resolver is available in 19 regions
worldwide:
| Region | Code |
| Americas | americas |
| Europe (EU) | eu |
| United Kingdom | uk |
| Australia | au |
| Singapore | sg |
| Canada | ca |
| Japan | jp |
| Germany | de |
| India | in |
| France | fr |
| Poland | pl |
| China | cn |
| Israel | il |
| Indonesia | id |
| Taiwan | tw |
| Qatar | qa |
| South Korea | kr |
| Saudi Arabia | sa |
| South Africa | za |
The resolver automatically selects the nearest optimal point of presence.
No manual region configuration is required. Prisma Browser users in
regions without a dedicated ADNSR PoP (e.g., Italy, Spain, Switzerland)
are automatically routed to the nearest available region.