DNS Resolution
Table of Contents
DNS Resolution
DNS Resolution Control
| Prisma Browser Desktop | Prisma Browser Extension | Prisma Browser for Mobile |
|---|---|---|
| Full support | No support | No support |
The DNS Resolution control configures how Prisma Browser resolves DNS
queries. It supports encrypted resolution via DNS-over-HTTPS (DoH), real-time threat
protection, and domain exclusions.
When Palo Alto Networks Advanced DNS Security Resolver is selected, Prisma Browser routes all browser-initiated DNS queries through the Palo Alto
Networks Advanced DNS Resolver service using DoH. This provides encrypted resolution
and real-time threat protection at the DNS layer — blocking malicious domains before
the browser establishes any connection to the destination.
DNS Security operates independently of the device's local DNS configuration. On
unmanaged devices (BYOD, contractor laptops), this provides enterprise-grade DNS
protection without requiring endpoint agents or VPN connectivity.
Changes to DNS resolution settings may affect browsing
behavior and network connectivity. Modify only if you understand the impact on your
organization's DNS infrastructure.
- From Strata Cloud Manager, select ConfigurationPrisma BrowserRulesSelect the rule to configure.Navigate to Browser SecurityBrowser Security ControlsNetwork ProtectionDNS ResolutionSelect one of the following options:
- OS Default — Use the operating system's DNS resolver. No browser-level DNS policy is enforced and DNS queries are sent to the system-configured resolver.
- DNS-over-HTTPS — Enable encrypted DNS resolution. Select a DoH provider:
- Palo Alto Networks Advanced DNS Security Resolver — Route all browser-initiated DNS queries through the Palo Alto Networks Advanced DNS Resolver service. Provides encrypted resolution and real-time threat protection. Malicious domains are blocked at the DNS level before Prisma Browser connects to the destination.
- Custom Resolver — Specify a third-party DNS-over-HTTPS resolver URL. Enter the full HTTPS URL of the DoH resolver endpoint. This option provides encrypted DNS resolution without Palo Alto Networks threat protection.
If you selected DNS-over-HTTPS, configure the failure behavior from the Upon DNS-over-HTTPS resolve failure dropdown:- Fail-open: resolve using plain DNS — Prisma Browser reverts to the operating system's default DNS resolver to attempt resolution. Browsing continues without encrypted DNS or threat protection.
- Fail-close — Prisma Browser blocks DNS resolution entirely. No domains are resolved until the DoH connection is restored.
When fail-close is selected and the DNS service is unavailable, all browsing stops. To ensure critical domains remain accessible during outages, add them as Internal Domains in the ADNSR configuration or as Private Applications in Prisma Browser configuration. Domains added to these exclusion lists are not scanned by DNS Security and will not receive threat protection.(Optional) If you selected Palo Alto Networks Advanced DNS Security Resolver, enable Hosts file protection.- Disabled (default) — The operating system's default lookup order is used. The local hosts file is queried before the DNS resolver.
- Enabled — Prisma Browser detects and blocks all requests that resolve via the local hosts file, protecting against hosts file hijacking and redirection attacks (e.g., DNSChanger malware). Local device (localhost) addresses are allowlisted and unaffected.
This control applies only to Prisma Browser traffic. Other applications on the device are not affected. If the organization relies on hosts file entries for internal routing, do not enable this control or scope it appropriately.Click Set.
Why Use Palo Alto Networks Advanced DNS Security?DNS is the first step in every web connection — every page load, API call, and resource fetch begins with a DNS query. Palo Alto Networks Advanced DNS Security adds threat protection at this earliest point in the network kill chain, blocking threats before a connection is ever established.Key benefits:- Earliest-in-chain protection — Malicious domains are blocked at the DNS layer, before any TCP connection, TLS handshake, or content is loaded. This reduces attack surface and saves bandwidth by stopping threats at the first possible checkpoint.
- Threat categories blocked — Domain Generation Algorithms (DGA), DNS tunneling, command-and-control (C2) domains, newly registered domains (NRDs), and known phishing/malware domains.
- Device-independent security — Protection is enforced by the browser itself, regardless of the device's local DNS settings, endpoint agents, or network configuration. This is particularly valuable on unmanaged and BYOD devices where no other security stack is present.
- Complements existing protections — DNS Security operates alongside URL Filtering and Live Page Scanning, adding a distinct detection layer that inspects both DNS requests and responses. Some threat categories (DGA, DNS tunneling) are detected exclusively at the DNS layer.
- Powered by Palo Alto Networks threat intelligence — The Advanced DNS Resolver leverages machine learning models and threat telemetry from Palo Alto Networks' global customer base, providing continuously updated verdicts without requiring manual policy updates.
Chromium Built-in DNS ResolverThe Disable Chromium built-in DNS resolver checkbox controls whether the browser's built-in DNS client is active. When checked, the browser's built-in DNS client is disabled and the OS default DNS resolver is used instead.The Chromium built-in DNS resolver is required when DNS-over-HTTPS is enabled. It replaces the OS default DNS client (not the resolution service) to handle DoH queries. This setting is automatically enforced and cannot be disabled while a DoH provider is selected.When the OS Default mode is selected, this checkbox is available for manual control by the administrator.Private Application DNS ExclusionPrivate applications are excluded from Palo Alto Networks DNS resolution by default. DNS queries for private applications are resolved using the endpoint's system DNS resolver.Internal domains can be configured in either of the following locations:- Private Applications in Prisma Browser configuration.
- Internal Domains in the ADNSR configuration in Strata Cloud Manager.
Prisma Browser checks both lists before resolution. If a domain is found in either list, the browser bypasses DoH and resolves the request using the system DNS.Multi-Profile LimitationThe DNS Resolution configuration is global and shared between all browser profiles. When multiple profiles are active:- User attribution of DNS queries may not work as expected — all profiles appear as the same user in ADNS logs.
- Multiple tenants or mixed ADNS configurations on the same device may cause unexpected DNS resolution errors.
Interaction with Explicit ProxyWhen Explicit Proxy (EP) is configured for Prisma Browser, the proxy handles all DNS resolution. Palo Alto Networks Advanced DNS Security Resolver is not queried for proxy-routed traffic.DNS is the first step in every web connection — every page load, API call, and resource fetch begins with a DNS query. Palo Alto Networks Advanced DNS Security adds threat protection at this earliest point in the network kill chain, blocking threats before a connection is ever established.Palo Alto Networks DNS Security applies only to traffic not routed through the proxy:- DIRECT traffic — Domains not routed through the proxy.
- Proxy hostname resolution — The DNS lookup for the proxy server address itself.
Interaction with Prisma Access AgentWhen the Prisma Access Agent (PAA) is installed on the same device, all endpoint traffic is routed through the Prisma Access tunnel by default unless specifically configured otherwise in the PAA forwarding profile.This includes Prisma Browser's DoH traffic to the Advanced DNS Resolver. DNS Security protection remains active — the resolver destination is still ADNSR, only the network path traverses Prisma Access. Prisma Browser does not perform any special routing to bypass PAA.If Explicit Proxy is enabled on the Prisma Access Agent, EP takes precedence and handles DNS resolution directly. In this case, ADNSR is not queried by Prisma Browser.DNS Security EventsWhen Palo Alto Networks Advanced DNS Security Resolver is selected, the following events are generated:Event Type Location Details Web access events (DNS block) Prisma Browser admin console, Events tab Web Scan Engine column displays "Advanced DNS Resolver" Web access events (Hosts file block) Prisma Browser admin console, Events tab Web Scan Engine column displays "Hosts file protection" Block events Prisma Browser admin console, Events tab Indicates the domain was blocked by DNS Security with threat verdict DNS query logs Strata Cloud Manager Log Viewer > Network > DNS Security All ADNSR logs (PB and traditional) appear here. Filter by rule labeled "Prisma Browser" to view PB-specific entries Strata Logging Service (SLS) is required for all Prisma Browser deployments. For standalone Prisma Browser, SLS is provisioned automatically with the license. ADNSR includes SLS with 1-year log retention for resolver logs.User QuotaEach licensed user has a daily DNS request allocation included with their Prisma Browser Pro license. If your organization expects to exceed this allocation, contact your Palo Alto Networks account team to discuss options.Regional AvailabilityThe Palo Alto Networks Advanced DNS Resolver is available in 19 regions worldwide:Region Code Americas americas Europe (EU) eu United Kingdom uk Australia au Singapore sg Canada ca Japan jp Germany de India in France fr Poland pl China cn Israel il Indonesia id Taiwan tw Qatar qa South Korea kr Saudi Arabia sa South Africa za The resolver automatically selects the nearest optimal point of presence. No manual region configuration is required. Prisma Browser users in regions without a dedicated ADNSR PoP (e.g., Italy, Spain, Switzerland) are automatically routed to the nearest available region.