to save the Anti-Spyware
profile.
Alternatively, if you want to exempt only specific trusted domains rather than bypassing all DNS Security inspection, you can use the bypass action on domain EDLs (PAN-OS 12.2.2 and later). In the DNS Policies tab, you should see the existing EDL of type domain-list created under External Dynamic Lists. Set the Policy Action to bypass. This skips DNS Security inspection for matching domains without generating log entries, while maintaining inspection for all other traffic.