New Features in August 2026
Focus
Focus
Advanced DNS Security Powered by Precision AI®

New Features in August 2026

Table of Contents

New Features in August 2026

Review the new features and platform changes for Advanced DNS Security in August 2026.

Remote Access Domain Support for Advanced DNS Security Resolver

August 27, 2026
The DNS Security Resolver now provides access to a new domain category for content-based DNS signature sources: remote-access. Remote access tool websites — used to download software like TeamViewer, AnyDesk, and LogMeIn — are frequent targets for cyberattacks that exploit authorized remote connections to infiltrate enterprise networks. You can now apply a discrete policy action for the remote-access domain category, allowing you to block access to sites that provide tools or information to facilitate remote access to private computers and attached networks.

New Service Regions for Advanced DNS Security Resolver

August 27, 2026
Advanced DNS Security Resolver now provides Point of Presence (PoP) service regions in Spain, Italy, and Switzerland to reduce DNS resolution latency based on client location. These new regional endpoints expand the existing Advanced DNS Security Resolver network, processing DNS queries locally to deliver faster, more efficient resolution for regional traffic.
Connected clients automatically discover and route traffic to the closest optimal regional endpoint without requiring manual configuration. Your tenant data region, selected during Strata Cloud Manager activation, determines where logs and data are stored.

Advanced DNS Security Support for Amazon Route 53

August 2026
You can now enforce Palo Alto Networks® Advanced DNS Security threat protections directly on the Amazon Route 53 Resolver DNS Firewall, eliminating the need to deploy separate firewalls per VPC or reconfigure VPC settings to redirect DNS query traffic for inspection. This integration delivers 30+ DNS threat detections—including command-and-control, domain generation algorithms (DGA), DNS tunneling, fast flux, and newly registered domains—through the high-availability infrastructure of Route 53 DNS Firewall.
You subscribe to Advanced DNS Security directly from the Route 53 DNS Firewall console through AWS Marketplace. After subscribing, you create DNS Firewall rules by selecting one or more Palo Alto Networks DNS security categories and specifying an action to block or alert on matching queries. You assign each rule a priority to control evaluation order, then add the rules to a rule group that you can share and associate with one or more VPCs and accounts in your organization using AWS Resource Access Manager (RAM). You can also distribute subscriptions across multiple accounts using AWS License Manager.
The integration uses a fail-open architecture to maintain DNS resolution availability—if a threat verdict is delayed, DNS queries continue without disruption. You can combine Palo Alto Networks DNS security rules with AWS Managed Domain Lists in the same rule group for layered protection. The feature covers both VPC DNS query traffic and hybrid-cloud traffic forwarded through Route 53 Resolver Endpoints or Route 53 Global Resolver, giving you unified DNS threat protection across AWS and on-premises environments from the Advanced DNS Security subscription.

DNS Security Threat Insights Dashboard

August 2026
The DNS Security Operator Dashboard (InsightsSecurityDNS Security) is a subscription-specific dashboard that provides a central view of DNS threat activity with immediate, actionable insights. Widgets surface critical efficacy metrics—such as top malicious domains, C2 domain traffic, and users and devices accessing malicious domains—offering a clear starting point for drill-down analysis. Using contextual data on users, devices, and policies, security teams can identify and resolve DNS-based threats faster than ever before.
The dashboard covers the following investigative and operational use cases:
  • Detect covert channels—Identify threats that encode C2 commands directly into DNS queries to bypass standard firewalls, and expose anomalous traffic patterns that signal active attacker communication.
  • Confirm compromise—Cross-reference high-volume malicious DNS traffic with specific users to confirm that a compromised host is communicating with attacker infrastructure.
  • Stop data exfiltration—Block C2 domains and identify DNS hijacking attempts in real-time, neutralizing the threat's ability to receive instructions or exfiltrate data.
  • Demonstrate ROI—Provide high-level summaries of blocked malicious traffic to demonstrate the value of your DNS security investment to leadership.
This dashboard requires Strata Cloud Manager, Strata Logging Service (SLS), and a DNS Security or Advanced DNS Security subscription.