New Features in July 2026
Focus
Focus
Advanced DNS Security Powered by Precision AI®

New Features in July 2026

Table of Contents

New Features in July 2026

Review the new features and platform changes for Advanced DNS Security in July 2026.

SafeSearch Support for Advanced DNS Security Resolver

July 31, 2026
You can now enforce SafeSearch across major search engines directly through the Palo Alto Networks® Advanced DNS Security Resolver, eliminating the need to decrypt traffic or manually track dynamic SafeSearch IP addresses. When you enable SafeSearch on a DNS Security profile, the resolver automatically rewrites DNS queries for supported search engines to their SafeSearch-enforced domains, ensuring that explicit content is filtered regardless of client-side browser settings or device configuration.
You configure SafeSearch from the Safe Search tab in your DNS Security profile. Select the Safe Search checkbox to enforce safe search across Google, Bing, Brave, DuckDuckGo, and Yandex. For YouTube, you select a filtering level—Strict or Moderate—to control the degree of content restriction independently from general search engine enforcement. The resolver redirects DNS queries at the resolution stage (for example, rewriting google.com to forcesafesearch.google.com), so enforcement applies to all users on your network without requiring per-device or per-browser configuration.
SafeSearch enforcement respects your existing DNS Security profile policy order. Internal domains and custom domain groups take precedence over SafeSearch rewrites, giving you flexibility to exclude specific domains from enforcement. If you configure a category action to block or sinkhole the search-engines or streaming-media category, that action takes precedence over SafeSearch. The feature supports A and AAAA DNS record types and maintains the low-latency resolution performance of the Advanced DNS Security.

Activity Insights: Threats Dashboard Improvements

July 31, 2026
Quantifying the specific protective value of Palo Alto Networks Advanced Security subscriptions, including Advanced Threat Prevention, Advanced URL Filtering, Advanced WildFire, and Advanced DNS Security, often requires manual correlation across fragmented views. This lack of clear attribution makes it difficult to understand how specialized services protect against unique, emerging threats compared to standard signatures.
You can now utilize the Activity Insights: Threats dashboard in Strata Cloud Manager to visualize the precise impact of your security subscriptions. This interface introduces platform effects metrics, demonstrating how shared intelligence from the global customer base and cross-service correlations automatically block patient-zero attacks in your environment. Detailed visualizations allow you to track trends in advanced threats, distinguishing between known signature-based blocks and novel attacks detected by cloud-based machine learning features.
The dashboard now provides a Threat | CVE toggle, giving you visibility into CVE exploits detected by Advanced Threat Prevention alongside your existing threat activity views. The CVE view helps you identify which real-world CVE exploits are targeting your environment, whether they are being blocked or alerted, and how to prioritize remediation using severity and exploitability metrics such as CVSS scores, EPSS scores, and exploit status.
Additionally, the Threat Search page now supports both Threat ID and CVE search, allowing you to investigate specific threat signatures or CVE exploits directly from the dashboard workflow. You can search by Threat ID to examine detection patterns for a specific signature, or search by CVE identifier to view all related threat activity, CVSS and EPSS metrics, and firewall coverage for that vulnerability.
By differentiating these protection sources and correlating CVE exploit data with your network activity, you can validate the specific return on investment of your subscriptions and gain deeper visibility into the sophisticated threat vectors targeting your network.

Improved DNS UDP Session Handling for Advanced DNS Security

July 30, 2026
You can now prevent dropped DNS resolution caused by the firewall discarding UDP sessions after a sinkhole or block action. When enabled, the No DNS UDP Discard setting keeps DNS UDP sessions active after a query is sinkholed or blocked, allowing subsequent DNS requests on the same session to be processed normally instead of being silently dropped.
Previously, when the firewall sinkholed or blocked a DNS query, the UDP session was placed in a DISCARD state. Because DNS clients commonly reuse the same UDP source port for multiple queries, subsequent requests that arrived on the same session tuple were dropped without notification, resulting in intermittent DNS resolution failures that were difficult to diagnose. This behavior affected queries sinkholed or blocked by EDL and content rules, Advanced DNS Security, and DNS Security.
You enable No DNS UDP Discard in the DNS Security profile settings. The setting is disabled by default to maintain backward compatibility. When you enable this setting, the firewall continues to enforce the sinkhole or block verdict on the triggering query but preserves the session state so that unrelated queries arriving on the same UDP session are inspected and processed normally.

EDL Bypass Action for DNS Security

July 30, 2026
You can now configure a bypass action on domain External Dynamic Lists (EDLs) to actively exempt trusted domains from DNS Security inspection, eliminating unnecessary alert logs and reducing operational noise in your security environment. Organizations that maintain EDLs of known-safe internal domains can now suppress DNS inspection for those domains without generating log entries that obscure genuine security events.
Many environments rely on domain EDLs to define trusted internal domains that do not require DNS threat inspection. Without a dedicated bypass action, you must configure the EDL with an alert action to achieve exemption from DNS Security processing. This generates a log entry for every matching DNS query, flooding your logging infrastructure with benign events and making it harder to identify actionable security alerts. The new bypass action solves this problem by functioning as an active allow that instructs the firewall to skip DNS request inspection for matching domains, without writing any log entries.
The bypass action takes precedence over all DNS Security category verdicts, ensuring that your trusted domains always pass through inspection cleanly. You configure the bypass action directly in the DNS Security profile under the domain EDL settings, alongside the existing alert, allow, block, and sinkhole actions. This gives you precise, per-domain control over which traffic bypasses DNS Security processing entirely.
By deploying the bypass action on your trusted domain EDLs, you reduce log volume, lower the operational burden on your security operations team, and maintain a cleaner signal-to-noise ratio in your DNS Security event data. You can focus your monitoring and response efforts on genuine threats rather than filtering through expected traffic from known-safe domains.