Someone in the office clicks a link in an email that looks like a shipping notice. Most of the time nothing stops that page from loading. If it's a fake login page or a malware download, your antivirus and your staff's judgement are the only things left between the click and the damage.
You can add one more layer for every device on the office network, usually in under half an hour and often for free: DNS filtering. And before you do that, there's a five-minute job that protects your own website and email from being hijacked: locking down your domain registrar account.
The quick answer
- Log in to wherever you bought your domain name (the registrar), turn on two-step sign-in, make sure the transfer lock is on and auto-renew is set with a card that won't expire.
- Log in to your office router and change its DNS servers to a filtering service, such as Cloudflare's
1.1.1.2and1.0.0.2or Quad9's9.9.9.9. - Check each browser isn't quietly using its own "secure DNS" that skips your filter.
- Test it with the provider's check page.
- Remember it only covers devices while they're on the office network. Laptops that travel need an app.
The rest of this post goes through each step and explains where it falls short.
What DNS is, in one paragraph
Every time anyone types a web address or clicks a link, their computer first asks a DNS server to turn the name (like managednerds.tech) into the numeric address of the server that hosts it. Normally your router passes that question to your internet provider, which answers it for any name at all, good or bad. A filtering DNS service answers the same question but refuses to give out the address of sites known to host malware or phishing. No address, no page. That's the whole trick.
Step 1: Lock down your domain registrar account
This step isn't about blocking websites. It protects the thing every customer and every email depends on: your domain name. Whoever controls the registrar account can point your website and email anywhere they like. That's exactly how a 2019 hijacking campaign worked: attackers stole the logins for accounts that could change DNS records, then redirected web and email traffic. CISA's emergency directive on DNS infrastructure tampering told federal agencies to audit their DNS records, change those account passwords and put multi-factor authentication on every account that could change DNS. The same advice applies to a five-person business.
Log in to your registrar (GoDaddy, Namecheap, Squarespace Domains, Cloudflare, Network Solutions and so on) and check these things. Menu names vary by registrar, so look for the words in bold.
Turn on two-step verification
Find Security or Account settings and turn on two-step verification (sometimes called 2FA or MFA). Use an authenticator app or a passkey rather than text messages if the registrar offers them. ICANN's security committee has recommended multi-factor sign-in on registrar accounts for years in its registrant's guide to protecting registration accounts. If the account is protected only by a password that was also used somewhere else, see our post on credential stuffing for why that matters.
Check the transfer lock is on
Look for Domain lock, Transfer lock or Registrar lock on the domain's settings page and make sure it's on. It stops the domain being moved to another registrar without someone first logging in and unlocking it. It doesn't protect the account itself, which is why two-step sign-in comes first.
Know who has the login
Write down who can log in. A surprising number of small businesses find their domain sits in a former web designer's account, or under the personal email of someone who left. If that's you, ask the registrar how to move the domain into an account the business owns, and make sure the contact email on the account is one you'll still read in five years.
Turn on auto-renew
Turn on Auto-renew and check the card on file won't expire before the renewal date. ICANN's registrant responsibilities put it on you to keep your contact and payment details current. A lapsed domain takes your website and email down with it, and an expired domain can be registered by someone else.
Optional: DNSSEC
If your registrar offers a DNSSEC switch and it also hosts your DNS, turning it on adds a signature that helps stop forged answers about your domain. If your DNS is hosted somewhere else (a web host or Cloudflare, for example), ask whoever runs it first: switching DNSSEC on in the wrong place can take your site offline.
Step 2: Point the office router at a filtering DNS service
Pick a service (as of October 2026)
These are free and need no account for the basic version:
- Cloudflare 1.1.1.1 for Families. Use
1.1.1.2and1.0.0.2to block malware, or1.1.1.3and1.0.0.3to block malware and adult content. The IPv6 addresses are2606:4700:4700::1112and2606:4700:4700::1002(malware) or::1113and::1003(malware and adult). Source: Cloudflare's setup docs. - Quad9. Use
9.9.9.9and149.112.112.112(IPv62620:fe::fe). Quad9 is a Swiss non-profit that blocks domains linked to malware, phishing and scams, and does no other content filtering. Source: Quad9's documentation.
Note that plain 1.1.1.1 and Quad9's 9.9.9.10 don't block anything. The numbers matter.
If you want your own block lists, reports of what was blocked, or to block categories like gambling, you need an account-based service:
- Cloudflare Zero Trust (Gateway). Cloudflare offers a free Zero Trust plan; at launch it covered up to 50 users and third-party pricing summaries still list that limit, but check Cloudflare's plans page before you rely on it. It includes DNS filtering policies and an app for laptops.
- NextDNS. The free plan covers 300,000 queries a month. Above that, NextDNS keeps answering but stops filtering, and a busy office can use that many queries quickly, so treat the free tier as a trial.
- Cisco Umbrella and DNSFilter are paid business products with central reporting and roaming agents for laptops. Neither publishes a simple price for small offices, so get a quote.
Change the router's DNS
Cloudflare's router guide has steps by brand. The general version:
- In a browser, go to your router's admin address (often
192.168.1.1or192.168.0.1; it's usually on a sticker on the router). - Sign in. If it still uses the password on the sticker, change it while you're there.
- Find the DNS setting. It's usually under Internet, WAN, LAN or DHCP, depending on the brand.
- Write down the current DNS addresses so you can undo the change.
- Enter the two IPv4 addresses for your chosen service. If the router has IPv6 DNS settings, enter the matching IPv6 addresses too, or IPv6 lookups may skip the filter.
- Save, then restart one computer (or unplug its network for a minute) so it picks up the new settings.
Some internet provider routers lock the DNS setting. If yours does, the usual fix is to change the DNS handed out by the DHCP server on the same router, or to put your own router behind the provider's one. That's a good point to get help.
Step 3: Stop browsers from skipping the filter
Modern browsers can encrypt their DNS lookups with "DNS over HTTPS" (secure DNS). It's a privacy feature, but if a browser sends its lookups straight to a different provider, those lookups never reach your filter. Check each browser on each office computer:
- Chrome: Settings > Privacy and security > Security, then under Advanced look at Use secure DNS. If it's on and set to your current service provider, it follows your router's settings and is fine. If someone has chosen a specific provider such as Google or plain Cloudflare, switch it back to the current provider or turn it off. Per Google's help page, secure DNS can't be used on managed computers or with parental controls on.
- Edge: Settings > Privacy, search, and services > Security > Use secure DNS. By default it uses your current provider, and it's off on computers managed by an organization (Microsoft's Edge privacy notes). Same rule as Chrome: current provider is fine, a hand-picked one bypasses the filter.
- Firefox: Settings > Privacy & Security, scroll to DNS over HTTPS (you may need to click Advanced settings). In the US, Firefox's default secure DNS provider has been Cloudflare's unfiltered service. Either set it to Off, or choose Max Protection with a custom provider set to your filter's own secure address:
https://security.cloudflare-dns.com/dns-queryfor 1.1.1.2,https://family.cloudflare-dns.com/dns-queryfor 1.1.1.3, orhttps://dns.quad9.net/dns-queryfor Quad9 (Mozilla's guide to the levels).
You may read that Firefox switches its secure DNS off by itself on filtered networks. It checks a special "canary" name, use-application-dns.net, but Mozilla says that only applies when secure DNS is on by default, not when someone turned it on, and the free filtering services above don't promise to trigger it. Set Firefox by hand.
If your computers are managed through Intune or Group Policy, lock this down centrally instead: Edge and Chrome both have a DnsOverHttpsMode policy (Edge policy reference) and Firefox has a DNSOverHTTPS policy (Mozilla policy templates).
VPN apps and Apple's iCloud Private Relay also send DNS lookups elsewhere, so a device using either one won't be filtered while it's on.
Step 4: Test that it works
- Quad9: visit on.quad9.net. It says "Yes" if you're using Quad9, and "No" if anything (including a mix of Quad9 and other servers) gets in the way.
- Cloudflare: visit one.one.one.one/help, which shows whether your lookups are reaching Cloudflare's resolvers.
- Cloudflare Zero Trust: Cloudflare publishes test names such as
malware.testcategory.comandphishing.testcategory.comthat should be blocked if your policy blocks those categories (Cloudflare's testing guide).
Test from a couple of different computers and from a phone on the office Wi-Fi. If a result looks wrong right after the change, restart the device; browsers and Windows remember old answers for a while.
What this won't do
DNS filtering is a good, cheap layer, not a wall:
- It only blocks sites already known to be bad. A phishing page or a fake virus warning registered this morning may not be on any list yet.
- It doesn't stop a scam email or a convincing phone call. If someone reads out a code or sends a payment, no DNS setting helps. See our posts on business email compromise and QR code phishing.
- It covers devices only while they're on the office network. A laptop at home or in a coffee shop uses that network's DNS, unless you install the provider's app (Cloudflare's One Client, or the agent from a paid service).
- Anyone with admin rights on their computer can change its DNS. Staff accounts without admin rights close that gap.
- It doesn't fix a flat network where the guest Wi-Fi, the card reader and the office PCs all share one space. That's covered in our Wi-Fi segmentation guide.
If something stops working
Occasionally a filter blocks a site you need. With the free no-account services you can't make exceptions, so your options are to report the false positive to the provider or switch to an account-based service where you can allow a domain. If the whole internet seems broken right after the change, put the old DNS addresses back (you wrote them down) and check you typed the new ones correctly.
When to call someone
- Your provider's router won't let you change DNS, or you're not sure which box is the router.
- You need laptops filtered away from the office, or reports of what's being blocked.
- You can't get into your registrar account, or you find the domain is in someone else's name.
If any of those sound familiar, our cybersecurity service can set this up and keep it running.




