Understand and validate the Sophos DNS Protection dashboard
Learn how to interpret setup status, DNS usage, blocks, and top domains and turn them into sound operational decisions.
Practical guides for planning, deploying, and operating Sophos DNS Protection securely on networks and endpoints, with a clear distinction between Xstream and Workspace Protection.
Choose the network or endpoint path first; the guides then cover locations, policies, device deployment, reporting, and troubleshooting.
Understand the dashboard, plan DNS paths, configure locations and policies, and validate operation safely.
Learn how to interpret setup status, DNS usage, blocks, and top domains and turn them into sound operational decisions.
Additional guidance for managing and troubleshooting Sophos DNS Protection.
Reports provide repeatable operational analysis; Live Discover adds detailed Data Lake queries within the documented DNS schema.
Filtering policies control DNS filtering per location. This guide explains assignment, decision precedence, narrow exceptions, piloting, reports, and …
The DNS Protection Root Certificate makes HTTPS block pages trusted on Windows, macOS, and Firefox. This guide covers download, installation, …
Domain lists supplement web categories with targeted allow and block decisions for up to 1,000 domains per list.
Locations map DNS queries to the correct site and policy. This guide covers the complete lifecycle, including safe migration and validation.
Decision guide and runbook for individual Macs: DNS servers per network service or a generated DoH configuration profile, including limitations, …
Decision guide and instructions for DNS routing, egress identity, firewall access, pilot deployment, validation, and troubleshooting.
This guide shows the manual Windows configuration using the tenant-specific DNS addresses and DoH template from Sophos Fusion.
A Windows DNS Server uses both DNS Protection IP addresses copied from Sophos Fusion as forwarders.
Sophos DNS Protection is a cloud-based DNS service in Sophos Fusion. It combines secure DNS resolution with threat blocking, custom policies, domain lists, and reports. Before configuring anything, choose the correct deployment path: Xstream Protection covers standalone protection for networks and locations, while Workspace Protection covers managed DNS protection for Windows endpoints through Sophos Endpoint. Both licensing paths support DNS over HTTPS, but they are not interchangeable.
Direct decision: Choose the network path for a site network, firewall, or unmanaged devices. Choose the endpoint path for managed Windows devices that must also be protected outside the corporate network. Do not combine both paths on the same device without planning.
Standalone DNS Protection is part of the Sophos Firewall Xstream Protection subscription and does not include Sophos Endpoint. Network devices use a central resolver, a firewall, or the DNS destinations assigned to the tenant. Locations, policies, and reports are managed in Sophos Fusion.
First, compare Sophos Firewall bundles to understand licensing. Then use Plan and set up DNS Protection on the network to choose the DNS path. If you use a Sophos Firewall as the resolver and forwarder, follow Set up Sophos DNS Protection with Sophos Firewall.
DNS Protection for endpoints is a Workspace Protection capability. Sophos Endpoint securely forwards DNS traffic from supported Windows devices to DNS Protection. This path is licensed per device; an Xstream subscription alone does not entitle you to use it.
Workspace Protection also includes Protected Browser, ZTNA, and Email Monitoring System. This does not make DNS Protection a feature of those other products: even integration with Protected Browser remains a separate endpoint DNS path. License Sophos Fusion explains licensing and usage logic; installation, policy, and piloting are covered in Configure DNS Protection for endpoints.
For example, an organization can pilot the Headquarters site network through the network path and separately test a small Windows-Pilot group through the endpoint path. Names are flexible; what matters is that each group follows exactly one documented path and that its requests can be assigned to the expected policy.
Under My Products > DNS Protection, several areas form one operational workflow:
The linked detailed guides describe the respective procedures. This topic overview provides orientation and does not repeat procedures for setting up locations, policies, and certificates or working with reports.
After the pilot, more than name resolution must work:
If these results are missing, do not immediately broaden policies. First determine whether the issue is on the network or endpoint path. For network, firewall, or location troubleshooting, use the linked network guides; for agents, device assignment, or endpoint policy, use the endpoint guide. This keeps troubleshooting limited to the active data path and avoids mixing two different paths.
DNS Protection processes DNS request data such as public source IP, requested domain, timestamp, and DNS response. Username and endpoint device name are processed only with Endpoint DNS Protection. The data supports policy enforcement, reporting, threat analysis, and troubleshooting. It is also used for product improvement and innovation, including detection and security techniques and performance optimization. Sophos Engineering, SophosLabs, and Sophos AI may also use it for product development, analysis, threat detection, research, and continuous improvement.
According to the Sophos Privacy Data Sheet, customer-usable DNS Protection data is retained in Sophos Fusion for 90 days, diagnostic logs for 30 days, and configuration data until the service is no longer used. Processing and storage take place in the region selected when the Sophos Fusion account is created. DNS requests, however, are routed to a suitable global resolver point of presence and processed there only temporarily before data is sent to the Fusion region. The management region and resolver location are therefore not the same.
In addition to US and EU, Sophos lists Australia, Brazil, India, Japan, and Canada as management regions. Regional availability and subprocessors may change, so verify current details before rollout and during regular reviews. Privacy and data sharing in Sophos Fusion describes the wider governance process.
This overview deliberately provides no universal off switch: safe rollback differs for network DNS, Sophos Firewall, and endpoint policy. Before a change, document the previous resolver or policy, test-group assignment, and expected behavior. If an error occurs, roll back only the affected deployment path by following its linked guide, then retest internal and public name resolution.
If you cannot identify the active path unambiguously, or there is no documented rollback for the deployed variant, stop safely. Do not delete locations, policies, or agent components on suspicion. Involve the administrators responsible for the network or endpoints first and, if necessary, escalate to Sophos Support with the recorded test data.
The release history explains why the paths are treated separately: standalone DNS Protection reached General Availability on June 11, 2024. Integration of DNS Protection with Sophos Endpoint was announced as Early Access on November 24, 2025 and redirected DNS requests over HTTPS. These dates are historical milestones, not statements about a current EAP, EOL, or retirement status.
During operation, regularly review licensing, administrative roles, locations, policies, domain lists, reports, data retention, and the tested rollback path. Validate changes first with a limited location or device group. Current help and release information takes precedence over historical announcements.