The ClearScreen blog.
DNS policy, threat feeds, and compliance notes for endpoint fleets.
- How to check if a domain is malicious: a practical triage guide Threat feeds, category lists, registration age, certificate history, and DNS posture — a five-step triage for suspicious domains, plus a free checker that runs the first two steps for you.
- Deploying DNS filtering to a Windows fleet with Intune Group assignment, platform scripts, and run states — how to roll a DNS filtering agent out through Intune, and why "assigned" is three steps away from "protected."
- Custom blocklist categories: when the standard taxonomy isn't enough Public lists will never know your terminated vendors or contractual exclusions. How tenant-defined categories keep in-house blocks auditable instead of piling up in a flat exception list.
- What NIS2 actually expects from web filtering and DNS controls Risk-management measures, cyber-hygiene baselines, and 24/72-hour reporting clocks — where DNS-layer filtering fits as an evidence-producing control in a NIS2 program.
- StevenBlack and UT1 blocklists in the enterprise: provenance, cadence, and safe operations What the two most widely used public blocklists actually are, who maintains them, and why raw hosts-file deployment is the wrong way to consume them at fleet scale.
- DNS filtering for MSPs: tenant isolation without policy sprawl Per-client tenants, per-tenant enrollment keys, and custom categories for contractual blocks — answering any client auditor from that client's tenant alone.
- Web filtering on Windows without a proxy: the local-resolver model No TLS interception, no PAC files, no gateway dependency — what the local-resolver agent model enforces, and an honest look at what a full SWG still does better.
- GDPR-compliant employee web filtering: what to log, what to skip Legitimate interest, proportionality, and data minimization — logging block events without building a browsing-history surveillance archive, and where works councils come in.
- DNS filtering vs proxy for endpoints: what CISOs should compare TLS inspection, PAC files, and local sinkholes — the trade-offs that matter when DORA and NIS2 reviewers ask where policy enforcement lives.
- DORA ICT risk: why the DNS layer belongs in your register Third-party resolvers, unsigned blocklists, and invisible enforcement — gaps that show up in ICT risk assessments for financial entities.
- Blocking AI tools without blocking productivity UT1 categories, allowlists, and review queues — how to stop unsanctioned LLM use while keeping engineering and research workflows intact.
- False-positive review workflow: from block page to audit evidence User reports, admin decisions, and exportable records — the loop regulators expect when DNS policy blocks a legitimate domain.
- UT1 categories: what to block first on a pilot fleet Malware, phishing, adult, gambling, and AI chat — a phased rollout order that passes legal review and keeps helpdesk load manageable.
- ed25519-signed threat feeds that work offline URLhaus, OpenPhish, and PhishTank in a signed bundle — why signature verification matters when agents cannot phone home every hour.
- The director who couldn't switch web-filtering vendors because his audit evidence was trapped inside the old one Portability is a control too. This post follows a director who tried to move filtering vendors and discovered his policies, exceptions, and years of block-decision evidence were locked in proprietary formats he couldn't export or re-attest.
- The CISO facing a 24-hour NIS2 reporting clock with no way to reconstruct what the endpoint talked to NIS2's tight incident-notification windows assume you can quickly establish scope, and DNS query history is often the fastest scope signal. This post is about a CISO who couldn't answer 'what did the device contact' inside the deadline.
- The IT manager whose block page looked like a malware warning, and trained users to ignore real ones A generic browser error in place of a clear block page erodes the one moment of user education filtering offers. This post covers an IT manager whose cryptic block experience taught users that security warnings are just 'the IT thing breaking again.'
- The compliance lead who tried to filter personal devices, and walked into a privacy problem Forcing full DNS filtering and logging onto employee-owned devices can collide with data-protection law and works-council rules. This post is about a compliance lead whose BYOD filtering push created a GDPR and employee-monitoring headache.
- The CISO standing in front of the board after a phishing hit, explaining why a known-bad domain wasn't blocked When a domain on a public phishing feed lands a victim, the board's first question is why it wasn't already blocked. This post traces a CISO's post-incident reckoning with feeds that existed but were never wired into endpoint enforcement.
- The director who blocked a too-broad category, triggered a productivity revolt, and disabled filtering entirely Blocking 'social media' or 'AI chat' with a blunt category at full fleet scope is how good filtering programs die in week two. This post is about a director whose overbroad first rule cost him the whole initiative.
- The director who trusted the agent, while local admins edited the hosts file and the resolver out of the loop An endpoint filter is only as strong as the user's inability to disable it. This post covers a director who discovered power users with local admin were editing hosts files and DNS settings to route straight past the agent.
- The endpoint manager who reported 100% Intune coverage, while a tenth of the fleet never got the filter Intune assignment is not Intune installation. This post is about an endpoint manager whose compliance dashboard said 100% but whose DNS logs proved a slice of devices never actually had the filtering agent running.
- The sales-side director who lost a deal because the security questionnaire asked for egress-control evidence he didn't have Enterprise buyers now ask vendors to prove endpoint egress and DNS controls, with logs. This post follows a director whose deal stalled in security review because 'we have a firewall' wasn't an answer to 'show us your DNS-layer enforcement.'
- The bank CISO who built a DORA ICT risk register and left the DNS layer out of it DORA wants the full ICT dependency chain in the register, and DNS resolution is a single point of failure most registers skip. This post is about a financial-sector CISO whose otherwise thorough register had a silent gap at the resolver.
- The IT manager who offboarded the admin's email but not his standing exception to the web filter Offboarding checklists kill mailboxes and VPN, but rarely the quiet policy exceptions a power user left behind. This post covers an IT manager who learned, post-departure, that an ex-admin's personal allow-list was still actively enforced.
- The IT director who budgeted per seat, then got billed for every contractor laptop that ever roamed Endpoint-filtering pricing models punish exactly the messy reality of contractors, BYOD and seasonal staff. This post is about an IT director whose renewal doubled because the count was 'devices that ever checked in,' not 'employees.'
- The service-desk manager whose filter rollout generated 300 tickets a day and a queue of silent overrides A web filter with no fast, governed false-positive path doesn't get tuned, it gets bypassed. This post follows a service-desk manager whose technicians, drowning in tickets, started whitelisting domains with no review and no record.
- The SOC manager who thought silence meant safe, while offline laptops ran on stale policy for weeks An endpoint agent that can't reach its console isn't protected, it's unmonitored. This post covers a SOC manager whose dashboard showed green because dead agents simply stopped reporting, masking a fleet drifting on weeks-old policy.
- The CISO who couldn't tell the board where the blocklist came from, or whether it had been tampered with Threat feeds that arrive as opaque downloads with no signature are a supply-chain risk hiding inside a security control. This post is about a CISO asked to attest to feed integrity who realized he had no cryptographic basis to do so.
- The security manager who banned ChatGPT in a memo, while 400 endpoints talked to 30 AI domains A written AI policy without DNS-level visibility is a feeling, not a control. This post covers a security operations manager who 'restricted AI tools' and then discovered, via DNS logs, the dozens of LLM endpoints his fleet was actually reaching.
- The MSP owner who sold 'managed filtering' and can't prove which policy applies to which client Per-endpoint policy edits feel flexible until an MSP has 4,000 endpoints across 60 tenants and no canonical answer to 'what is enforced for client X.' This post is about policy sprawl that becomes a liability the day a client's lawyer asks.
- When the auditor asks 'why was this blocked,' and the GRC lead has no answer to give A clean blocklist is not audit evidence. This post follows a GRC lead through a NIS2 audit where 'the filter blocked it' was the answer, and the auditor wanted the policy, the category source, the timestamp, and who could have overridden it.
- The IT director who believed his web filter was enforced, until a browser turned on DoH and routed around it Encrypted DNS (DoH/DoT) baked into Chrome, Edge and Firefox silently bypasses any filter that lives at the network resolver. This post shows how an IT director's 'policy is enforced' became 'policy is optional' the moment a browser picked its own resolver.
- SmartScreen is being deprecated, and the CISO who assumed Defender covers it inherits the gap Microsoft's November 2025 deprecation of in-process SmartScreen in IE and IE Mode quietly removed the URL-reputation interstitials many CISOs still counted as their web-reputation control. This post traces how 'Defender has it' became a coverage gap nobody booked.