Secure DNS: Free DNS security service
Secure DNS is a free DNS security service that protects organisations from known threats by blocking malicious domains and IP addresses. Powered by mnemonic's Threat Intelligence, Secure DNS continuously adapts to emerging threats

Secure DNS is a free service that prevents computers from reaching websites known to be a threat. If a user or system requests a known malicious domain, Secure DNS will intercept the request and redirect the user to a safe website informing them of the risk that was averted.
The service only takes minutes to set up, operates transparently to users with no additional latency, is very robust with high up-time, and is powered by mnemonic’s global Threat Intelligence to provide organisations with real-time protection in this ever-changing landscape.
mnemonic Secure DNS goes beyond other commercial DNS protection services
Secure DNS is powered by mnemonic's Threat Intelligence. Our experienced cyber threat intelligence analysts continuously monitor the threat landscape to understand how attackers operate and identify the infrastructure they use. This enables Secure DNS to block not only malware, phishing and ransomware, but also targeted and persistent threats that many commercial DNS protection services do not detect.
Secure DNS also supports encrypted DNS through DNS-over-TLS (DoT) and DNS-over-HTTPS (DoH). Clients can use encrypted DNS connectivity to help protect DNS queries in transit, while continuing to benefit from the same protection Secure DNS already provides.
This extends the existing Secure DNS service without changing its core purpose: preventing users and systems from reaching websites and infrastructure known to be malicious.
Enterprise options
For organisations with additional requirements, mnemonic Secure DNS is also available with enterprise options. These can help adapt the service to your organisation’s operational, reporting and security needs.
As part of our enterprise upgrades these alternatives are available:
Custom reporting
- A periodic report and various metrics based on the number of malicious resolutions and observations.
Custom blockpage
- A block page with customised content and design scheme as you want it!
Custom blocklists
- A blocklist customised for your needs on top of existing Secure DNS protection.
Custom sinkhole
- A dedicated sinkhole server that can safely interact with and extract intelligence from the malicious lookups.
Ready to get started?
Configure your device, browser, router or corporate DNS service using the option that best matches your environment. Standard DNS is available using mnemonic’s Secure DNS resolver addresses, while encrypted DNS transport is available using DoT or DoH.
| Option | Use when | Configuration |
|
Standard DNS |
You want simple DNS-based protection against known malicious domains and IPs. |
IPv4: IPv6: |
|
DNSSEC-validating DNS |
You want Secure DNS with DNSSEC validation. DNSSEC validates DNS responses, but does not encrypt DNS transport. |
IPv4: IPv6: |
|
DNS-over-TLS (DoT) |
You want encrypted DNS transport using a dedicated TLS connection. |
Hostname: Port: |
|
DNSSEC-over-TLS (DoT) |
Hostname: Port: |
|
|
DNS-over-HTTPS (DoH) |
You want encrypted DNS transport over HTTPS, for example in browsers, operating systems or clients that support DoH configuration. |
|
|
DNS-over-HTTPS (DoH) with DNSSEC validation |
You want encrypted DNS transport over HTTPS together with DNSSEC validation. |
We strongly advise configuring redundant resolvers where supported, in order to achieve the best possible protection against downtime.
Terms of Service for Secure DNS
Contact us to learn more about our Enterprise options
