Twingate Internet Security

Proactively block threats
with DNS Filtering
and Content Filtering

Security for everyone, everywhere. From the office, to the coffee shop, to the airport: protect all of your internet traffic in any environment.

rutorrentz.net

rutorrentz.net

Status

Blocked

Condition

Piracy

sportbet360.com

sportbet360.com

Status

Blocked

Condition

Gambling

gamezone.com

github.com

linear.app

news.google.com

linkedin.com

reddit.com

DNS · INTERNET SECURITY

What is Twingate Internet Security?

Twingate Internet Security is a DNS and content filtering solution that protects internet traffic on every device, across every environment, whether that's the office, a home network, or public Wi-Fi. It inspects DNS queries in real time, catching phishing attempts, malware, cryptojacking, and access to high-risk content before a connection is ever established.

Deployment happens through your existing MDM, so there's no need to introduce new agents or workflows. Policy applies network-wide without backhauling traffic through a central location, keeping performance fast for users while keeping security consistent everywhere they work. Every DNS query gets logged, giving your team full visibility into device activity, browsing patterns, and the specific reasons behind each blocked request.

Traditional secure web gateways operate as a separate layer, bolted onto your existing security stack. Twingate Internet Security instead runs as part of the broader Zero Trust platform, meaning the identity- and device-aware controls that already govern access to private resources extend naturally to govern internet access too. Teams get a single, unified policy layer that covers both private and public traffic, deployable in minutes rather than weeks.

Programatic protection

Deploy and manage via MDM to build internet security into your existing workflows without adding to admin overhead.

Universal internet security

Keep your users protected from threats and human error with comprehensive protection for internet traffic in any environment.

Threat analysis

Discover vulnerabilities and identify trends in internet traffic with query and activity data across your entire network.

What threats does DNS filtering block?

What threats does
DNS filtering block?

Twingate evaluates every DNS request against continuously updated threat intelligence, then encrypts it with DNS-over-HTTPS to your resolver of choice. Malware, phishing, and command-and-control domains are dropped at lookup time. No proxy hop, no separate agent.

Threat protection, on by default

Malware, phishing, command-and-control, cryptomining, DNS tunneling, and newly registered domains are blocked from day one.

Encrypted DNS everywhere

Every query is wrapped in DNS-over-HTTPS so the local network — hotel, café, airport — sees only opaque TLS.

Custom allow / block lists

Layer organization-specific domains on top of the built-in feeds. Changes apply instantly to every enrolled client.

Acceptable-use policy, without acceptable-use pain.

Restrict entire categories of the internet like gambling, adult, piracy, streaming, social media, and unauthorized SaaS. Apply policies per group or org-wide. Same client, same policy plane as DNS filtering and ZTNA.

Policy Content Categories

apply_to = group: standard_users

Social Media

Streaming & Video

Gambling

Adult Content

Piracy

Shopping

Unauthorized SaaS

Custom allow-list

Custom block-list

Dozens of categories

Social, streaming, gambling, adult, piracy, weapons, shopping, dating, games, ads, and trackers. Toggle each one on or off.

Group-scoped policies

Bind filtering profiles to identity-provider groups. Engineering, Finance, K–12 students, or contractors each get the right policy.

Built for regulated environments

Schools, healthcare, financial services, and shared devices meet acceptable-use requirements at the OS level, on and off the network.

Shadow AI

What AI tools are your employees actually using?

Discover AI services across protected devices, understand usage patterns, and attribute activity to the users and devices behind each request.

Coming soon

A

Autoco

autoco.twingate.com

21

TOOLS DETECTED

1.8M

AI REQUESTS

Tool inventory

Authentication & Identity-based Access

Every detected AI service ranked by observed adoption and tagged by category: assistant, coding, notetaker, writing, developer platform, media, and more.

01 ChatGPT

Assistant

02 Github Copilot

Coding

03 Granola

Notetaker

Usage & trends

Authentication & Identity-based Access

Devices, requests, and days-active per tool. Coverage shown against total requests and total devices in the org.

Per-user attribution

Authentication & Identity-based Access

SIEM and CSV export with per-user and per-device breakdowns. Share with Security, Finance, or bring into existing workflows.

One policy. Every device. Every network.

In the office

Enforce DNS policy without hairpinning traffic through a headquarters appliance. Runs at the OS level, not the network edge.

In the office

Enforce DNS policy without hairpinning traffic through a headquarters appliance. Runs at the OS level, not the network edge.

In the office

Enforce DNS policy without hairpinning traffic through a headquarters appliance. Runs at the OS level, not the network edge.

On coffee-shop Wi‑Fi

DNS-over-HTTPS wraps every query so the local network operator can’t snoop or hijack lookups on untrusted hotspots.

On coffee-shop Wi‑Fi

DNS-over-HTTPS wraps every query so the local network operator can’t snoop or hijack lookups on untrusted hotspots.

On coffee-shop Wi‑Fi

DNS-over-HTTPS wraps every query so the local network operator can’t snoop or hijack lookups on untrusted hotspots.

Traveling worldwide

Consistent global policy from any airport, hotel, or conference — no split policies, no VPN concentrator to reach.

Traveling worldwide

Consistent global policy from any airport, hotel, or conference — no split policies, no VPN concentrator to reach.

Traveling worldwide

Consistent global policy from any airport, hotel, or conference — no split policies, no VPN concentrator to reach.

BYOD & personal laptops

Ship one lightweight client for macOS, Windows and Linux. Personal browsing history stays private from the local network.

BYOD & personal laptops

Ship one lightweight client for macOS, Windows and Linux. Personal browsing history stays private from the local network.

BYOD & personal laptops

Ship one lightweight client for macOS, Windows and Linux. Personal browsing history stays private from the local network.

Powerful security deployed in minutes

Powerful security deployed in minutes

No more challenging deployments, poor performance, and constant user complaints. Protect all your users' internet traffic without slowing down the pace of business.

90%

90%

90%

reduction in deployment time

reduction in deployment time

reduction in deployment time

99.999+%

99.999+%

99.999+%

reliability

reliability

reliability

86%

86%

86%

faster than VPN

faster than VPN

faster than VPN

How does Internet Security fit your existing security stack?

Twingate is a central Zero Trust orchestration layer, so you can create a best-in-class security ecosystem without having to recut your network. Leverage out-of-the-box integrations with major IdPs, MDM/EDRs, SIEMs, DOH providers, and more.

How does Internet Security fit your existing security stack?

Twingate is a central Zero Trust orchestration layer, so you can create a best-in-class security ecosystem without having to recut your network. Leverage out-of-the-box integrations with major IdPs, MDM/EDRs, SIEMs, DOH providers, and more.

How does Internet Security fit your existing security stack?

Twingate is a central Zero Trust orchestration layer, so you can create a best-in-class security ecosystem without having to recut your network. Leverage out-of-the-box integrations with major IdPs, MDM/EDRs, SIEMs, DOH providers, and more.

Frequently Asked Questions

What is Twingate Internet Security?

Twingate Internet Security is a DNS filtering and content control solution that protects users from malware, phishing, and inappropriate content no matter where they connect from: office, home, or public Wi-Fi. It works by inspecting DNS queries before a connection is made, blocking access to malicious or restricted domains at the network layer rather than relying on device-by-device software. It's built on Twingate's Zero Trust platform, so security teams get DNS-level protection alongside Zero Trust Network Access (ZTNA) without deploying a separate agent or reconfiguring the network.

What is DNS filtering and how does it work?

DNS filtering is a security technique that blocks access to dangerous or unwanted websites by intercepting the DNS lookup that happens before a device connects to a site. Twingate's DNS filtering uses DNS-over-HTTPS (DoH): once enabled, a user's device sends DNS queries to Twingate's resolvers, which check each domain against configured rules and block it if it matches a threat category, content category, or an admin-defined denylist. Blocked domains simply fail to resolve, so the site behaves as if it doesn't exist, no connection is ever established.

What threats does Twingate Internet Security protect against?

Twingate DNS filtering blocks eight categories of security threats: malware feeds, phishing sites (via Google Safe Browsing), DNS rebinding attacks, IDN homograph attacks, typosquatting domains, domain generation algorithm (DGA) domains, newly registered domains, and parked domains. This covers the most common ways attackers get users to connect to malicious infrastructure, including phishing links, drive-by malware, and cryptojacking scripts, before a connection is ever made.

What kind of content can Twingate block besides security threats?

Beyond security threats, Twingate DNS filtering can restrict nine content categories: gambling, dating, adult content, piracy, social media, games, and streaming, plus options to force Google Safe Search and YouTube Safe Mode. It also includes privacy protections that block disguised trackers, affiliate/tracking links, and ad networks. Admins choose which categories to enforce per group, so policies can differ between departments, contractors, or locations.

How do I configure DNS filtering policies for different teams?

DNS filtering policies are configured using profiles — rule sets that combine security categories, content categories, and custom allowlists/denylists — which are then assigned to specific user groups. Twingate supports up to 10 profiles, evaluated in priority order, so admins can apply stricter rules to one group (e.g., contractors) and more permissive rules to another (e.g., IT staff) without maintaining separate networks or infrastructure.

Which devices and operating systems support Twingate DNS filtering?

Twingate DNS filtering currently supports macOS, Windows, and Linux client devices. It is not yet available on iOS or Android. Any user or group without DNS filtering explicitly assigned continues to browse without those restrictions, so admins should confirm group assignments when rolling the feature out.

How is DNS filtering different from a traditional firewall or secure web gateway?

Unlike a traditional firewall or secure web gateway, Twingate's DNS filtering blocks malicious or restricted domains at the moment of DNS resolution, before any packet reaches the destination, and it travels with the device rather than being tied to a specific network perimeter. Because it's built into the same client used for Zero Trust Network Access, there's no separate appliance, VPN concentrator, or gateway to deploy, patch, or scale, and protection follows remote and hybrid employees wherever they connect.

Does Twingate Internet Security protect remote and hybrid employees outside the office?

Yes. Because DNS filtering is enforced on the device through Twingate's client, protection applies equally in the office, at home, at a café, or while traveling. Anywhere the employee's laptop connects to the internet. This closes a common gap where content and security policies only apply on the corporate network and disappear the moment someone works remotely.

How does DNS filtering integrate with Twingate's Zero Trust access model?

DNS filtering runs on the same Twingate client and admin console used for Zero Trust Network Access, so security teams manage both from one place instead of stitching together a separate DNS security product. It operates independently of resource-level access policies — DNS filtering secures what a device can reach on the open internet, while Zero Trust policies control access to internal resources — but both are enforced through the same lightweight agent and identity-based groups.

Can employees bypass or disable Twingate's DNS filtering?

No. Because filtering is enforced through DNS-over-HTTPS at the client level and tied to identity-based group policy rather than local network settings, employees can't disable it by switching Wi-Fi networks, using a different DNS resolver, or leaving the corporate network. Admins control which groups have filtering applied centrally through the Twingate admin console.

What visibility and reporting does Twingate Internet Security provide?

Twingate provides 7-, 30-, and 90-day filtering summaries along with recent activity logs showing which domains were blocked or allowed, which profile applied, and why. Logs can be synced to AWS S3 in JSON format for ingestion into a SIEM, giving security teams full visibility into DNS-layer threats and content trends across the organization.

Do I need new hardware or to reconfigure my network to use Twingate DNS filtering?

No. Twingate DNS filtering works entirely through the existing Twingate client already used for Zero Trust access, so there's no additional hardware, no DNS server changes at the router level, and no network reconfiguration required. It can also be deployed and managed through existing MDM tooling, which is part of why Twingate customers report roughly 90% faster deployment and an 87% drop in related support tickets compared to legacy approaches.

Which Twingate plans include DNS filtering?

DNS filtering is available as an add-on for Twingate's Business and Enterprise plans. Contact Twingate or check the current pricing page for exact availability and packaging.

Can Twingate DNS filtering stop phishing and cryptojacking specifically?

Yes. Phishing domains are blocked using Google Safe Browsing data as part of the security threat categories, and cryptojacking scripts typically rely on domains that fall under malware feeds or newly registered/DGA domains, both of which are blocked outright at the DNS layer, before the malicious script or page ever loads in the browser.

Twingate
Enterprise

Twingate
Enterprise

Twingate
Enterprise

For organizations that need comprehensive security and access controls, plus detailed auditing

No limits on users, admins, or remote networks

Enhanced API & Labs capabilities

Invoicing

SLAs & custom MSAs

Priority support & customer success