Introducing Safe Search for the Advanced DNS Security Resolver

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Articles
2 min read
L0 Member
No ratings

Security Resolver.png

 

For network administrators, securing web traffic is a delicate balancing act between safety, privacy, and performance. This challenge is especially acute in educational institutions and enterprise environments enforcing strict workplace content policies.

Historically, enforcing SafeSearch across major search engines forced administrators into frustrating trade-offs:

 

  • Decryption Friction: SSL/TLS decryption allows deep inspection, but data privacy regulations and BYOD (Bring Your Own Device) environments make full-scale decryption legally complex or technically non-viable.
  • Operational Overhead: Using traditional DNS proxies requires constant manual tracking of dynamic SafeSearch IP addresses—a maintenance headache that degrades over time.
  • Local Bypasses: Relying on browser-level settings or endpoint management fails the moment an unmanaged personal device connects to the network.

 

Today, we are eliminating these trade-offs. We are excited to announce native SafeSearch enforcement built directly into the Palo Alto Networks Advanced DNS Security Resolver (ADNSR).

 

How It Works: Safety at the DNS Level 


Instead of waiting for HTTP/HTTPS content inspection or relying on endpoint configuration, the Advanced DNS Security Resolver intercepts and rewrites DNS queries for supported search engines directly at the resolution stage.

 

When a user on your network attempts to access a search engine, ADNSR automatically resolves the domain to its SafeSearch-enforced target (evaluating both A and AAAA record types). Supported search engines include:

 

  • Google
  • Bing
  • YouTube
  • DuckDuckGo
  • Yandex
  • Brave

 

Because enforcement occurs at the DNS layer before a connection is established, explicit content, thumbnails, and harmful search results are blocked automatically—without requiring traffic decryption or per-device management.

 

Getting Started 


Enabling SafeSearch across your entire network takes less than two minutes:

 

  1. Log in to Strata Cloud Manager.
  2. Navigate to Configuration, select ADNS Resolver, then select the DNS Security Profiles tab.
  3. Select an existing DNS Security profile or create a new one.
  4. Select the Safe Search tab.
  5. Enable Safe Search. Once enabled, the Advanced DNS Security Resolver automatically rewrites DNS queries for supported search engines to their SafeSearch-enforced domains. (Note: Google, Bing, Brave, DuckDuckGo, and Yandex are enforced collectively and cannot be enabled individually.)
  6. (Optional) Configure Restrict YouTube Access and select your preferred Filtering Level.
  7. Save the DNS Security profile configuration.

 

By shifting SafeSearch enforcement to the Advanced DNS Security Resolver, you get instant coverage, complete privacy compliance, and zero endpoint overhead.

 

Update your DNS Security profiles today to take advantage of effortless, network-wide SafeSearch enforcement.

Rate this article:
  • 18 Views
  • 0 comments
  • 0 Likes
Contributors
Labels
Article Dashboard
Version history
Last Updated:
‎08-07-2026 01:29 AM
Updated by: