Yes, DNS filtering should sit inside every school’s baseline protection. It blocks access to malicious and inappropriate domains before a page ever loads, cuts the administrative burden of manual site blocking, and directly supports the filtering and monitoring core standard that the Department for Education expects schools and colleges to meet.
It is not, on its own, a complete safeguarding solution. DNS filtering works at the domain level, so it needs endpoint security, application-aware controls, and staff training alongside it.
- Blocks malicious and inappropriate domains at the point of lookup, before content loads
- Reduces manual site-by-site blocking and lightens IT admin workload
- Supports statutory filtering and monitoring duties under DfE guidance
- Does not replace endpoint protection, content-aware proxies, or classroom teaching on online safety
The quick win: the NCSC’s PDNS for Schools service, launched in October 2024, gives eligible schools a free, enterprise-grade protective DNS layer with no client software to install.
Key Takeaways
DNS filtering succeeds when it pairs statutory compliance with layered technical controls, clear governance roles, and regular review, not when it’s treated as a one-off purchase.
| Point | Details |
|---|---|
| Start with a compliance baseline | Map your current filtering against the DfE filtering and monitoring core standard before buying anything new. |
| Use PDNS as a low-cost pilot | Check NCSC PDNS for Schools eligibility for a free protective DNS layer with no client installs. |
| Plan for encrypted DNS | Enforce DNS settings at the network level to stop DoH and DoT bypassing your filter. |
| Assign review roles clearly | Give DSLs monthly access to blocked-domain logs and set a quarterly policy review cadence. |
| Consider a managed deployment | Re-Solution builds DNS filtering into a wider managed network service with DfE-aligned policy design and training. |
Table of Contents
- How DNS filtering for schools actually works
- Why schools need DNS filtering for safeguarding and compliance
- How to choose and configure DNS filtering for your school
- Deployment options and integrating DNS filtering with zero-trust
- Monitoring, reporting and reviewing your DNS filter
- Re-Solution: managed deployments built for education compliance
- Sources
- FAQ
How DNS filtering for schools actually works
DNS filtering intercepts the lookup that happens every time a device tries to reach a website. Before a browser can load a page, it asks a resolver to translate a domain name into an IP address. Filter that resolver, and you control which domains ever get answered.
The mechanics matter for anyone assessing whether a product will hold up under real school traffic:
- Resolution point. Filtering typically happens at a recursive resolver, either on-premise, in the cloud, or through a service like PDNS, which sits between school devices and the wider internet.
- Domain versus page-level blocking. Most DNS filters block or allow whole domains, not individual pages. A category list marks example-site.com as “gambling” or “social media,” and every subpage inherits that verdict, which is why false positives can happen and exception workflows matter.
- Encrypted DNS complications. DNS-over-HTTPS and DNS-over-TLS route lookups outside the traditional resolver path, which can bypass network-level filtering entirely unless you enforce DNS settings at the network or device level.
- The endpoint gap. DNS filtering cannot inspect what happens after a connection is allowed. Malware already resident on a device, or an attack delivered over an approved domain, needs endpoint and application-layer controls to catch.
Treat DNS filtering as the first checkpoint, not the last one.
Why schools need DNS filtering for safeguarding and compliance
Filtering and monitoring are not optional extras for UK schools. The DfE’s filtering and monitoring core standard sets out what “appropriate” provision looks like, and Keeping Children Safe in Education reinforces that senior leaders and designated safeguarding leads carry direct responsibility for it.
DNS-layer defences give early visibility into traffic and can catch phishing and malware before they reach a device, making them one of the more cost-effective controls a school can put in place; learn more about how to protect business email from phishing attacks for added security here.
The financial case is straightforward too: a ransomware incident that starts with a single clicked phishing link can take down an entire school network for days, whereas blocking the malicious domain at the DNS layer stops the chain before it starts. This single layer also feeds directly into the teaching online safety work schools are expected to deliver. Technical blocking without classroom context tends to produce pupils who find workarounds rather than pupils who understand risk.
How to choose and configure DNS filtering for your school
Procurement decisions live or die on the detail. Before signing anything, work through these criteria with your shortlist:
- Policy granularity. Look for education-specific category templates (exam boards, safeguarding terms, self-harm content) rather than generic corporate lists, plus a fast whitelisting process for legitimate resources that get caught by mistake.
- Identity and device handling. Confirm Active Directory or LDAP integration so policies follow the user, not just the network, and ask explicitly how BYOD devices are handled on guest and staff networks.
- Reporting and log retention. Designated safeguarding leads and governors need exportable logs that satisfy audit requirements without exposing irrelevant personal browsing detail.
- Resilience and support. Check the SLA, onboarding timeline, staff training provision, and how quickly an emergency override can unblock a resource during a live lesson.
Pro Tip: *Ask any shortlisted vendor to show you their exception-handling turnaround time in writing, not just describe it.
Red flags worth walking away from: no education-specific category sets, no clear data retention policy, or a support model that routes every override request through a generic ticketing queue with no defined response time.
Deployment options and integrating DNS filtering with zero-trust
Schools generally choose between three deployment models, each with a different balance of control and effort.
- Cloud-based protective DNS, such as PDNS for Schools, needs no on-site hardware and updates threat intelligence centrally, though it depends on internet connectivity to the resolver.
- Hybrid deployments keep a local resolver for latency-sensitive traffic while pushing category decisions and threat feeds from the cloud, giving IT teams more control over caching and outage behaviour.
- Fully in-network resolvers offer maximum control and data residency but put the update and maintenance burden on internal staff.
DNS filtering also slots naturally into a wider zero-trust architecture: identity-aware policies decide who gets which DNS rules, endpoint agents catch what DNS misses, and web proxies add page-level inspection where domain-level blocking isn’t precise enough. Layering these controls, rather than picking one, is what actually reduces risk.
Monitoring, reporting and reviewing your DNS filter
A filter installed and forgotten degrades fast. Category lists shift, new domains appear daily, and legitimate resources get miscategorised without anyone noticing until a teacher complains.
- Give designated safeguarding leads monthly access to blocked-domain reports and flagged search terms, not just annual summaries.
- Build a short incident workflow for wrongly blocked resources: report, verify, whitelist, communicate back to the requester within a set number of hours.
- Review category policies and log retention settings at least quarterly, with a fuller annual review tied to your safeguarding policy refresh.
The NSPCC’s guidance on online safety is explicit that regular review and clearly assigned roles matter as much as the technology itself. A brilliant filter with nobody checking its logs is barely better than no filter at all.
Re-Solution: managed deployments built for education compliance
Schools that want the outcomes above without carrying the day-to-day operational load tend to look for a managed route. As a Cisco partner with over 35 years in network infrastructure, Re-Solution builds DNS filtering into a wider managed security stack rather than treating it as a bolt-on.
- Policy templates mapped to DfE filtering and monitoring expectations from day one
- Identity integration so staff, pupil, and guest networks each get the right ruleset
- Network audits that surface gaps before an inspection does, not after
- Ongoing training and support so DSLs and IT staff can actually use the reporting they’re given
A typical engagement runs from an initial audit through policy design, phased rollout, and staff handover, giving schools a working filter and a team that knows how to keep it that way.
Author perspective: priorities for IT leads choosing DNS filtering
Most schools overthink category granularity and underthink stakeholder buy-in. The technical decision is rarely the hard part. Getting a DSL, a headteacher, and a network manager to agree on review cadence and override authority usually is.
Start with a small pilot, one building or year group, before rolling out estate-wide. Pair every technical control with staff training so filtering doesn’t become the thing teachers quietly resent.
— Jacob
How Re-Solution helps schools implement DNS filtering
Re-Solution is the practical alternative to piecing together DNS filtering, identity integration, and safeguarding reporting yourself across multiple vendors. Rather than juggling separate tools for category filtering, log retention, and DfE compliance checks, schools get one Cisco-based managed service that handles policy design, rollout, and ongoing review as a single engagement.
The process starts with a network audit that maps your current filtering gaps against the DfE core standard, moves into policy design tailored to your safeguarding structure, and finishes with staff training so your DSL team can read the reports without needing IT to translate them. Re-Solution’s Network as a Service model bundles ongoing DNS policy management into a single support contract, backed by managed IT services that cover the wider network estate.
If your school is weighing up a DIY DNS deployment against a managed one, the practical next step is a discovery conversation: get in touch to scope an IT infrastructure review and see what a compliant, education-ready deployment actually looks like for your estate.
Sources
- Meeting digital and technology standards in schools and colleges: filtering and monitoring core standard
- ‘PDNS for Schools’ to provide cyber resilience for more institutions | National Cyber Security Centre
- Online safety (e-safety) and schools | NSPCC Learning
FAQ
What website blockers do schools use?
UK schools typically use DNS-based filtering services, often paired with content-aware web proxies, to block categories such as adult content, gambling, and known malicious domains, with many now considering the free NCSC PDNS for Schools service as a baseline layer.
Should I turn on DNS filtering?
Yes. DNS filtering is a low-effort, high-value control that blocks risky domains before they load and helps meet the DfE filtering and monitoring standard, though it should sit alongside endpoint security rather than replace it.
What is DNS filtering and how does it work?
DNS filtering intercepts the domain name lookup that happens before a website loads and blocks or allows access based on category lists and threat intelligence, stopping malicious or inappropriate domains at the resolver stage rather than after the page has loaded.
What is the best DNS filter for schools?
There’s no single best option for every school. Eligible UK institutions should first check NCSC PDNS for Schools eligibility for a free protective layer, then weigh a managed deployment through a provider like Re-Solution if identity integration, reporting, and DfE-aligned policy design matter more than a self-managed setup.
Recommended
- Effective network access management for schools in 2026
- Educational IT solutions: a 2026 guide for schools
- How to plan network access for schools
- DfE Switching Standards & Cisco Meraki | Re-Solution UK







