NextDNS vs DNSFilter / Why Multi Layered Security Matters
There are different approaches to security that can be taken, different layers, different viewpoints.
Some methods are simply better than others and with this I wanted to show how Multi Layered approach is a better way of dealing with Threats by comparing NextDNS to a Enterprise Competitior and how their different approaches yields different results in a quite frankly surprising way.
For this tests there are 15 domains mostly from today and a few are from yesterday. These are alive and malicious giving the DNS the necessary needs to analyze the domain on request (these have been tested and reported.) Here are the results.
In total out of the 15 domains, NextDNS catched 10 of the domains purely by the AI-Driven Threat Detection 14 being blocked by Threat Intelligence Feeds and 1 being blocked by NextDNS Ads & Trackers Blocklist and OISD. So in total all of them were catched, these aren't exactly 0 days and again have been reported but overall shows that if someone were to see these threats themselves they would have quite an amazing protection with the ability to fine tune using additional filters.
-----
Now for DNS Filter, it's a honestly more flashy service, their Page that shows a loading screen while the AI scan is going etc, yeah looks better. This is a service that seems more expensive and offers less features for their Basic plan compared to Pro and Enterprise. They don't list their pricing per client in terms of Enterprise so can't comment but let's get to the testing.
15 domains as before and all the functions that I could enable for security are enabled. I also double checked with their built in domain checking tool to make sure the results were the same with their preferred configuration.
9 were blocked and 6 were let through, this still isn't the worst but the problem is, when there aren't multiple layers, the 6 domains passed both their testing website and the urls loaded successfully.
-----
In total comparing the AI services of both NextDNS got 10 domains and DNSFilter got 9. Comparable.
But with NextDNS using multiple layers such as Feeds, Blocklists and AI it managed to get a complete score with overhead for additional filters that are more agressive to possibly give even more security with a more than usable state for Enterprise users that do far less random browsing that might lead to false positives.
-----
It's great to see as a NextDNS user but also shocking as both networks are comparable in terms of latency and worldwide reach. Yet the other allows some threats that are known and have been reported earlier today.
-----
This whole thing was Inspired thanks to Sohan Ray and DynamicNotSlow so thanks for the intial question and the curiosity that got me to do this.
18 replies
-
Awsme work! I hope more people read this so they are confident in what they are investing in. And also, NextDns people, as it feels good to be appreciated and it motivates them to do even better. Cheers!
-
Have you ever tried ControlD dns? Its a product of Windscribe VPN company. I wonder how it compares to NextDns....
-
Transitioning back to NextDNS from DNSFilter. DNSFilter is expensive with monthly minimums (i.e., pro plan is $2 per user with a $50/mo minimum). However, I do love its reporting abilities, domain name lookup tools, etc.
Really wish NextDNS would release updates that allowed a lot of things that DNSFilter offers. I would be willing to pay more for it if they did.
Content aside
-
2
Likes
- 2 mths agoLast active
- 18Replies
- 1484Views
-
4
Following