Control D
Encrypted DNS filtering for teams across desktop and mobile devices.
Control D is a DNS filtering service for blocking malware, trackers, unwanted content, and specific apps or services across managed devices and networks. It supports encrypted DNS protocols, native clients for major operating systems, policy management, logs, analytics, SIEM streaming, and multi-tenant administration for IT teams and MSPs.
Why it stands out
- Native client coverage spans all major desktop and mobile operating systems rather than focusing mainly on Windows.
- Per-endpoint pricing is presented without minimums or annual lock-in, which can suit smaller teams and MSP client rollouts.
- Includes API access and SIEM streaming on every plan, not only higher enterprise tiers.
- Supports modern encrypted DNS protocols by default, including newer options such as DNS-over-QUIC.
- Built-in traffic redirection can handle some access-routing workflows that would otherwise require a VPN.
Good to know
- Query logs are listed as retained for 30 days, so longer forensic lookbacks may require exporting or streaming data elsewhere.
- Costs scale by endpoint count, which matters for large fleets or MSPs with many protected devices.
- The on-page cost calculator is an estimate based on public pricing and market data, not a formal quote.
- Complex migrations or multi-client deployments may still need rollout planning rather than a fully self-serve switch.
Under the radar: If you are evaluating it against a VPN-based access setup, look specifically at the traffic redirection feature; the customer examples suggest it can replace some internal routing use cases without deploying a VPN.
Photos

IT and security teams managing mixed Mac, Windows, Linux, iOS, and Android fleets can enforce one DNS policy across endpoints. Roll out malware and content filtering without installing an agent on every device when network-level DNS deployment is enough. Give MSP clients separated DNS policies, reporting, and administration from one dashboard. Stream DNS activity into a SIEM for security monitoring and audit evidence. Replace or compare an existing DNS security provider using endpoint-based pricing estimates.
Malware, tracker, web, content, app/service, and custom DNS filtering; support for DNS-over-HTTPS/3, DNS-over-TLS, DNS-over-QUIC, and legacy DNS; native clients for macOS, Windows, Linux, iOS, and Android; multi-tenant dashboard; query logs, analytics, admin logs, traffic redirection, API access, CLI support, and SIEM data streaming.
Technical Notes
- Public API documentation is linked from the site, and the page says API access is included on every plan.
- SIEM data streaming is available on every plan for structured DNS/security event ingestion.
- The site also mentions CLI support for MSP and administrative workflows.
Alternative listings
An open-source blocker for ads, trackers, and cookie pop-ups.
Privacy & security tools / big-tech alternativesGhostery provides privacy-focused browser tools that block ads, limit tracking scripts, and automate rejection of many tracking cookies. Its broader site also includes WhoTracks.Me tracker reports and a privacy-news digest, giving users more visibility into the companies collecting data across the web.
0 votesVisit siteNetwork-level ad and tracker blocking with customizable DNS rules.
Privacy & security tools / big-tech alternativesAdGuard DNS is a cloud DNS service that filters requests before they reach websites or apps, blocking known advertising, tracking, phishing, malware, and adult-content domains depending on the mode you choose. It can be used as a public DNS resolver or managed through a dashboard for device-level rules, request statistics, and custom allow/block lists.
0 votesVisit site
Similar sites elsewhere
- NextDNS — nextdns.io
- DNSFilter — dnsfilter.com
- Cloudflare Zero Trust — cloudflare.com
- Cisco Umbrella — umbrella.cisco.com
1 of 5