8 layers of DNS protection

Enterprise security. Zero installation.

Everything runs at the DNS layer — before threats reach your devices.

Threat Intelligence

1.5 million malicious domains blocked in real-time

We aggregate 18 threat feeds — URLhaus, ThreatFox, Feodo Tracker, Spamhaus, OpenPhish, PhishTank, StevenBlack, AdGuard, HaGeZi Pro, and OISD Big among them. The combined blocklist updates every 5 minutes. Every DNS query is checked in microseconds, and malicious domains are stopped before a single packet reaches your network.

How threat blocking works →
DGA Detection

Catches malware that hides from blocklists

Domain Generation Algorithms let malware create thousands of random domains to evade static blocklists. Escudo runs Shannon entropy analysis, character-pattern scoring, and suspicious TLD detection on every query. If a domain looks machine-generated, we block it — even if no threat feed has seen it yet.

ENTROPY ANALYSIS google.com 2.1 bits PASS amazon.co.uk 2.8 bits PASS xk9m2v7q.xyz 4.7 bits BLOCK j3kf8wd2p.top 4.9 bits BLOCK LOW MED HIGH
Fraud Detection

Regional banking fraud protection

Escudo detects fraudulent domains targeting financial institutions using Levenshtein-distance typosquat detection, keyword scoring, and suspicious TLD flagging. If someone registers a lookalike domain to steal banking credentials, we block it at the DNS layer before the page loads. Covers 20+ institutions with region-specific detection rules.

Learn more →
BANK Transferencia bancodobrasii.com Levenshtein: 1 · BLOCKED bb.com.br Official · ALLOWED Itau Bradesco Nubank Caixa Inter C6
Parental Controls

Protect kids without touching their devices

Block adult content, gambling, social media, gaming, and more — across every device on your network. Seven category groups let you choose what gets through. Set time-based schedules so homework hours stay focused. Changes propagate to DNS in under a second, and a PIN lock prevents kids from disabling protection.

Parental Controls OFF Adult Content OFF Gambling ON Social Media ON Gaming Schedule 08:00-15:00 strict 15:00-21:00 moderate 21:00-08:00 blocked PIN: **** 7 categories · Instant propagation · PIN-locked
Identity Protection

Find out if your data has been leaked

Escudo checks your email addresses against the Have I Been Pwned database — covering over 700 breaches and billions of compromised records. 60% of users find a leak in their first week. After the initial scan, daily auto-checks run quietly in the background. When a new breach surfaces, you get notified before criminals can use your data.

Breach Monitor 3 Breaches 2 Pastes 700+ Databases LinkedIn (2024) email, password hash, name Adobe (2023) email, encrypted password Pastebin (2024) email found in public paste Daily auto-check enabled · Next: 06:00 UTC
Device Intelligence

See every device on your network

Most people have no idea what is connected to their network. Escudo identifies every device using 127 passive DNS fingerprinting rules — no port scanning, no agents, no traffic disruption. Smart TVs, IoT sensors, security cameras, game consoles: each one appears in your dashboard with a device type, OS guess, and query history.

DNS MacBook macOS 15 iPhone iOS 19 Samsung TV Tizen 8 Ring Cam IoT PS5 Gaming HP Printer IoT 127 rules
Forensic Evidence

Legal-grade proof of every DNS event

Every query is logged with SHA-256 hashing, hourly integrity checkpoints, and daily Merkle-tree verification. Export logs as JSON or CSV for compliance audits, insurance claims, or law enforcement. Fully aligned with LGPD and NIS2 requirements. When you need to prove what happened and when, the evidence is already there.

forensic_log.json {"ts":"2026-04-03T14:22:01Z", "query":"malware-c2.xyz", "action":"BLOCKED", "reason":"threatfox_feed", "sha256":"a3f8c9..."} Daily Merkle Tree root: 7f2a... h0: c4e1... h1: 9b3d... LGPD NIS2 SHA-256
Infrastructure

Sao Paulo + Frankfurt. Sub-5ms.

Two DNS nodes on separate providers in separate continents. Sao Paulo covers the Americas. Frankfurt covers Europe, Africa, and Asia. Both run the same Rust binary with identical rulesets. If one node goes down, the other takes over automatically. Average resolution time: under 5 milliseconds. No single point of failure.

Sao Paulo 216.238.116.9 Frankfurt 46.224.13.50 failover Americas <3ms EU/Asia <5ms

Protect your network in 2 minutes

Change your DNS settings. Every device is protected. No software to install, no agents to manage.