INFRA Signal 142
Introducing DNS filtering by Control D
Tailscale customers can now buy DNS filtering from Control D and apply it through tailnet ACLs with per-group or per-device rules billed per user.
It removes the need for a separate procurement process by letting Tailscale handle billing and provisioning. Encrypted DNS queries are sent to Control D, applying filtering rules defined in its dashboard or API. Teams gain centralized control over malicious, phishing, or unwanted destinations without leaving the Tailscale admin console.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
DNS filtering is added as a nameserver in the Tailscale admin console and linked to Control D rules via ACL mappings.
Control D provides threat-feed based blocking, category filtering, and custom rule creation for domains and apps.
Billing is based on the number of users needing filtering, eliminating the need to count devices or serverless nodes.
THE READ
What the cluster adds up to.
Tailscale announced that its customers can purchase DNS filtering directly from Control D through the Tailscale sales team. The service integrates with the tailnet by adding Control D as a nameserver in the admin console. Users map groups, tags, or devices to Control D rules via Tailscale ACLs. This creates a unified way to apply DNS policies inside the private network.
After adding Control D as a nameserver, administrators open the Control D dashboard to select or create a filtering rule. The chosen rule is then referenced in a Tailscale ACL that maps users, groups, or devices to that rule. Devices send DNS queries over encrypted DNS to Control D, which applies the selected filtering ruleset. Because Tailscale handles billing, there is no separate purchasing or contract negotiation needed.
Control D combines threat feeds, malicious domain and IP detection, and machine learning to block malware and phishing. It offers category-based filtering, a maintained list of services and apps, and the ability to write custom allow, block, or redirect rules. The service is described as fast and reliable, with low latency observed in testing. Users continue to manage rules through the Control D dashboard or API while Tailscale handles the network integration.
Tailscale bills customers based on the number of users requiring DNS filtering, avoiding the need to estimate devices or serverless nodes. The filtering applies to any device that uses the tailnet’s DNS resolution, including laptops, phones, and servers. If a device resolves DNS outside the tailnet (e.g., using external resolvers), the Control D filtering will not be enforced. Organizations that need network-level filtering beyond DNS (such as IP-based blocking) must supplement this solution with other tools.
Written by elseif from the cluster below · checked for specifics the sources never containedTHE CLUSTER
↗