Blog|productAugust 28, 2026

Introducing DNS filtering by Control D

Author

Kabir SikandKabir Sikand
Two app icons on a purple background: a dark grid icon with nine circles (center white circle highlighted) connected by five lavender dots to a black icon with a four-petal flower shape in white.

Tailscale customers can now purchase DNS filtering by Control D from the Tailscale sales team. Control D’s DNS filtering solution integrates directly into your tailnet with per-group or per-device controls.

Teams that want to block malicious, phishing, or unwanted destinations can set up DNS filtering rules in Control D and apply those rules to any groups, tags, or devices in their tailnet with a simple access control list (ACL) integration. And starting today, you don’t have to go through another procurement process to do so.

Tailscale dashboard showing a Create Rule dialog for blocking domains. The form displays gambling.com as the domain to block, United States as the source location, Block action to prevent domain resolution, Root Folder selection, and a comment field with 64 characters remaining. A cyan Create button is positioned at the bottom of the modal.

How it works

Add Control D as a nameserver in the Tailscale admin console, and head over to your Control D dashboard to find a default security rule (or create a custom rule). In your Tailscale ACL, map the users, groups, or devices to the Control D rule. Your devices will then send DNS queries through Control D over encrypted DNS, applying the filtering ruleset you’ve just set up.

{
  "nodeAttrs": [
    {
      "target": ["group:employees"],
      "attr": [
        "controld:o13v9z7zns",
      ],
    },
  ],
}

Tailscale will bill you for the number of users you need DNS filtering for. No need to predict how many devices, serverless nodes, or other infrastructure you’re going to have. Just let us know the size of your organization, and we’ll send you a simple user-based bill at the end of the month.

You still manage DNS filtering rules inside Control D, whether through the Dashboard or API.

Tailscale control dashboard showing Profiles page with four profile collections: Family Profile with 11 filters and 11 services, Secure with 0 filters and services, Server with 0 filters and services, and Tailscale Default with 7 filters, 35 services, and 117 rules. Left sidebar contains navigation for Profiles, Endpoints, Analytics, and Preferences.

Why Control D?

Control D is one of the fastest and most reliable DNS filtering services we’ve tried out (under 7 ms in North America). We already have customers using their service, and when we met the team behind Control D, we knew they were onto something great.

Control D blends threat feeds, malicious domain and IP detection, and machine learning to block malware, phishing, and suspicious domains. It’s consistently ranked as one of the top DNS malware blockers. Control D lets you filter by content categories, choose from a maintained list of over 1,000 services and apps, and write custom rules to block, allow, or redirect anything else. It gives you the same kind of straightforward control over the public Internet that Tailscale gives you inside your tailnet. Filter by recognizable domains and write custom rules to block, allow, redirect, or reroute traffic using Control D managed domain lists.

To purchase DNS Filtering by Control D, come have a chat with us.

Share
Loading...

Try Tailscale for free

Schedule a demo
Contact sales
cta phone
mercury
instacrt
Retool
duolingo