Trois-Rivières, serving all of Quebec 450 231-3836 info@oktosolutions.ca
FR

DNS filtering for SMBs in Quebec: blocking malicious sites

Portrait of Antonio Pazzi, president of OKTO Solutions

By ·

President of OKTO Solutions · 6 minute read

An employee gets an email that looks like it came from a supplier. He clicks the link. In a split second, his browser tries to open a booby-trapped site built to steal his passwords. With no protection, the page loads and the damage is done. With DNS filtering, the connection is cut before the page ever appears on screen.

It is one of the simplest security layers to put in place in a small business, and one of the most cost-effective. In Trois-Rivières as everywhere in the Mauricie, small businesses get targeted just as much as large ones, often because they have fewer defences. Here is how DNS filtering works, what it really blocks and how to turn it on at your place.

Quick answer: DNS filtering acts like a guard post at the entrance to the internet. Every time a device tries to reach a site, the request goes through a service that checks the domain’s reputation and blocks the malicious ones (phishing, ransomware, fraudulent sites) before the page can load.

1. DNS filtering explained simply

DNS is the phone book of the internet. When you type an address such as oktosolutions.ca, your device first asks a DNS server to translate that name into a numeric address, a bit like looking up a phone number in a directory before you call. This step happens hundreds of times a day on every workstation, and nobody ever notices.

DNS filtering slots in at exactly that moment. Instead of using an ordinary directory, your devices use a filtering service that keeps an up-to-date list of dangerous domains. When a workstation asks for the address of a site known to host a virus or a fake sign-in page, the service simply answers no. The page never opens. It is fast, quiet, and it works on every device that goes through that server, phones as well as computers.

The advantage for a small business is that there is nothing to install on each workstation. You change one network setting, often at the router or through a small application, and the protection applies to everyone at once.

2. Why small businesses in the Mauricie are targeted

Plenty of owners still think a small business in Trois-Rivières holds no interest for hackers. The opposite is true. Attacks are automated: bots send out millions of emails and look for the easiest door to open. A small business with no filtering, no two-factor authentication and no trained staff is exactly that easy door.

The Canadian Centre for Cyber Security points out that phishing remains one of the most common ways to compromise an organization, whatever its size. DNS filtering does not replace employee vigilance, but it catches human error before it gets expensive. When someone clicks a bad link on reflex, the block happens on its own.

This is the kind of protection we build into most of our engagements. You can see our whole approach on our managed IT services page, where network security is part of the package rather than an option added after an incident.

DNS filtering for small businesses, threat monitoring on security screens

3. What DNS filtering blocks day to day

A good DNS filtering service handles several kinds of threats at the same time. Here is what it intercepts most often in a small business:

  • Phishing sites that imitate Microsoft 365, a bank or a supplier to steal credentials.
  • Domains that distribute ransomware and malware.
  • Command servers used by a virus already on the machine to talk to the attackers.
  • Fraudulent sites and fake stores created only hours earlier.
  • Depending on your needs, certain non-work categories such as gambling or inappropriate content.

The strength of DNS filtering is that it acts early in the attack chain. Even if malware manages to run on a workstation, it usually needs to reach an outside server to get its instructions or send off your data. If that domain is blocked, the attack runs on empty. It is a second chance that has already saved plenty of businesses from a full-blown leak.

4. DNS filtering and phishing: the first line of defence

Phishing is still the number one threat for Quebec small businesses. A fake email, a fake text message, a fake sign-in page, and an employee’s credentials end up in the wrong hands. Once inside a Microsoft 365 mailbox, an attacker can read your email, divert your invoices and pass for you with your clients.

DNS filtering cuts off access to the fake page before the employee types in a password. Combined with two-factor authentication, that makes for a solid defence. Microsoft explains how those layers complement each other in its documentation on anti-phishing protection. The idea is not to rely on a single tool, but to stack several barriers so one mistake does not turn into a disaster.

DNS filtering and phishing protection for small businesses in Quebec

5. How to turn on DNS filtering in your business

Setting up DNS filtering is no big project. Here are the main steps an IT provider usually follows:

  • Choose a reputable filtering service, one that can cover workstations at the office as well as employees working from home.
  • Redirect the company’s DNS requests to that service, at the router or through a small agent installed on mobile devices.
  • Configure the categories to block based on your reality, without getting in the way of the tools you need to work.
  • Test with a few workstations before deploying everywhere, so you do not block a legitimate site by mistake.
  • Watch the reports to spot blocked attempts and adjust the rules over time.

A small business can do this on its own if it has the skills in-house. Most prefer to hand it to a partner who also handles monitoring and updates. If you want to know what would suit your network, write to us through our contact page and we will look at your situation together.

6. DNS filtering or firewall: not the same thing

The two often get confused, but they do not play the same role. The firewall controls what traffic enters and leaves your network according to technical rules (ports, protocols, addresses). DNS filtering decides which domain names your devices are allowed to reach. One watches the pipes, the other checks the destinations.

The two complement each other. A firewall does not always know that a domain created this morning is being used for phishing, whereas a DNS filtering service updates its list continuously. In a well-protected small business you find both, plus a modern antivirus and two-factor authentication. No single tool is enough, it is the combination that makes an attack far harder.

DNS filtering and firewall monitored across every device in a small business

Frequently asked questions

Does DNS filtering slow down browsing?

No, quite the opposite: a good filtering service often answers faster than an ordinary DNS server. The check takes a few milliseconds, and the user notices no difference on screen.

Does DNS filtering replace antivirus?

No. It blocks access to dangerous domains, but it does not clean up a file already sitting on a workstation. Think of it as a layer that adds to antivirus and two-factor authentication, not as a replacement.

Does DNS filtering protect employees working from home?

Yes, as long as you install a small agent on mobile devices or use a service designed for that. The protection then follows the employee, whether they are at the Trois-Rivières office or at home.

Protect your network with a partner in the Mauricie

DNS filtering is one of the fastest ways to cut risk in a small business, but it delivers its full effect as part of a complete strategy. At OKTO Solutions in Trois-Rivières, we build this protection into our managed IT services and we monitor your network day to day. To talk about your situation and get a clear picture of your weak spots, go through our contact page and we will get back to you quickly.

An article sets out the principle. Putting it in place happens one workstation at a time: our managed cybersecurity service, backup and disaster recovery and our IT services in Montreal.

A question on this subject, for your own company?

An article explains the principle. A twenty minute call tells you what it changes at your place, with your systems and your constraints.