Prevent threats from reaching their target, and keep unwanted destinations off-limits, at the DNS layer, before a single packet reaches a malicious server. Agentless coverage for the unmanaged, IoT/OT, and BYOD devices the rest of your stack can’t reach.

Every connection a device makes begins with a question: Where is this domain? The answer comes back with no questions asked. DNS was built to translate names into addresses, nothing more. It will resolve a phishing site as faithfully as it resolves your payroll system.
That's the gap. And it's the earliest point to close it. The Island Secure DNS Resolver enforces policy at that first hop, and stops malicious and unwanted traffic before a connection is ever established, with no software on the device.
Traditional DNS does exactly one job: it turns evil-phish-site.com into an IP address. It has no opinion about where that address leads. A user clicking a lookalike link, a compromised process reaching for its command-and-control server, a piece of malware phoning home: DNS answers all of them, instantly and identically. By the time a firewall or proxy sees the traffic, the connection is already forming.
Meanwhile, the hardest devices to protect are the ones that can't run software at all. Guest laptops, contractor machines, printers, cameras, badge readers, and medical and industrial equipment: none of them will ever take an agent. But every one of them still asks the same first question, over and over. That question is the control point almost everyone leaves open.
The Island Secure DNS Resolver inspects and controls DNS queries, the very first step a device takes to reach any destination, and enforces policy at the resolver level. Because the decision happens before the connection is established, the resolver stops malicious and unwanted traffic at the earliest possible point: no TCP handshake, no data exchange, no packet to the bad server, and no software on the device.
It is agentless by design. Point a network (or a single device) at Island's resolver, and the resolver classifies every query the device makes, then answers or blocks it before a connection is ever opened.

With one policy, the resolver:
The model rests on one fact: the lookup happens first. The query for evil-phish-site.com travels to Island's resolver instead of a public one, over standard DNS on a forwarded network, or encrypted as DNS-over-HTTPS (DoH) on a device. There, Island matches it against threat and category data and scores it with AI in real time. If policy blocks it, the resolver returns a block page instead of the real IP, so the connection is never established; if it's allowed, the genuine record comes back.
Because the resolver decides at resolution time, before any content is fetched, a malicious server never receives a packet from your users, and nothing installs on the device to make it happen.

Instead of running on the endpoint, every DNS query goes to Island's secure resolver, which classifies it and either answers or blocks it before the device ever opens a connection. There are two ways to send it there.
Network forwarding. Point a site's router or DHCP-issued DNS at the resolver IP addresses. Every device behind that network inherits the policy, with no per-device configuration and no software to install. Ideal for guest Wi-Fi, retail, and IoT/OT segments. Coverage follows the site's public IP, so roaming devices need Island Desktop or per-device DoH instead.
DNS-over-HTTPS (DoH). Apply the profile's DoH URL directly on a supported device or browser. Useful where you want a specific device, not the whole network, on the profile.
The resolver runs on a global Anycast network, so every query routes to the nearest available node automatically, no manual region configuration needed. Median response time worldwide sits under 30 milliseconds, and if a node goes offline, automatic failover reroutes traffic so there's no single point of failure.

This is where enforcing at the resolver earns its keep. A printer, a PLC on a factory floor, a smart TV in a conference room, a contractor's personal laptop: none of them will ever run an endpoint agent, and none of them belong on your managed fleet. What they all do is make DNS queries. Forward a segment's DNS to the Island resolver and every device behind it inherits the same threat and acceptable-use policy in one move: no imaging, no provisioning, no touch on hardware IT doesn't control.
But the same DNS filtering isn't only for the unmanaged edge. It also runs on your managed fleet through the agent-based path, and the two are built to work together:
Same policy engine, 50+ categories, same real-time classification, whether the device runs Island Desktop or nothing at all. The agentless resolver closes the blind spots agents can't reach; Island Desktop extends identical enforcement to the endpoints that can, on and off the network. Together they leave no device uncovered.

The Secure DNS Resolver isn't a standalone box. It's the pre-connect layer of the Island Enterprise Network, running on the same policy fabric as Secure Web Gateway, Private Access, and the rest of the platform. DNS filtering closes the gap at the query, the earliest point in the stack, and the browser and endpoint carry that same policy through everything that follows. One console, one policy engine, one audit trail, from the first lookup to the last click.
The result is coverage with no gaps: agentless at the resolver for the devices that can't run software, and agent-based through Island Desktop and the Enterprise Browser for the ones that can, all under a single set of rules.
Security spends most of its energy on what happens after a connection opens. The DNS query happens before all of it, and it's the one thing every device does, managed or not, agent or no agent. Deciding there means the resolver stops threats before a packet is ever sent, covers unmanaged and IoT/OT devices without touching them, and enforces acceptable use with a single rule.
One profile in. The addresses to point at, out. Everything it protects, protected before it ever connects.