Recursive DNS resolution via global anycast network
Umbrella operates as a recursive DNS resolver that customers point their networks, devices, or roaming agents at instead of an internal or ISP resolver. Queries are answered by data centers distributed worldwide that share the same resolver IP addresses, so anycast routing sends each request to the nearest available site. This provides the name resolution itself while placing Umbrella in the path of every DNS lookup, and it removes dependence on any single data center because traffic shifts to another site if one becomes unreachable.
02
DNS-layer security blocking malware, ransomware, phishing, botnet, and C2 domains before connection
When a device asks Umbrella to resolve a name, the resolver checks the requested domain against categories of known-malicious destinations before returning an answer. Domains associated with malware distribution, ransomware, phishing pages, botnet infrastructure, and command-and-control callbacks are answered with a block response rather than the real address, so the connection is never established. Because enforcement happens at resolution time, the block applies to any application or port on the device, not only web browsing, and it stops the traffic before a TCP session or payload transfer begins.
03
Talos-powered threat intelligence with real-time domain/IP/URL reputation
Umbrella's blocking and categorization decisions draw on Cisco Talos threat research, which supplies reputation data for domains, IP addresses, and URLs. Reputation records are updated continuously so that destinations newly identified as malicious are enforced against without waiting for a scheduled feed update. The same intelligence backs the verdicts shown in reporting and investigation tools, so an analyst reviewing a blocked request can see the reputation basis for the decision.
04
Predictive threat detection using statistical models on DNS data (co-occurrence, spike detection, DGA detection)
Umbrella applies statistical analysis to the DNS request patterns it observes across its resolver population in order to identify malicious infrastructure that has not yet been reported. Co-occurrence models flag domains that are consistently requested alongside known-bad domains within short time windows. Spike detection identifies domains whose query volume rises abruptly in a pattern typical of a campaign launch, and domain generation algorithm detection flags names whose character composition matches algorithmically generated patterns used by malware to locate command-and-control servers. Domains surfaced by these models can be enforced against as threats.
05
Newly seen domains detection and blocking
Umbrella tracks when a domain was first observed being resolved on its network and treats recently registered or recently seen domains as a separate risk class. Because attacker infrastructure is frequently used within a short window of registration, administrators can enable enforcement that blocks requests to domains inside that newness window. The result is that a device requesting a domain nobody has resolved before receives a block response rather than the real address.
Your plan caps how many capabilities are shown — upgrade to see the full list