Infoblox Threat Defense logo

Infoblox Threat Defense

Infoblox Threat Defense is a DNS-layer security platform from Infoblox that blocks threats before they reach endpoints, with agentless protection across hybrid, multi-cloud, remote, IoT and OT environments. Pricing is token-based and available by quote only.

Listing updated . Checked by MSP Software .

From the vendor

Infoblox Threat Defense is a protective DNS and threat defence solution from Infoblox for managed service providers protecting customer networks against DNS-based attacks and intrusions. The platform operates as a cloud-native security resolver that stops attacks at the DNS layer before malicious domains can be resolved, using behavioural analysis and machine learning to identify zero-day threats without requiring endpoint agents or firewall modifications.

The solution detects threats an average of 68 days earlier than competing tools, blocks approximately 90 percent of threats before the initial DNS query, and maintains a false positive rate of 0.0002 percent. Infoblox Threat Defense monitors over 204,000 active threat actor clusters and tracks 660 plus actors behind global malicious activity, using this comprehensive threat intelligence to power predictive protection across corporate systems, remote workers, IoT and operational technology environments. The platform includes lookalike domain monitoring to combat brand impersonation attacks and tracks phishing, ransomware, malware and domain generation algorithms across its extensive threat feeds.

Infoblox Threat Defense deploys as cloud-first management through the Security Workspace, with optional on-premises and hybrid configurations for organisations integrating with existing DNS infrastructure. The platform provides agentless visibility across all device types without requiring agents or firewalls, eliminating implementation barriers common with other security approaches. Multi-tenant capabilities support the MSP business model with per-site policy controls and centralised visibility across customer networks and per-customer threat activity logs. Pricing is token-based rather than per-user or per-endpoint, with Infoblox directing prospective customers to sales for customised quotes based on their security requirements and deployment scale. Infoblox is based in Chicago, United States, and has been part of Vista Equity Partners since 2016.

Our take

Infoblox Threat Defense stands out for agentless deployment and early threat detection at the DNS layer, which suits MSPs that want protection without endpoint software or firewall modifications. The token-based pricing model requires a sales conversation rather than self-service purchasing, which differs from competitors like Cisco Umbrella or Cloudflare Gateway that publish per-unit pricing. Before committing, check whether threat intelligence feeds cover your customer base geography and threat profile, and confirm integration availability with your existing RMM or security stack. The multi-tenant dashboard supports MSP operations but verify it covers your specific management and policy isolation needs.

Read the DNS and web filtering buying guide

How this listing is researched

Alternatives in DNS and web filtering

All DNS and web filtering software
Cisco Umbrella Cloud DNS filtering and secure web gateway for multi-site networks and roaming users. No reviews yet Cloudflare Gateway DNS and web gateway filtering via Cloudflare's global edge network, with policy-based access control. No reviews yet DefensX Browser security with AI protection and DNS filtering for MSPs, quote-only pricing with flexible tiers. No reviews yet DNSFilter AI-powered DNS filtering and threat blocking for networks and roaming devices. No reviews yet · from US$1.00 All alternatives to Infoblox Threat Defense

Features

DNS and web filtering features
FeatureSupportedNote
DNS-layer blockingyesBlocks malicious domains at DNS layer, stops 90 percent of threats before query execution
Content category filteringyesProtective DNS with category-based filtering for phishing, ransomware, malware and DGAs
Roaming agent for off-network devicesyesAgentless protection across remote, hybrid and multi-cloud environments without requiring endpoint agents
Secure web gatewayyesSecurity Workspace integration provides gateway capabilities
Multi-tenant dashboardyesMulti-tenant management through Security Workspace for MSP operations
Per-site policyyesCloud and on-premises hybrid deployment supports per-network policy control
RMM integrationunknownIntegration capability through ecosystem, specific RMM partners not documented on public pages
Threat intelligence feedyesMonitors 660 plus threat actors and 204,000 plus threat actor clusters with predictive intelligence
SafeSearch enforcementunknownNot explicitly mentioned in available documentation
Reporting and audit logyesReporting and audit capabilities through Security Workspace
Custom block and allow listsyesImplied through security ecosystem integration and policy configuration capabilities
Network-wide router deploymentyesNetwork-wide protective DNS resolver deployment across cloud, on-premises and hybrid infrastructure

FAQ

How much does Infoblox Threat Defense cost?
Infoblox Threat Defense does not publish a list price. No MSP price reports have been approved yet.
Does Infoblox Threat Defense offer a free trial?
There is no free version.
What does Infoblox Threat Defense integrate with?
Infoblox Threat Defense lists integrations with Infoblox DDI, Microsoft 365 and Defender and Infoblox Partner Ecosystem.
Is Infoblox Threat Defense cloud or on-premises?
Infoblox Threat Defense can be run in the cloud or on-premises. Infoblox Threat Defense supports a hybrid deployment.
Who is Infoblox Threat Defense for?
MSPs report using Infoblox Threat Defense at sizes of 6-15, 16-50, 51-200 and 200+ technicians.
How does Infoblox Threat Defense differ from network-based firewalls?

Infoblox Threat Defense operates at the DNS layer rather than the network perimeter, blocking malicious domains before they are resolved rather than filtering traffic after connection. This approach does not require endpoint agents or firewall modifications and works agentlessly across corporate systems, remote workers, IoT and OT environments. Infoblox Threat Defense detects threats an average of 68 days earlier than competing solutions by using predictive threat intelligence and behavioural analysis.

What deployment options does Infoblox Threat Defense support?

Infoblox Threat Defense deploys as cloud-first management through the Security Workspace, with optional on-premises and hybrid configurations. Organisations can integrate Infoblox Threat Defense with existing DNS infrastructure in hybrid environments, providing flexibility for organisations that need to split operations between cloud and on-premises deployments. The platform works agentlessly across all device types without requiring additional software installation on endpoints.

How is Infoblox Threat Defense priced?

Infoblox Threat Defense uses token-based licensing rather than traditional per-user or per-endpoint pricing. Customers purchase token packs for a contract term and can adjust usage as needs change. Specific pricing is not published on the website; Infoblox directs prospective customers to contact sales for customised quotes based on their requirements. The token-based model allows capacity to be exceeded temporarily without penalties.

Does Infoblox Threat Defense support multi-tenant management for MSPs?

Yes, Infoblox Threat Defense includes multi-tenant management capabilities through the Security Workspace, allowing managed service providers to manage multiple customer environments from a single dashboard. This supports the MSP business model by providing per-site policy controls and centralised visibility across customer networks and threat activity.

What threat intelligence does Infoblox Threat Defense provide?

Infoblox Threat Defense monitors over 660 threat actors and 204,000 active threat actor clusters to power its predictive threat intelligence. The platform blocks approximately 90 percent of threats before the initial DNS query, maintains a false positive rate of 0.0002 percent, and detects threats an average of 68 days earlier than competing tools. Threat intelligence includes lookalike domain monitoring to detect brand impersonation attacks.

Infoblox Threat Defense reviews

Reviews are moderated. How reviews work.

Be the first MSP to review Infoblox Threat Defense

Share what it is like to use this product day to day. Your experience helps other MSPs choose with confidence.

Write the first review

Sign in or create an account

Use your work email to review tools, share pricing and manage your vendor profile.

By continuing, you agree to our terms and acknowledge our privacy policy.