Infoblox Threat Defense is a DNS-layer security platform from Infoblox that blocks threats before they reach endpoints, with agentless protection across hybrid, multi-cloud, remote, IoT and OT environments. Pricing is token-based and available by quote only.
Listing updated . Checked by MSP Software .
Infoblox Threat Defense is a protective DNS and threat defence solution from Infoblox for managed service providers protecting customer networks against DNS-based attacks and intrusions. The platform operates as a cloud-native security resolver that stops attacks at the DNS layer before malicious domains can be resolved, using behavioural analysis and machine learning to identify zero-day threats without requiring endpoint agents or firewall modifications.
The solution detects threats an average of 68 days earlier than competing tools, blocks approximately 90 percent of threats before the initial DNS query, and maintains a false positive rate of 0.0002 percent. Infoblox Threat Defense monitors over 204,000 active threat actor clusters and tracks 660 plus actors behind global malicious activity, using this comprehensive threat intelligence to power predictive protection across corporate systems, remote workers, IoT and operational technology environments. The platform includes lookalike domain monitoring to combat brand impersonation attacks and tracks phishing, ransomware, malware and domain generation algorithms across its extensive threat feeds.
Infoblox Threat Defense deploys as cloud-first management through the Security Workspace, with optional on-premises and hybrid configurations for organisations integrating with existing DNS infrastructure. The platform provides agentless visibility across all device types without requiring agents or firewalls, eliminating implementation barriers common with other security approaches. Multi-tenant capabilities support the MSP business model with per-site policy controls and centralised visibility across customer networks and per-customer threat activity logs. Pricing is token-based rather than per-user or per-endpoint, with Infoblox directing prospective customers to sales for customised quotes based on their security requirements and deployment scale. Infoblox is based in Chicago, United States, and has been part of Vista Equity Partners since 2016.
Infoblox Threat Defense stands out for agentless deployment and early threat detection at the DNS layer, which suits MSPs that want protection without endpoint software or firewall modifications. The token-based pricing model requires a sales conversation rather than self-service purchasing, which differs from competitors like Cisco Umbrella or Cloudflare Gateway that publish per-unit pricing. Before committing, check whether threat intelligence feeds cover your customer base geography and threat profile, and confirm integration availability with your existing RMM or security stack. The multi-tenant dashboard supports MSP operations but verify it covers your specific management and policy isolation needs.
| Feature | Supported | Note |
|---|---|---|
| DNS-layer blocking | yes | Blocks malicious domains at DNS layer, stops 90 percent of threats before query execution |
| Content category filtering | yes | Protective DNS with category-based filtering for phishing, ransomware, malware and DGAs |
| Roaming agent for off-network devices | yes | Agentless protection across remote, hybrid and multi-cloud environments without requiring endpoint agents |
| Secure web gateway | yes | Security Workspace integration provides gateway capabilities |
| Multi-tenant dashboard | yes | Multi-tenant management through Security Workspace for MSP operations |
| Per-site policy | yes | Cloud and on-premises hybrid deployment supports per-network policy control |
| RMM integration | unknown | Integration capability through ecosystem, specific RMM partners not documented on public pages |
| Threat intelligence feed | yes | Monitors 660 plus threat actors and 204,000 plus threat actor clusters with predictive intelligence |
| SafeSearch enforcement | unknown | Not explicitly mentioned in available documentation |
| Reporting and audit log | yes | Reporting and audit capabilities through Security Workspace |
| Custom block and allow lists | yes | Implied through security ecosystem integration and policy configuration capabilities |
| Network-wide router deployment | yes | Network-wide protective DNS resolver deployment across cloud, on-premises and hybrid infrastructure |
Infoblox Threat Defense operates at the DNS layer rather than the network perimeter, blocking malicious domains before they are resolved rather than filtering traffic after connection. This approach does not require endpoint agents or firewall modifications and works agentlessly across corporate systems, remote workers, IoT and OT environments. Infoblox Threat Defense detects threats an average of 68 days earlier than competing solutions by using predictive threat intelligence and behavioural analysis.
Infoblox Threat Defense deploys as cloud-first management through the Security Workspace, with optional on-premises and hybrid configurations. Organisations can integrate Infoblox Threat Defense with existing DNS infrastructure in hybrid environments, providing flexibility for organisations that need to split operations between cloud and on-premises deployments. The platform works agentlessly across all device types without requiring additional software installation on endpoints.
Infoblox Threat Defense uses token-based licensing rather than traditional per-user or per-endpoint pricing. Customers purchase token packs for a contract term and can adjust usage as needs change. Specific pricing is not published on the website; Infoblox directs prospective customers to contact sales for customised quotes based on their requirements. The token-based model allows capacity to be exceeded temporarily without penalties.
Yes, Infoblox Threat Defense includes multi-tenant management capabilities through the Security Workspace, allowing managed service providers to manage multiple customer environments from a single dashboard. This supports the MSP business model by providing per-site policy controls and centralised visibility across customer networks and threat activity.
Infoblox Threat Defense monitors over 660 threat actors and 204,000 active threat actor clusters to power its predictive threat intelligence. The platform blocks approximately 90 percent of threats before the initial DNS query, maintains a false positive rate of 0.0002 percent, and detects threats an average of 68 days earlier than competing tools. Threat intelligence includes lookalike domain monitoring to detect brand impersonation attacks.
Reviews are moderated. How reviews work.
Share what it is like to use this product day to day. Your experience helps other MSPs choose with confidence.
Write the first review