# OpenText Core DNS Protection

> DNS-layer threat blocking with agent-based enforcement for remote and hybrid endpoints.

OpenText Core DNS Protection is a DNS-layer security solution for managed endpoints, blocking malicious domains and command-and-control servers before connection. It combines agent-level DNS filtering with process-level enforcement for hybrid and remote workers, with pricing available on quote. Listing updated 6 September 2026. Checked by MSP Software 6 September 2026.

- Page: https://mspsoftware.net/software/webroot-dns-protection
- Vendor: OpenText, https://mspsoftware.net/vendors/webroot, website https://cybersecurity.opentext.com/products/threat-detection/dns-protection/
- Categories: DNS and web filtering (primary)
- Free version: no.
- Deployment: cloud. Platforms: Windows, macOS and Linux. HQ: United States. Founded: 1997.
- Support: email and knowledge base. Training: documentation.

## From the vendor

OpenText Core DNS Protection is a cloud-native DNS filtering solution from OpenText Cybersecurity (formerly Webroot), designed for managed service providers protecting hybrid and remote workforces. The solution blocks malicious domains, ransomware, phishing attacks and command-and-control servers at the DNS layer, preventing both initial infection and data exfiltration before users reach compromised sites. Unlike traditional network-based DNS filtering, it uses agent-level enforcement with dynamic DNS server detection to block unauthorized DNS resolution at the process level, preventing sophisticated bypass attempts including encrypted DNS traffic such as DNS-over-HTTPS and DNS-over-TLS. This approach suits MSPs whose clients work from multiple locations and need endpoint-level protection rather than relying solely on network perimeter controls. The product deploys quickly across Windows, macOS and Linux endpoints without requiring specialized network infrastructure or user disruption. OpenText Core DNS Protection integrates with major MSP platforms including ConnectWise Manage, Autotask, HaloPSA and Syncro for centralized policy management and multi-tenant administration across client networks. It delivers real-time threat detection with comprehensive audit logging and centralized policy enforcement across all endpoints, supporting MSPs managing multiple client sites with varying security requirements and compliance postures. The solution tracks DNS requests at the process level, identifying which applications attempt to reach malicious domains and enabling granular policy decisions. OpenText remains headquartered in the United States through its Cybersecurity division, gaining integration with OpenText's broader endpoint protection and compliance portfolio. Pricing is available on quote only (checked September 2026), typically based on endpoint or user count. Before purchasing, MSPs should confirm RMM and PSA integration with their specific tools, evaluate whether per-endpoint or per-user pricing aligns with their billing model, and verify that DNS-over-HTTPS enforcement suits their clients' application environments.

## Our take

OpenText Core DNS Protection stands out for process-level DNS enforcement and support for encrypted DNS traffic, which blocks more sophisticated bypass attempts than traditional DNS filters. It suits MSPs protecting distributed workforces and those needing per-endpoint control rather than network-wide filtering alone. Because it's now part of OpenText and integrates with major MSP PSAs and RMMs, check that your stack is on the current integration list. Compare the agent-based model against network-wide DNS filtering solutions like Cloudflare Gateway or Cisco Umbrella if your clients prefer simpler, non-agent deployment. Confirm whether pricing is per endpoint, per user or flat-fee before evaluating against per-site alternatives.

## Pricing

OpenText Core DNS Protection does not publish a list price.

## Features

| Feature | Supported | Note |
| --- | --- | --- |
| DNS-layer blocking | yes | Blocks malicious domains and command-and-control servers at DNS layer |
| Roaming agent for off-network devices | yes | Agent-based enforcement with dynamic DNS detection for remote and hybrid workers |
| Secure web gateway | no | DNS filtering only, not a full web gateway |
| Multi-tenant dashboard | yes | Centralized policy enforcement across multiple client sites |
| Per-site policy | yes | Supports varying security requirements per client network |
| RMM integration | yes | Integrates with ConnectWise, Autotask, HaloPSA, Syncro and other MSP platforms |
| Threat intelligence feed | yes | Dynamic threat detection of malicious domains and ransomware |
| Reporting and audit log | yes | Comprehensive audit logging and centralized reporting |
| Custom block and allow lists | yes | Process-level enforcement enables custom DNS resolution rules |
| Network-wide router deployment | yes | Cloud-native agent deployment across all endpoint operating systems |

## Integrations

- ConnectWise Manage, https://mspsoftware.net/software/connectwise-psa
- Autotask, https://mspsoftware.net/software/autotask
- HaloPSA, https://mspsoftware.net/software/halopsa
- Syncro, https://mspsoftware.net/software/syncro
- Rewst, https://mspsoftware.net/software/rewst
- Kaseya BMS, https://mspsoftware.net/software/kaseya-bms

## Alternatives

- DNSFilter: AI-powered DNS filtering and threat blocking for networks and roaming devices. https://mspsoftware.net/software/dnsfilter. Compare: https://mspsoftware.net/compare/dnsfilter-vs-webroot-dns-protection
- Heimdal DNS Security: Enterprise DNS filtering and threat detection with cloud and endpoint deployment for MSPs. https://mspsoftware.net/software/heimdal-dns-security
- Advanced DNS Security: Cloud DNS security for Palo Alto firewalls, blocking 157 million malicious domains daily. https://mspsoftware.net/software/palo-alto-dns-security
- Cisco Umbrella: Cloud DNS filtering and secure web gateway for multi-site networks and roaming users. https://mspsoftware.net/software/cisco-umbrella

## FAQ

### How much does OpenText Core DNS Protection cost?

OpenText Core DNS Protection does not publish a list price. No MSP price reports have been approved yet.

### Does OpenText Core DNS Protection offer a free trial?

There is no free version.

### What does OpenText Core DNS Protection integrate with?

OpenText Core DNS Protection lists integrations with ConnectWise Manage, Autotask, HaloPSA, Syncro, Rewst and Kaseya BMS.

### Is OpenText Core DNS Protection cloud or on-premises?

OpenText Core DNS Protection is cloud-hosted; there is no on-premises version.

### Who is OpenText Core DNS Protection for?

MSPs report using OpenText Core DNS Protection at sizes of 6-15, 16-50, 51-200 and 200+ technicians.

### How does OpenText Core DNS Protection differ from traditional DNS filtering?

OpenText Core DNS Protection uses agent-level enforcement with dynamic DNS server detection, blocking unauthorized DNS resolution at the process level rather than just at the network level. This agent-based approach prevents sophisticated bypass techniques including encrypted DNS traffic (DNS-over-HTTPS and DNS-over-TLS), which traditional DNS-only filters cannot block. The solution is designed specifically for distributed workforces, supporting remote and hybrid workers wherever they connect, rather than only protecting users on the corporate network.

### Does OpenText Core DNS Protection integrate with my PSA or RMM?

OpenText Core DNS Protection integrates with major MSP platforms including ConnectWise Manage, Autotask, HaloPSA and Syncro. It also supports broader integration with PSAs, RMMs, SIEM systems and billing platforms through an open API. Before purchasing, confirm your specific PSA and RMM are on the current integration list with OpenText, as integration availability can change and vendor integration roadmaps shift.

### Is OpenText Core DNS Protection priced per endpoint or per user?

OpenText Core DNS Protection pricing is not published by the vendor; MSPs report it is quote-only based on evaluation. Based on similar DNS filtering solutions in the dns-filtering category, pricing is likely either per endpoint or per user per month or per year, but this must be confirmed directly with OpenText sales before budgeting. MSPs should request pricing for their specific user and device count during evaluation.

### Can OpenText Core DNS Protection be deployed off-network?

OpenText Core DNS Protection is designed for remote and hybrid workers with agent-based deployment that enables DNS filtering and enforcement across any network, whether corporate, home, mobile or public Wi-Fi. The cloud-native architecture means no on-premises appliance or network gateway is required, making it suitable for distributed teams without a centralized office or VPN.

### Is Webroot still an independent company?

Webroot is no longer independent; it was acquired by OpenText in 2019 and consolidated into the OpenText Cybersecurity division. OpenText Core DNS Protection is now the official product name, though some existing customers may still reference it as Webroot DNS Protection. The acquisition means the product benefits from integration with OpenText's broader endpoint protection, email security, backup and compliance product lines.