How Shield protects WiFi at the DNS layer
Before a device opens a site or an app, it asks DNS where to find it. Shield answers, using the policy for the network the device is on. If the domain is blocked, the connection never starts.
- news.exampleOpenAllowed
- casino-bonus.exampleOpenBlocked
- ads.tracker.exampleOpenStripped
- c2-callback.exampleSecureBlocked
- bookings.exampleSecureAllowed
- phish-login.examplexPSKBlocked
- video.examplexPSKAllowed
- malware-cdn.exampleOpenBlocked
- news.exampleOpenAllowed
- casino-bonus.exampleOpenBlocked · Gambling
- ads.tracker.exampleOpenStripped · Ads
- c2-callback.exampleSecureBlocked · Command and control
- bookings.exampleSecureAllowed
- phish-login.examplexPSKBlocked · Phishing
- video.examplexPSKAllowed
- malware-cdn.exampleOpenBlocked · Malware
- 241k
- threats blocked a week at St George's
- 10 days
- earlier warning than standard blocklists
- 500%
- faster page loads with ads stripped
From lookup to answer
Every lookup checked before a connection starts
A device asks for a domain
A guest taps a link or an app reaches out to a server. Before anything connects, the device sends a DNS lookup to the resolver set on the network.
- Content categories
- Allow and block lists
- Threat intelligence
Shield checks it against the policy for that network
Shield is that resolver. It checks the domain against the content categories, allow and block lists and schedule for this network, and against its threat intelligence.
- Content categories
- Allow and block lists
- Threat intelligence
Allowed domains resolve as normal
If the domain is allowed, Shield answers with its address and the page loads. With ad blocking on, ad, tracker and bloatware domains are dropped here.
- Content categories
- Allow and block lists
- Threat intelligence
Blocked domains are never reached
If the domain is blocked, the device sees your branded block page instead. A command-and-control callback goes unanswered, and the infected device never reaches home.
- Content categories
- Allow and block lists
- Threat intelligence
After the connection
A DNS layer that knows which network it is on
Shield applies after the device has joined the network, so the policy follows the network and the VLAN, not the device. Every network, on Purple Access or any other WiFi, gets its own rules.
- Per SSID and per VLANGuest, staff, resident and paid networks each carry their own policy.
- Per venueEach venue keeps its own allow and block lists.
- By time of day and day of weekStricter in the evening, different at the weekend.
- OpenGuest WiFi through a captive portalStrict, family-safe
- SecurePasspoint and OpenRoaming, staff on EAP-TLS with MDMThreat defense first
- xPSKThings, communities and concessionsSafeguarding per group
Resilience
It fails closed, across multiple data centers, so protection never lapses
If something goes wrong, Shield does not open the network up. It fails closed, so an outage never leaves a network unfiltered, and it runs across multiple data centers, so a fault in one does not take your service down and users stay protected wherever they are. You never trade safety for uptime. Shield runs on the Purple platform, which carries 500 million logins a year at a 99.999% uptime SLA.
- Fails closedAn outage never leaves a network unfiltered.
- Multiple data centersUsers are protected wherever they are.
- No agents, no hardwareNothing installed on devices, nothing racked at the venue.
Running passenger or public WiFi where uptime comes first? Talk it through with a Shield expert before you switch.
- Data center 1
- Data center 2Offline
- Data center 3
Setup
Live in minutes, with no new hardware
No appliance to rack, no firewall change, no agent to push. Four steps, and the first is a single setting. If your estate runs change control, our engineers plan a pilot on one SSID with your team or your ICT provider.
Point the network's DNS at Shield
Set Shield as the resolver on the SSID, as a per-network setting or a DHCP change on your controller.
Choose a policy
Start from a ready-made policy or build your own allow and block lists, per venue or per SSID.
Filtering goes live
Every device on that network is covered at once, with nothing installed on any of them.
Manage and report
Read blocked URLs, threat analysis and usage, and adjust policy, from one dashboard.
Network settings
- SSID
- Guest WiFi
- DNS resolver
- Purple Shield
- Protective DNS
A per-network setting, or a DHCP change on your controller
Questions about how Shield works
How is Shield different from a firewall?
A firewall inspects traffic once a connection starts. Shield blocks the DNS lookup first, so a malicious or blocked domain is never reached. It also covers guest and BYOD devices a firewall agent never touches, which is why it runs behind a firewall, not instead of one.
Does Shield need any hardware or agents on devices?
No. Pointing the network's DNS at Shield covers every device on that WiFi, with nothing installed on iOS, Android, Windows or guest devices. There is no appliance to rack and no firewall change.
How does Shield catch threats a blocklist would miss?
AI detection flags new malicious domains up to 10 days before they reach standard blocklists, and Shield blocks known phishing and malware domains and command-and-control callbacks at the lookup.
What happens if Shield goes down?
Protection does not lapse. Shield fails closed, so an outage never leaves a network unfiltered, and it runs across multiple data centers, so a fault in one does not take your service down and users stay protected wherever they are. You never trade safety for uptime. Shield runs on the Purple platform, which carries 500 million logins a year at a 99.999% uptime SLA.
Decide what your WiFi reaches, free for 30 days
Tell us which networks you run and who is on them. We map a policy to each one: guests, staff, students, residents and paid tiers. Then point one network at Shield and see what it stops for 30 days, before you pay anything. Running change control? We plan a pilot on one SSID with your team instead. No hardware, no agents on devices.
- We map your networksA Purple expert maps your networks, your venues and the people on each, and answers your questions on bypass, outages, data handling and integrations.
- You get a policy for each oneGuests, staff, students, residents and paid tiers, each with the policy it needs.
- You prove it, then get your tailored quote30 days free on one network, or a pilot on one SSID planned with your team, then Shield priced standalone or as an add-on to your Access plan.
Your policy map
Tell us your networks. We map a policy to each one.
A Purple expert comes back with a policy for every SSID you run, from the team that has run content filtering on WiFi since 2012 and runs WiFi for 80,000+ venues in 90 countries.