Connect DNSFilter
DNSFilter is a protective DNS service: it answers your clients' DNS lookups, blocks the ones that lead to malware, phishing and command-and-control infrastructure, and enforces the content policy you…
Written By Christopher Scaminaci
Last updated 6 days ago
DNSFilter is a protective DNS service: it answers your clients' DNS lookups, blocks the ones that lead to malware, phishing and command-and-control infrastructure, and enforces the content policy you set — per network, per site, and per roaming laptop. StackJack talks to DNSFilter through its public API.
Connecting DNSFilter to StackJack gives your AI assistant a family of dnsfilter_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Investigate — search the raw DNS query log to see exactly what a machine, user or network resolved, and when, with whether each lookup was allowed or blocked
- Report — request and threat volume over any window, broken down by organization, network, roaming client, user or collection; the busiest domains, categories and applications; and query rates showing which sites are actually live
- Show security value — threat lookups blocked per client, which is the number that belongs in a monthly report
- Understand coverage — deployment and roaming-client counts, and application usage across your customer base
How StackJack authenticates to DNSFilter
DNSFilter uses a single API token. There is no client ID, no secret pair, and no expiry to track — the token works until you revoke it.
Create the token
- Sign in to the DNSFilter dashboard at app.dnsfilter.com as a user who can see every organization and network you want StackJack to reach. A DNSFilter token inherits the permissions of the account that created it.
- Open your account settings and select API Keys.
- Create a new key and name it something that identifies StackJack, so you can tell later which integration a token belongs to if you ever need to revoke one.
- Copy the token as soon as it is shown and store it securely. Treat it as a password — anyone holding it can read your DNS query history and change your filtering policies.
Add it to StackJack
Open Connectors in StackJack, choose DNSFilter, and paste the token. There is no URL to enter: DNSFilter runs on one global endpoint, so there is nothing regional to choose.
Paste the token on its own. DNSFilter does not use the word "Bearer" in front of the token the way many other products do — the token itself is the whole credential. If you do paste a value starting with Bearer , StackJack removes that word for you rather than failing every call, but the safest thing is to paste exactly what DNSFilter gave you.
Use Test Connection to confirm it works. StackJack checks the token against DNSFilter's own account-identity endpoint, which every token can reach regardless of what else it is allowed to do.
What each plan includes
Reporting and investigation are entirely on the Free tier — the analytics surface is the largest part of this connector and none of it is gated.
Permissions
DNSFilter API tokens have no per-token permission settings. A token can do whatever the account that created it can do, so the account you use to create it decides what StackJack can reach.
StackJack adds its own controls on top of that. Each tool belongs to a permission group — traffic reports, networks, policies, roaming clients, organizations, and so on — and you choose which groups a given AI assistant may use when you set up its access. That is how you let an assistant read reports without letting it change filtering.
Tools that change live filtering
Some DNSFilter tools affect real people immediately, so they require the Pro tier and are marked destructive. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review those settings before you grant any of these:
- Deleting a network, policy, block page or roaming client
- Clearing an allow list or block list
- Changing a person's password, or cancelling an organization
- Removing the DNSFilter agent from machines, or resetting the enrollment secret a network's roaming clients use
Two are worth calling out on their own. Suggesting a domain as a threat sends it to DNSFilter's own threat-intelligence review — that leaves your account entirely and cannot be taken back. Revoking an API key is irreversible and can lock out other integrations, including StackJack itself if you revoke the wrong one.
Adding or removing a single domain from an allow or block list is treated as a normal change rather than a destructive one, because the opposite action puts things back exactly as they were. These tools still change what your users can reach, so the assistant will tell you what it is about to do.
Troubleshooting
Everything fails with an authorization error. Check the token first. The most common cause is a token pasted with extra text around it, or one that has been revoked in the DNSFilter dashboard. Create a fresh key and re-enter it.
Some tools work and others are refused. This is almost always the permissions of the account that created the token, not the token itself. DNSFilter reports "you may not do that" the same way it reports "your credential is wrong", so a refusal on one area while everything else works points at what the creating account can see. Create the token as a user with the visibility you need.
A report comes back empty. Check the time window and the organization. Most reports default to the token's own organization, so if you manage several you need to name the one you mean. Your assistant can list your organizations to find the right identifier.
A report seems to be missing recent data. DNSFilter aggregates traffic data, so the most recent minutes may not have landed yet. Widen the window slightly and try again.
Full tool list
See the generated DNSFilter tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
DNSFilter tools
dnsfilter_ · 238 tools · Free 151 · Pro 87
Traffic Reports & Query Logs
API Keys
Block Pages
Organizations & Users
Networks & Sites
Roaming Clients (Agents)
Policies & Filtering Lists
Agent Local Users
Categories & Applications
Domain Lookups & Notes
MAC Addresses
Scheduled Policies
Scheduled Reports
Usage Metrics & Exports
Dashboards
Account
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team