Skip to main content
Connector guides

Connect DNSFilter

DNSFilter is a protective DNS service: it answers your clients' DNS lookups, blocks the ones that lead to malware, phishing and command-and-control infrastructure, and enforces the content policy you…

Written By Christopher Scaminaci

Last updated 6 days ago

DNSFilter is a protective DNS service: it answers your clients' DNS lookups, blocks the ones that lead to malware, phishing and command-and-control infrastructure, and enforces the content policy you set — per network, per site, and per roaming laptop. StackJack talks to DNSFilter through its public API.

Connecting DNSFilter to StackJack gives your AI assistant a family of dnsfilter_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Investigate — search the raw DNS query log to see exactly what a machine, user or network resolved, and when, with whether each lookup was allowed or blocked
  • Report — request and threat volume over any window, broken down by organization, network, roaming client, user or collection; the busiest domains, categories and applications; and query rates showing which sites are actually live
  • Show security value — threat lookups blocked per client, which is the number that belongs in a monthly report
  • Understand coverage — deployment and roaming-client counts, and application usage across your customer base

How StackJack authenticates to DNSFilter

DNSFilter uses a single API token. There is no client ID, no secret pair, and no expiry to track — the token works until you revoke it.

Create the token

  1. Sign in to the DNSFilter dashboard at app.dnsfilter.com as a user who can see every organization and network you want StackJack to reach. A DNSFilter token inherits the permissions of the account that created it.
  2. Open your account settings and select API Keys.
  3. Create a new key and name it something that identifies StackJack, so you can tell later which integration a token belongs to if you ever need to revoke one.
  4. Copy the token as soon as it is shown and store it securely. Treat it as a password — anyone holding it can read your DNS query history and change your filtering policies.

Add it to StackJack

Open Connectors in StackJack, choose DNSFilter, and paste the token. There is no URL to enter: DNSFilter runs on one global endpoint, so there is nothing regional to choose.

Paste the token on its own. DNSFilter does not use the word "Bearer" in front of the token the way many other products do — the token itself is the whole credential. If you do paste a value starting with Bearer , StackJack removes that word for you rather than failing every call, but the safest thing is to paste exactly what DNSFilter gave you.

Use Test Connection to confirm it works. StackJack checks the token against DNSFilter's own account-identity endpoint, which every token can reach regardless of what else it is allowed to do.

What each plan includes

PlanWhat you get
FreeEvery DNSFilter read: traffic reports, query-log search, and the full inventory of networks, policies, roaming clients, organizations and block pages
ProEverything in Free, plus the tools that change DNSFilter: creating and updating networks, policies, block pages and scheduled reports, editing allow and block lists, and managing roaming clients and organization users
BusinessThe Pro tool set with higher monthly usage limits

Reporting and investigation are entirely on the Free tier — the analytics surface is the largest part of this connector and none of it is gated.

Permissions

DNSFilter API tokens have no per-token permission settings. A token can do whatever the account that created it can do, so the account you use to create it decides what StackJack can reach.

StackJack adds its own controls on top of that. Each tool belongs to a permission group — traffic reports, networks, policies, roaming clients, organizations, and so on — and you choose which groups a given AI assistant may use when you set up its access. That is how you let an assistant read reports without letting it change filtering.

Tools that change live filtering

Some DNSFilter tools affect real people immediately, so they require the Pro tier and are marked destructive. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review those settings before you grant any of these:

  • Deleting a network, policy, block page or roaming client
  • Clearing an allow list or block list
  • Changing a person's password, or cancelling an organization
  • Removing the DNSFilter agent from machines, or resetting the enrollment secret a network's roaming clients use

Two are worth calling out on their own. Suggesting a domain as a threat sends it to DNSFilter's own threat-intelligence review — that leaves your account entirely and cannot be taken back. Revoking an API key is irreversible and can lock out other integrations, including StackJack itself if you revoke the wrong one.

Adding or removing a single domain from an allow or block list is treated as a normal change rather than a destructive one, because the opposite action puts things back exactly as they were. These tools still change what your users can reach, so the assistant will tell you what it is about to do.

Troubleshooting

Everything fails with an authorization error. Check the token first. The most common cause is a token pasted with extra text around it, or one that has been revoked in the DNSFilter dashboard. Create a fresh key and re-enter it.

Some tools work and others are refused. This is almost always the permissions of the account that created the token, not the token itself. DNSFilter reports "you may not do that" the same way it reports "your credential is wrong", so a refusal on one area while everything else works points at what the creating account can see. Create the token as a user with the visibility you need.

A report comes back empty. Check the time window and the organization. Most reports default to the token's own organization, so if you manage several you need to name the one you mean. Your assistant can list your organizations to find the right identifier.

A report seems to be missing recent data. DNSFilter aggregates traffic data, so the most recent minutes may not have landed yet. Widen the window slightly and try again.

Full tool list

See the generated DNSFilter tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

DNSFilter tools

dnsfilter_ · 238 tools · Free 151 · Pro 87

Traffic Reports & Query Logs

ToolWhat it does
dnsfilter_traffic_qps
Free · Read-only
Query rate (queries per second) over a time window — the load view, as opposed to the raw counts total_requests returns.
dnsfilter_traffic_qps_active_agents
Free · Read-only
Roaming client agents actively sending DNS queries in the window, with their query rate.
dnsfilter_traffic_qps_active_collections
Free · Read-only
Collections actively sending DNS queries in the window, with their query rate.
dnsfilter_traffic_qps_active_organizations
Free · Read-only
Organizations actively sending DNS queries in the window, with their query rate.
dnsfilter_traffic_qps_active_users
Free · Read-only
Users actively sending DNS queries in the window, with their query rate.
dnsfilter_traffic_query_logs
Free · Read-only
Search the raw DNS query log — every individual lookup, with the domain asked for and whether it was allowed or blocked.
dnsfilter_traffic_top_agents
Free · Read-only
The busiest roaming client agents in the window, ranked by request volume.
dnsfilter_traffic_top_application_categories
Free · Read-only
The most-used application categories in the window, ranked.
dnsfilter_traffic_top_categories
Free · Read-only
The most-requested content categories in the window, ranked.
dnsfilter_traffic_top_collections
Free · Read-only
The busiest collections in the window, ranked by request volume.
dnsfilter_traffic_top_domains
Free · Read-only
The most-requested domains in the window, ranked.
dnsfilter_traffic_top_networks
Free · Read-only
The busiest networks in the window, ranked by request volume.
dnsfilter_traffic_top_organizations
Free · Read-only
The busiest organizations in the window, ranked by request volume.
dnsfilter_traffic_top_organizations_requests
Free · Read-only
Organizations ranked by request count within a single parent organization's scope.
dnsfilter_traffic_top_users
Free · Read-only
The busiest users in the window, ranked by request volume.
dnsfilter_traffic_total_applications_agents_stats
Free · Read-only
Application usage statistics over a time window, attributed to roaming client agents.
dnsfilter_traffic_total_applications_collections_stats
Free · Read-only
Application usage statistics over a time window, attributed to collections.
dnsfilter_traffic_total_applications_networks_stats
Free · Read-only
Application usage statistics over a time window, attributed to networks.
dnsfilter_traffic_total_applications_organizations_stats
Free · Read-only
Application usage statistics over a time window, attributed to organizations.
dnsfilter_traffic_total_applications_stats
Free · Read-only
Application usage statistics over a time window — which SaaS and web applications are being reached.
dnsfilter_traffic_total_applications_users_stats
Free · Read-only
Application usage statistics over a time window, attributed to users.
dnsfilter_traffic_total_categories
Free · Read-only
DNS traffic broken down by content category over a time window — what people are browsing, grouped the way the filtering policy groups it.
dnsfilter_traffic_total_categories_agents
Free · Read-only
Content-category traffic over a time window, attributed to roaming client agents.
dnsfilter_traffic_total_categories_collections
Free · Read-only
Content-category traffic over a time window, attributed to collections.
dnsfilter_traffic_total_categories_organizations
Free · Read-only
Content-category traffic over a time window, attributed to organizations.
dnsfilter_traffic_total_categories_users
Free · Read-only
Content-category traffic over a time window, attributed to users.
dnsfilter_traffic_total_category_stats
Free · Read-only
Summary statistics for content categories over a time window.
dnsfilter_traffic_total_client_stats
Free · Read-only
Summary client statistics over a time window.
dnsfilter_traffic_total_collections
Free · Read-only
DNS traffic broken down by collection over a time window.
dnsfilter_traffic_total_collections_agents
Free · Read-only
Collection traffic over a time window, attributed to roaming client agents.
dnsfilter_traffic_total_collections_organizations
Free · Read-only
Collection traffic over a time window, attributed to organizations.
dnsfilter_traffic_total_collections_users
Free · Read-only
Collection traffic over a time window, attributed to users.
dnsfilter_traffic_total_deployments
Free · Read-only
Current deployment count for an organization.
dnsfilter_traffic_total_domain_requests
Free · Read-only
Request totals for one domain over a time window.
dnsfilter_traffic_total_domain_stats
Free · Read-only
Summary statistics for one domain over a time window.
dnsfilter_traffic_total_domains
Free · Read-only
DNS traffic broken down by domain over a time window.
dnsfilter_traffic_total_domains_collections
Free · Read-only
Domain traffic over a time window, attributed to collections.
dnsfilter_traffic_total_domains_organizations
Free · Read-only
Domain traffic over a time window, attributed to organizations.
dnsfilter_traffic_total_domains_users
Free · Read-only
Domain traffic over a time window, attributed to users.
dnsfilter_traffic_total_organizations_requests
Free · Read-only
Request totals for organizations within a parent organization's scope.
dnsfilter_traffic_total_organizations_stats
Free · Read-only
Summary statistics for a single organization over a time window.
dnsfilter_traffic_total_requests
Free · Read-only
Total DNS requests over a time window, returned as a time series for charting.
dnsfilter_traffic_total_requests_agents
Free · Read-only
Total DNS requests over a time window, attributed to roaming client agents.
dnsfilter_traffic_total_requests_collections
Free · Read-only
Total DNS requests over a time window, attributed to collections.
dnsfilter_traffic_total_requests_geo
Free · Read-only
DNS request volume broken down by geography, for the requested number of top locations.
dnsfilter_traffic_total_requests_organizations
Free · Read-only
Total DNS requests over a time window, attributed to organizations.
dnsfilter_traffic_total_requests_users
Free · Read-only
Total DNS requests over a time window, attributed to users.
dnsfilter_traffic_total_roaming_clients
Free · Read-only
Current roaming client count for an organization.
dnsfilter_traffic_total_threats
Free · Read-only
Total threat lookups blocked over a time window, as a time series.
dnsfilter_traffic_total_threats_agents
Free · Read-only
Threat lookups blocked over a time window, attributed to roaming client agents — use it to find the specific machines generating threat traffic.
dnsfilter_traffic_total_threats_collections
Free · Read-only
Threat lookups blocked over a time window, attributed to collections.
dnsfilter_traffic_total_threats_organizations
Free · Read-only
Threat lookups blocked over a time window, attributed to organizations — the report that answers which client is most at risk.
dnsfilter_traffic_total_threats_users
Free · Read-only
Threat lookups blocked over a time window, attributed to users.

API Keys

ToolWhat it does
dnsfilter_create_api_key
Pro · Write
Mint a new DNSFilter API key.
dnsfilter_delete_api_key
Pro · Destructive
Permanently delete a DNSFilter API key by ID (from dnsfilter_list_api_keys).
dnsfilter_get_api_key
Free · Read-only
Get one DNSFilter API key by ID (from dnsfilter_list_api_keys).
dnsfilter_list_api_keys
Free · Read-only
List the DNSFilter API keys belonging to the account this connection authenticates as.
dnsfilter_revoke_api_key
Pro · Destructive
Revoke a DNSFilter API key by ID (from dnsfilter_list_api_keys), invalidating the token while leaving the record in place.

Block Pages

ToolWhat it does
dnsfilter_create_block_page
Pro · Write
Create a block page — the branded page end users see when DNSFilter blocks a lookup.
dnsfilter_delete_block_page
Pro · Destructive
Permanently delete a block page by ID (from dnsfilter_list_block_pages).
dnsfilter_get_block_page
Free · Read-only
Get one block page by ID (from dnsfilter_list_block_pages), including its branding fields and, by default, the related records that reference it.
dnsfilter_list_all_block_pages
Free · Read-only
List ALL block pages the account can see, DNSFilter's wider counterpart to dnsfilter_list_block_pages.
dnsfilter_list_block_pages
Free · Read-only
List the block pages available to the account this connection authenticates as — the branded pages DNSFilter serves when it blocks a lookup.
dnsfilter_update_block_page
Pro · Write
Update a block page by ID (from dnsfilter_list_block_pages).

Organizations & Users

ToolWhat it does
dnsfilter_add_collection_user
Pro · Write
Add an existing user to a collection.
dnsfilter_bulk_update_organizations
Pro · Destructive
Apply settings to MANY organizations in one call — agent auto-update, uninstall notifications and their recipient list, VPN settings.
dnsfilter_cancel_organization
Pro · Destructive
Set an organization to "Canceled".
dnsfilter_change_user_password
Pro · Destructive
Change the password of the currently authenticated DNSFilter user — the account behind this connection, NOT an arbitrary user.
dnsfilter_create_organization
Pro · Write
Create an organization (for an MSP, a new customer tenant).
dnsfilter_create_organization_user
Pro · Write
Grant a person access to an organization by email, creating the DNSFilter user if it does not already exist.
dnsfilter_delete_organization
Pro · Destructive
Delete an MSP customer organization by ID.
dnsfilter_delete_organization_user
Pro · Destructive
Remove a person's access to an organization.
dnsfilter_get_collection_user
Free · Read-only
Get one user's details within a collection.
dnsfilter_get_organization
Free · Read-only
Get one organization by ID (from dnsfilter_list_organizations), optionally with its current MRR.
dnsfilter_get_organization_settings
Free · Read-only
Read organization-level settings — the account-wide toggles (agent auto-update, uninstall notifications, VPN settings) that dnsfilter_bulk_update_organizations writes.
dnsfilter_get_organization_user
Free · Read-only
Get one organization user with their role and permission set.
dnsfilter_get_user
Free · Read-only
Get one DNSFilter console user by ID.
dnsfilter_list_all_organizations
Free · Read-only
List ALL organizations the account can see, DNSFilter's wider counterpart to dnsfilter_list_organizations.
dnsfilter_list_all_users
Free · Read-only
List ALL DNSFilter console users, the wider counterpart to dnsfilter_list_users.
dnsfilter_list_collection_users
Free · Read-only
List the users belonging to a collection — the grouping DNSFilter uses to scope policies and reporting to a set of people.
dnsfilter_list_organization_users
Free · Read-only
List the DNSFilter console users who have access to an organization, with their roles.
dnsfilter_list_organizations
Free · Read-only
List the organizations this account can see — for an MSP, the customer tenants.
dnsfilter_list_users
Free · Read-only
List the DNSFilter console users visible to this account.
dnsfilter_promote_organization_to_msp
Pro · Destructive
Promote an organization to MSP status, letting it own sub-organizations.
dnsfilter_remove_collection_user
Pro · Write
Remove a user from a collection.
dnsfilter_resend_organization_user_invite
Pro · Destructive
Resend the DNSFilter invitation email for a user in an organization.
dnsfilter_update_organization
Pro · Write
Update one organization by ID (from dnsfilter_list_organizations).
dnsfilter_update_organization_user
Pro · Write
Update an organization user's details, role or permissions.

Networks & Sites

ToolWhat it does
dnsfilter_bulk_create_networks
Pro · Write
Create many networks in one call.
dnsfilter_bulk_delete_networks
Pro · Destructive
Delete MANY networks in one call.
dnsfilter_bulk_update_networks
Pro · Destructive
Reassign policy, scheduled policy or block page across MANY networks at once.
dnsfilter_create_ip_address
Pro · Write
Register a public IP address against a network, which is what makes traffic from that address get filtered by the site's policy.
dnsfilter_create_network
Pro · Write
Create a network (site).
dnsfilter_create_network_secret_key
Pro · Destructive
Create the secret key agents use to enrol against a network.
dnsfilter_create_network_subnet
Pro · Write
Add a subnet to a network so an internal address range gets its own policy.
dnsfilter_create_networks_csv_export
Pro · Write
Start a CSV export of networks, filtered the same way the list reads are.
dnsfilter_delete_ip_address
Pro · Destructive
Remove a registered IP address.
dnsfilter_delete_network
Pro · Destructive
Delete a network (site) by ID.
dnsfilter_delete_network_secret_key
Pro · Destructive
Revoke a network's agent enrolment secret key.
dnsfilter_delete_network_subnet
Pro · Destructive
Delete a subnet from a network.
dnsfilter_get_bulk_create_networks_status
Free · Read-only
Check the outcome of a dnsfilter_bulk_create_networks job.
dnsfilter_get_bulk_delete_networks_status
Free · Read-only
Check the outcome of a dnsfilter_bulk_delete_networks job.
dnsfilter_get_bulk_update_networks_status
Free · Read-only
Check the outcome of a dnsfilter_bulk_update_networks job.
dnsfilter_get_ip_address
Free · Read-only
Get one registered IP address by ID, including the network it belongs to.
dnsfilter_get_my_ip
Free · Read-only
Return the public IP address DNSFilter sees this request coming from.
dnsfilter_get_network
Free · Read-only
Get one network by ID, including its assigned policies, block page and IP addresses.
dnsfilter_get_network_counts
Free · Read-only
Counts of networks grouped by status — the cheap health read to run before listing anything, and across an MSP's customers in one call.
dnsfilter_get_network_lan_ip
Free · Read-only
Get one recorded LAN IP behind a network.
dnsfilter_get_network_subnet
Free · Read-only
Get one subnet of a network, including the policy and block page assigned to its address range.
dnsfilter_get_networks_csv_export
Free · Read-only
Read back a networks CSV export by ID (from dnsfilter_create_networks_csv_export).
dnsfilter_get_networks_geo
Free · Read-only
List the account's networks with their geographic information only — the map view of where sites are.
dnsfilter_list_all_ip_addresses
Free · Read-only
List ALL registered public IP addresses, the wider counterpart to dnsfilter_list_ip_addresses.
dnsfilter_list_all_msp_networks
Free · Read-only
List ALL networks of one organization from an MSP account, the wider counterpart to dnsfilter_list_msp_networks.
dnsfilter_list_all_network_subnets
Free · Read-only
List every site subnet the account can see, across networks.
dnsfilter_list_all_networks
Free · Read-only
List ALL networks the account can see, DNSFilter's wider counterpart to dnsfilter_list_networks.
dnsfilter_list_ip_addresses
Free · Read-only
List the public IP addresses registered to the account's networks — the addresses DNSFilter matches inbound queries against to decide which site, and therefore which policy, a query belongs to.
dnsfilter_list_msp_networks
Free · Read-only
List the networks of one organization from an MSP account.
dnsfilter_list_network_lan_ips
Free · Read-only
List the LAN IP addresses DNSFilter has recorded behind a network — the internal addresses it has seen making queries.
dnsfilter_list_network_subnets
Free · Read-only
List the subnets defined on one network.
dnsfilter_list_networks
Free · Read-only
List networks (sites) — a fixed location identified by its public IP, where filtering applies to everything behind that IP rather than to an installed agent.
dnsfilter_lookup_network_by_ip
Free · Read-only
Find which network owns a public IP address.
dnsfilter_rotate_network_secret_key
Pro · Destructive
Rotate a network's agent enrolment secret key.
dnsfilter_update_ip_address
Pro · Write
Update a registered IP address — its value, its dynamic hostname, or the network it belongs to.
dnsfilter_update_network
Pro · Write
Update one network by ID.
dnsfilter_update_network_lan_ip
Pro · Write
Rename a recorded LAN IP so reports show a machine name instead of a bare address.
dnsfilter_update_network_subnet
Pro · Write
Update a subnet's range, policy or block page.
dnsfilter_verify_ip_address
Free · Read-only
Check whether an IP address is already registered in DNSFilter before you try to add it.

Roaming Clients (Agents)

ToolWhat it does
dnsfilter_check_user_agent_bulk_update_mixed
Free · Read-only
Report which attributes differ across the selected roaming clients.
dnsfilter_create_user_agent_bulk_delete
Pro · Destructive
Delete or uninstall MANY roaming clients at once.
dnsfilter_create_user_agent_bulk_update
Pro · Destructive
Apply one changeset to MANY roaming clients.
dnsfilter_create_user_agent_cleanup
Pro · Destructive
Create a cleanup that removes roaming clients inactive for longer than a given number of days.
dnsfilter_create_user_agent_csv_export
Pro · Write
Start a CSV export of roaming clients, filtered the same way the list reads are.
dnsfilter_delete_user_agent
Pro · Destructive
Remove a roaming client.
dnsfilter_dequeue_uninstall_user_agent
Pro · Destructive
Take a roaming client OFF the uninstall queue.
dnsfilter_export_user_agents_csv
Free · Read-only
Export an organization's roaming clients.
dnsfilter_get_user_agent
Free · Read-only
Get one roaming client by UUID, with its hostname, platform, version, assigned policy, tags and current state.
dnsfilter_get_user_agent_bulk_delete
Free · Read-only
Read back a bulk delete job by ID to see how it went.
dnsfilter_get_user_agent_bulk_delete_counts
Free · Read-only
Count the roaming clients a given filter set would delete.
dnsfilter_get_user_agent_bulk_update
Free · Read-only
Read back a bulk update job by ID to see how it went.
dnsfilter_get_user_agent_bulk_update_counts
Free · Read-only
Count the roaming clients a given filter set would select.
dnsfilter_get_user_agent_cleanup
Free · Read-only
Read a stale-agent cleanup by ID, including its threshold and progress.
dnsfilter_get_user_agent_counts
Free · Read-only
Counts of roaming clients per status — the cheap fleet-health read.
dnsfilter_get_user_agent_csv_export
Free · Read-only
Read back a roaming-client CSV export by ID (from dnsfilter_create_user_agent_csv_export).
dnsfilter_get_user_agent_uninstall_pin
Pro · Read-only
Get the PIN that authorizes uninstalling the DNSFilter agent on an organization's machines.
dnsfilter_list_all_user_agents
Free · Read-only
List ALL roaming clients, DNSFilter's wider counterpart to dnsfilter_list_user_agents with a narrower filter set — it takes a single organizationId rather than a list, and none of the operator filters.
dnsfilter_list_relay_releases
Free · Read-only
List the latest DNSFilter relay releases per architecture, release channel and white label.
dnsfilter_list_user_agent_releases
Free · Read-only
List the latest agent release per platform, architecture, release channel and white label.
dnsfilter_list_user_agent_tags
Free · Read-only
List the tags in use across roaming clients.
dnsfilter_list_user_agents
Free · Read-only
List roaming clients (agents) — the DNSFilter software installed on individual machines, which filters them wherever they are rather than only behind a site IP.
dnsfilter_update_user_agent
Pro · Write
Update one roaming client — friendly name, tags, assigned network, policy, scheduled policy, block page, VPN settings, or status.
dnsfilter_update_user_agent_cleanup
Pro · Destructive
Update a stale-agent cleanup, and START it by sending start=true.
dnsfilter_update_user_agent_settings
Pro · Write
Update a roaming client's device and filtering-client settings — CyberSight, the filtering client itself, diagnostics level, and the connection, filtering and failover methods.

Policies & Filtering Lists

ToolWhat it does
dnsfilter_add_policy_allowed_application
Pro · Write
Allow one application in a policy.
dnsfilter_add_policy_allowed_domain
Pro · Write
Add one domain to a policy's allow list, exempting it from category and threat blocking for everyone the policy covers.
dnsfilter_add_policy_blocked_application
Pro · Write
Block one application in a policy — this stops it working for everyone the policy covers, so check what depends on it first.
dnsfilter_add_policy_blocked_category
Pro · Write
Block a whole content category in a policy.
dnsfilter_add_policy_blocked_domain
Pro · Write
Add one domain to a policy's block list.
dnsfilter_bulk_add_policy_allowed_domains
Pro · Write
Add several domains to several policies' allow lists in one call.
dnsfilter_bulk_add_policy_blocked_domains
Pro · Write
Add several domains to several policies' block lists in one call — the fastest way to push an indicator of compromise across every customer.
dnsfilter_bulk_remove_policy_allowed_domains
Pro · Write
Remove several domains from several policies' allow lists.
dnsfilter_bulk_remove_policy_blocked_domains
Pro · Write
Remove several domains from several policies' block lists, so they resolve again wherever those policies apply.
dnsfilter_create_policy
Pro · Write
Create a filtering policy.
dnsfilter_delete_policy
Pro · Destructive
Delete a policy.
dnsfilter_get_application_policies
Free · Read-only
Show how each policy currently treats one application — which policies allow it and which block it.
dnsfilter_get_policy
Free · Read-only
Get one policy by ID with its full rule set — allowed and blocked domains, blocked categories, application rules and the safe-search and YouTube-restriction flags.
dnsfilter_get_policy_ip
Free · Read-only
Get one policy IP by ID.
dnsfilter_get_policy_permissive_mode
Free · Read-only
Read whether a policy is in permissive mode.
dnsfilter_list_all_policies
Free · Read-only
List ALL policies the account can see, the wider counterpart to dnsfilter_list_policies.
dnsfilter_list_policies
Free · Read-only
List filtering policies — the rule sets that decide which domains, categories and applications are allowed or blocked.
dnsfilter_list_policy_ips
Free · Read-only
List the policy IPs — the DNSFilter resolver addresses a policy answers on, which is what a site or device points its DNS at.
dnsfilter_remove_policy_allowed_application
Pro · Write
Remove one application from a policy's allow list.
dnsfilter_remove_policy_allowed_domain
Pro · Write
Remove one domain from a policy's allow list, so the ordinary category and threat rules apply to it again.
dnsfilter_remove_policy_blocked_application
Pro · Write
Remove one application from a policy's block list, letting it work again.
dnsfilter_remove_policy_blocked_category
Pro · Write
Stop blocking a content category in a policy.
dnsfilter_remove_policy_blocked_domain
Pro · Write
Remove one domain from a policy's block list, so it resolves normally again unless another rule still blocks it.
dnsfilter_set_policy_permissive_mode
Pro · Destructive
Turn a policy's permissive mode on or off.
dnsfilter_update_application_policies
Pro · Destructive
Set which policies allow and which block one application, in a single call.
dnsfilter_update_policy
Pro · Write
Update a policy.

Agent Local Users

ToolWhat it does
dnsfilter_create_agent_local_user_bulk_delete
Pro · Destructive
Delete MANY agent local users at once.
dnsfilter_create_agent_local_users_csv_export
Pro · Write
Start a CSV export of agent local users.
dnsfilter_delete_agent_local_user
Pro · Destructive
Delete an agent local user record.
dnsfilter_get_agent_local_user
Free · Read-only
Get one agent local user by ID, with their assigned policy, scheduled policy and block page.
dnsfilter_get_agent_local_user_bulk_delete
Free · Read-only
Read back a bulk delete job by ID to see how it went.
dnsfilter_get_agent_local_user_bulk_delete_count
Free · Read-only
Count the users covered by a bulk delete job.
dnsfilter_get_agent_local_user_counts
Free · Read-only
Counts of agent local users grouped by policy-assignment status — how many have a policy of their own versus inheriting one.
dnsfilter_get_agent_local_users_csv_export
Free · Read-only
Read back an agent local users CSV export.
dnsfilter_list_agent_local_users
Free · Read-only
List agent local users — the people signed in to machines running the roaming client, which is how DNSFilter attributes traffic and applies per-user policy.
dnsfilter_list_all_agent_local_users
Free · Read-only
List ALL agent local users, the wider counterpart to dnsfilter_list_agent_local_users with a narrower filter set — none of the operator filters.
dnsfilter_update_agent_local_user
Pro · Write
Update an agent local user's friendly name, or assign them a policy, scheduled policy or block page directly.

Categories & Applications

ToolWhat it does
dnsfilter_get_application
Free · Read-only
Get one application by ID.
dnsfilter_get_application_category
Free · Read-only
Get one application category by ID.
dnsfilter_get_category
Free · Read-only
Get one content category by ID.
dnsfilter_list_ai_applications
Free · Read-only
List the AI applications and websites DNSFilter recognises — the reference set behind AI-usage reporting and the starting point for building a policy around generative-AI access.
dnsfilter_list_all_applications
Free · Read-only
List ALL applications INCLUDING deleted ones, which dnsfilter_list_applications omits.
dnsfilter_list_all_categories
Free · Read-only
List ALL content categories INCLUDING DNSFilter's internal ones, which dnsfilter_list_categories omits.
dnsfilter_list_application_categories
Free · Read-only
List the application categories — the grouping over applications, and a different axis from the CONTENT categories in dnsfilter_list_categories.
dnsfilter_list_applications
Free · Read-only
List the applications DNSFilter can allow or block by name — the vocabulary the policy application tools expect.
dnsfilter_list_categories
Free · Read-only
List DNSFilter's content categories — the buckets ("Malware", "Social Media", and so on) a policy blocks by ID.
dnsfilter_list_cybersight_activity_types
Free · Read-only
List the activity types CyberSight reports can contain.
dnsfilter_list_qp_methods
Free · Read-only
List DNSFilter's QP methods dictionary.
dnsfilter_list_vpn_settings_state_types
Free · Read-only
List the valid VPN settings state types.

Domain Lookups & Notes

ToolWhat it does
dnsfilter_batch_delete_domain_notes
Pro · Destructive
Delete the notes for several domains at once.
dnsfilter_batch_update_domain_notes
Pro · Write
Set notes for many domains at once on a policy, MSP or organization.
dnsfilter_bulk_lookup_domains
Free · Read-only
Look up the classification of several FQDNs in one call.
dnsfilter_delete_domain_note
Pro · Destructive
Delete the note recorded against one domain.
dnsfilter_get_domain_notes
Free · Read-only
Read the notes recorded against one domain on a policy, MSP or organization — the free-text record of WHY a domain was allowed or blocked.
dnsfilter_lookup_domain
Free · Read-only
Look up how DNSFilter classifies one FQDN — the domains and content categories it is associated with.
dnsfilter_suggest_threat
Pro · Destructive
Submit an FQDN to DNSFilter for threat review, with your suggested security categories and notes.
dnsfilter_update_domain_note
Pro · Write
Set the note recorded against one domain on a policy, MSP or organization.

MAC Addresses

ToolWhat it does
dnsfilter_create_mac_address
Pro · Write
Register a MAC address so a specific device gets its own policy.
dnsfilter_delete_mac_address
Pro · Destructive
Delete a registered MAC address.
dnsfilter_get_mac_address
Free · Read-only
Get one registered MAC address with the policy, scheduled policy and block page assigned to it.
dnsfilter_list_all_mac_addresses
Free · Read-only
List ALL registered MAC addresses, the wider counterpart to dnsfilter_list_mac_addresses.
dnsfilter_list_mac_addresses
Free · Read-only
List registered MAC addresses — per-device filtering rules keyed to a hardware address, used where a device needs its own policy without running the roaming client.
dnsfilter_update_mac_address
Pro · Write
Update a registered MAC address or the policy assigned to it.

Scheduled Policies

ToolWhat it does
dnsfilter_create_scheduled_policy
Pro · Write
Create a scheduled policy over a set of existing policies.
dnsfilter_delete_scheduled_policy
Pro · Destructive
Delete a scheduled policy.
dnsfilter_get_scheduled_policy
Free · Read-only
Get one scheduled policy, including which policies it cycles between and the timezone the schedule is evaluated in.
dnsfilter_list_all_scheduled_policies
Free · Read-only
List ALL scheduled policies, the wider counterpart to dnsfilter_list_scheduled_policies.
dnsfilter_list_scheduled_policies
Free · Read-only
List scheduled policies — the time-based wrappers that swap between ordinary policies on a schedule, so a site can filter differently during and outside working hours.
dnsfilter_update_scheduled_policy
Pro · Write
Update a scheduled policy.

Scheduled Reports

ToolWhat it does
dnsfilter_create_scheduled_report
Pro · Write
Create a recurring report that DNSFilter emails to the recipients you name.
dnsfilter_create_scheduled_report_preview
Pro · Write
Generate a preview of what a scheduled report would contain, without creating the schedule or emailing anyone.
dnsfilter_delete_scheduled_report
Pro · Destructive
Delete a scheduled report.
dnsfilter_get_scheduled_report
Free · Read-only
Get one scheduled report with its frequency, contents and recipient list.
dnsfilter_get_scheduled_report_preview
Free · Read-only
Read back a scheduled report preview by ID.
dnsfilter_list_scheduled_reports
Free · Read-only
List the scheduled reports configured for an organization — the recurring summary emails DNSFilter sends to named recipients.
dnsfilter_update_scheduled_report
Pro · Write
Update a scheduled report's frequency, contents or recipients.

Usage Metrics & Exports

ToolWhat it does
dnsfilter_create_cybersight_csv_export
Pro · Write
Start a CSV export of a CyberSight report — activity logs, top websites, applications, categories, streaming, risky users, active clients or AI usage.
dnsfilter_get_cybersight_csv_export
Free · Read-only
Read back a CyberSight CSV export.
dnsfilter_get_organization_usage
Free · Read-only
Usage figures for one organization over a date range — the seat and query counts behind what DNSFilter bills.
dnsfilter_get_organization_usage_detailed
Free · Read-only
Usage figures for one organization with a roaming-client count included.

Dashboards

ToolWhat it does
dnsfilter_list_available_dashboards
Free · Read-only
List the dashboards available to this account, including ones other users have shared into the organizations it belongs to.
dnsfilter_list_dashboards
Free · Read-only
List the dashboards for the account this connection authenticates as, default first and the rest alphabetically.
dnsfilter_list_owned_dashboards
Free · Read-only
List only the dashboards this account owns, as opposed to ones shared with it.

Account

ToolWhat it does
dnsfilter_get_current_user
Free · Read-only
Read the DNSFilter account this connection authenticates as.
dnsfilter_get_psa_integration_link
Pro · Write
Get the redirect link that starts DNSFilter's PSA integration flow for an organization.
dnsfilter_update_current_user
Pro · Write
Update the profile of the account this connection authenticates as — first name, last name, phone.