Dnsfilter for AI agents
DNSFilter is cloud-based DNS security software that blocks malicious sites and filters content across an organization's networks, used by IT teams protecting employees and managed customers. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Dnsfilter.
Check a policy's blocklist
Read the domains and categories blocked under a policy before troubleshooting a user's access issue.
Add a domain to a policy
Add a newly flagged domain to the blocklist for a specific policy after a security review.
Confirm before deleting policies
Require approval before deleting policies in bulk, since it removes filtering rules across the affected networks.
170 Dnsfilter actions, graded by risk.
Every Dnsfilter action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
116Look things up. Allowed by default.
- dnsfilter.get_userGet User
- dnsfilter.get_notesGet Notes
- dnsfilter.get_api_keysGet API Key
- dnsfilter.get_categoryGet Category
- dnsfilter.get_policiesGet Policy
- dnsfilter.list_billingList Billing
- dnsfilter.get_policy_ipGet Policy IP
- dnsfilter.list_api_keysList API Keys
- dnsfilter.list_invoicesList Invoices
- dnsfilter.list_policiesList Policies
- dnsfilter.get_ip_addressGet IP Address
- dnsfilter.list_users_allList All Users
- dnsfilter.get_mac_addressGet MAC Address
- dnsfilter.list_policy_ipsList Policy IPs
- dnsfilter.list_qp_methodsList QP Methods
- dnsfilter.get_organizationGet Organization
write
36Create and change things. Allow, or ask the user first.
- dnsfilter.create_api_keysCreate API Keys
- dnsfilter.create_networksCreate Networks
- dnsfilter.create_policiesCreate Policies
- dnsfilter.update_policiesUpdate Policies
- dnsfilter.create_ip_addressCreate IP Address
- dnsfilter.update_ip_addressUpdate IP Address
- dnsfilter.create_mac_addressCreate MAC Address
- dnsfilter.update_current_userUpdate Current User
- dnsfilter.add_whitelist_domainAdd Whitelist Domain
- dnsfilter.create_networks_bulkBulk Create Networks
- dnsfilter.update_mac_addressesUpdate MAC Address
- dnsfilter.update_networks_bulkBulk Update Networks
- dnsfilter.update_organizationsUpdate Organizations
- dnsfilter.update_billing_addressUpdate Billing Address
- dnsfilter.add_allowed_applicationAdd Allowed Application
- dnsfilter.add_blocked_applicationAdd Blocked Application
destructive
18Delete, cancel or archive. Ask first, or deny outright.
- dnsfilter.delete_api_keyDelete API Key
- dnsfilter.delete_policiesDelete Policies
- dnsfilter.delete_ip_addressDelete IP Address
- dnsfilter.delete_mac_addressDelete MAC Address
- dnsfilter.cancel_organizationCancel Organization
- dnsfilter.delete_networks_bulkDelete Networks (Bulk)
- dnsfilter.delete_scheduled_reportDelete Scheduled Report
- dnsfilter.remove_blocklist_domainsRemove Blocklist Domains
- dnsfilter.delete_scheduled_policiesDelete Scheduled Policies
- dnsfilter.remove_blacklist_categoryRemove Blacklist Category
- dnsfilter.remove_allowed_applicationRemove Allowed Application
- dnsfilter.remove_blocked_applicationRemove Blocked Application
- dnsfilter.remove_blacklist_domain_from_policyRemove Blacklist Domain From Policy
- dnsfilter.remove_whitelist_domain_from_policyRemove Whitelist Domain from Policy
- dnsfilter.remove_allowlist_domains_from_policiesRemove Allowlist Domains from Policies
- dnsfilter.list_all_block_pagesList All Block Pages
Dnsfilter in three steps.
- 01Your users connect DnsfilterThey add their Dnsfilter api key on Arc0 Connect, under your brand. It goes straight into the vault.
- 02You set the rulesReads run, writes like “create API Keys” can wait for the user, and “delete API Key” can be denied outright.
- 03Any agent can actYour agent calls Dnsfilter through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('dnsfilter', { read: 'allow', write: 'ask', // create_api_keys destructive: 'deny', // delete_api_key }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Dnsfilter connects.
Users add their Dnsfilter api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
The same Dnsfilter connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- API key
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Dnsfilter from any agent.
More security and identity apps.
Dnsfilter and Arc0, answered.
Can I use Dnsfilter with Claude, ChatGPT or Cursor?
Yes. Connect Dnsfilter to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Dnsfilter actions you allow.
How do users connect Dnsfilter?
Users add their Dnsfilter api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
Which Dnsfilter actions can my agent take?
170 in total: 116 read, 36 write and 18 destructive, such as “create API Keys”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in Dnsfilter?
Yes. Actions like “delete API Key” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call Dnsfilter too?
Yes. The same Dnsfilter connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Dnsfilter into your agent.
Your users connect Dnsfilter once, under your brand. Your agent gets 170 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan