blueAPACHE offers free Secure Recursive DNS
Summary
This post announces that blueAPACHE extended its emPOWER Internet offering to include free secure recursive DNS with integrated blacklisting for all emPOWER Internet customers, both existing and new. It is aimed at existing and prospective emPOWER Internet clients weighing up an additional layer of protection against phishing, malware and ransomware, and it explains the mechanics of how blacklist-based recursive DNS filtering blocks access to known malicious domains before a user's device can reach them. The underlying problem the post addresses, users being tricked into visiting malicious domains through spam, phishing and compromised websites, has not gone away, and layered DNS-level filtering remains a standard part of blueAPACHE's current security stack alongside its managed detection and response and human risk management services.
Key facts
| Label | Value |
|---|---|
| Publication year | 2016 |
| Topic | blueAPACHE adds free secure recursive DNS with integrated blacklisting to emPOWER Internet |
| Eligibility | Offered free to all existing and new emPOWER Internet customers |
| Statistic cited | Each business user sent and received an average of 42 emails a day, with spam accounting for more than half of inbound business email traffic in 2015, per the Symantec Internet Security Threat Report cited in the post |
| Mechanism | Uses a real-time Domain Block List (DBL) of spam payload URLs, spam sources and senders, and malware-related sites; blocked users see a blueAPACHE block page instead of the requested domain |
| Services referenced | emPOWER security, managed detection and response, human risk management |
Article
blueAPACHE extends Internet offering to include free secure recursive DNS services with integrated blacklisting for all emPOWER Internet customers.The rapid rise in sophisticated threats like zero-day malware, Trojans and advanced persistent threats makes cybersecurity a daunting challenge for both individuals and businesses. In their simplest form, many scams rely on the poor security habits of users, such as clicking on links or attachments in spam emails, to succeed. According to the Internet Security Threat Report published earlier this year by Symantec Corporation, on average, each business user sent and received 42 emails each day, with spam accounting for more than half of inbound business email traffic in 2015. As regularly mentioned (including in our recent PayPal Scam news), tricking users into visiting a malicious domain by clicking on spam emails is a common approach used by criminals to launch targeted and personalised phishing and malware attacks against organisations. There are also numerous instances of legitimate websites that have been hacked and, unknown to its administrators, malicious code embedded into it. These compromised websites act as effective bait for victims who might believe that they are visiting a trusted website, but in reality, are allowing cyber criminals to send malicious code directly to visitor’s computers. Despite extensive use of network security measures, the reported number of successful breaches has continued to rise. Enterprise security today can no longer rely solely upon the old cornerstones of traditional firewalls, built-in security tools or anti-malware software. Instead, organisations need a broad-based, holistic and resilient approach to cyber security.
blueAPACHE offers emPOWER secure recursive DNS service at no cost
In our continued effort to proactively respond to today’s constantly evolving threat landscape, blueAPACHE have expanded our Internet offering to include emPOWER secure recursive DNS. It is different from industry standard recursive DNS thanks to the integrated site blacklisting that automatically blocks known malicious sites. This service is offered to existing emPOWER Internet customers for free. It is also offered free to all new emPOWER Internet customers.
“We wanted all of our emPOWER Internet clients to benefit from the extra security our recursive DNS brings” said James Hendry, General Manager Commercial at blueAPACHE. “Integrating blacklisting adds to our service costs, but offering it as a free upgrade reinforces our commitment to securing our clients. If it helps only one customer avoid downtime caused by ransomware or malware, the investment we are absorbing will be easily justified”. While recursive DNS is not a standalone security solution by itself, integrating blacklisting adds another layer to existing solutions including email security, next-generation firewalls, end point security and zero trust networks, to create a stronger and more scalable security posture. Email security provides the first level of protection by filtering emails sent and received at the network / internet perimeter, and blocking incoming threats such as spam, phishing attacks, viruses, malware and malicious links. The secure recursive DNS service offers the next level of protection, blocking access to known malicious links should an email make its way to a user.
How it works
The secure recursive DNS service acts as a gatekeeper between your organisation and the outside world by blocking access to malicious domains and preventing users from inadvertently compromising the security of your data and systems. Built into the emPOWER secure recursive DNS service is a lookup filter that utilises a real-time database (also called the Domain Block List or DBL) of malicious domains. The DBL is a database of spam payload URLs, spam sources and senders, known spammers and spam gangs, and virus and malware-related sites that are typically found in spam messages. This database is maintained by a dedicated team of specialists who constantly analyse and update it with malicious domains identified from around the world. It can be queried in real-time to recognise, tag and block domains that have previously been identified as being malicious. If an emPOWER Internet user clicks on a link or tries to browse to a website that appears on the DBL, they will see the blueAPACHE block page, instead of the domain they are trying to access.
Most ransomware including Cryptolocker, are launched using malicious links that direct users to a compromised website. The ransomware are typically programmed to ‘talk’ back to the attackers by looking up the domain name for its Command and Control (C&C) server. However, if the domain name appears on the DBL, the recursive DNS service is able to block the malware from communicating with its C&C server, rendering it useless. In summary, emPOWER secure recursive DNS service is a simple addition to secure your users’ Internet experience by blocking unsafe sites. Simple, effective and free. It is an additional element in a multi-pronged, multi-layered approach to security that can lead your organisation to a more reliable, stringent level of protection against targeted, phishing and other advanced malware attacks. If you would like secure recursive DNS added to your emPOWER Internet, contact our account team.
Why this still matters
The core problem this post describes, users being lured to malicious domains through spam, phishing emails and compromised legitimate websites, remains one of the most common ways ransomware and malware first make contact with an organisation's network. Recursive DNS filtering addresses a specific point in that chain: even where a phishing email evades an email security filter and a user clicks the link, DNS-level blacklisting can still stop the connection to the malicious domain before any payload downloads or before ransomware can call back to its command-and-control server. That mechanism has not changed since 2016 and is still one of the more straightforward, low-friction controls an organisation can add to its security posture.
blueAPACHE frames this specifically as a layer that sits alongside, not instead of, other controls: email security filters inbound threats at the perimeter, and secure recursive DNS provides a second layer that blocks known-malicious destinations if a threat gets past the first layer. That layered logic is still how blueAPACHE structures its current security services, which now extend beyond DNS filtering to managed detection and response and human risk management, both aimed at different points in the same attack chain the 2016 post describes. Read together with those services, this post is less a historical curiosity than an early example of the layered security approach blueAPACHE continues to sell today.
Frequently asked questions
What does blueAPACHE's secure recursive DNS service do? It acts as a gatekeeper between an organisation and the wider internet, blocking access to domains identified as malicious. If a user clicks a link or tries to browse to a site on blueAPACHE's Domain Block List, they see a blueAPACHE block page instead of reaching the destination.
How is blueAPACHE's recursive DNS different from standard recursive DNS? The post states it differs from industry-standard recursive DNS through integrated site blacklisting that automatically blocks known malicious sites, using a real-time database of spam payload URLs, spam sources and senders, and malware-related domains.
Who is eligible for this free DNS service? The post states the service is offered at no cost to all existing emPOWER Internet customers and is also free to all new emPOWER Internet customers.
How does recursive DNS filtering help against ransomware specifically? The post explains that ransomware is typically programmed to contact its Command and Control server by looking up that server's domain name. If the domain appears on blueAPACHE's Domain Block List, the recursive DNS service blocks that lookup, which can render the ransomware unable to communicate with its controllers.
Does recursive DNS filtering replace the need for email security? No. The post is explicit that recursive DNS is not a standalone security solution. It describes email security as the first layer of protection, filtering spam, phishing and malicious links at the network perimeter, with secure recursive DNS providing a second layer that blocks access if a threat makes it past email filtering.
Why did blueAPACHE make this a free addition rather than a paid upgrade? The post quotes James Hendry, General Manager Commercial at blueAPACHE, saying that while integrating blacklisting adds to blueAPACHE's service costs, offering it as a free upgrade reflects a commitment to client security, and that the investment is justified if it helps even one customer avoid downtime from ransomware or malware.
What statistic does the post cite about email-based threats? The post cites the Symantec Internet Security Threat Report, stating that in 2015 the average business user sent and received 42 emails a day, with spam accounting for more than half of inbound business email traffic.
What other blueAPACHE services address the same threats as recursive DNS? Beyond DNS-level filtering, blueAPACHE's current emPOWER security services include managed detection and response and human risk management, both aimed at reducing the same class of phishing- and malware-driven risk this post describes, alongside general firewall, endpoint and zero trust network controls referenced in the post.
Related
- emPOWER Security
- Security services
- Managed detection and response
- Human risk management
- Archers Strata case study
Source
https://www.blueapache.com/blog/blueapache-offers-free-recursive-dns-internet/
Knowledge Base
What new service does blueAPACHE offer for free to emPOWER Internet customers?
blueAPACHE offers a free secure recursive DNS service with integrated site blacklisting to all emPOWER Internet customers, both existing and new.
How is blueAPACHE's secure recursive DNS different from industry standard recursive DNS?
It is different from industry standard recursive DNS because it has integrated site blacklisting that automatically blocks known malicious sites.
Who commented on the launch of the free secure recursive DNS service, and what did they say?
James Hendry, General Manager Commercial at blueAPACHE, said, "We wanted all of our emPOWER Internet clients to benefit from the extra security our recursive DNS brings," and added, "Integrating blacklisting adds to our service costs, but offering it as a free upgrade reinforces our commitment to securing our clients. If it helps only one customer avoid downtime caused by ransomware or malware, the investment we are absorbing will be easily justified."
How does the emPOWER secure recursive DNS service technically work?
It uses a lookup filter that utilises a real-time database called the Domain Block List (DBL), which contains spam payload URLs, spam sources and senders, known spammers and spam gangs, and virus and malware-related sites. The database is maintained by a dedicated team of specialists who constantly analyse and update it with malicious domains identified worldwide, and it can be queried in real-time to recognise, tag and block previously identified malicious domains.
What happens if an emPOWER Internet user tries to access a site on the Domain Block List (DBL)?
If a user clicks on a link or tries to browse to a website that appears on the DBL, they will see the blueAPACHE block page instead of the domain they are trying to access.
How does the recursive DNS service help against ransomware like Cryptolocker?
Most ransomware, including Cryptolocker, is launched using malicious links that direct users to a compromised website, and the ransomware typically tries to 'talk' back to attackers via a Command and Control (C&C) server domain. If that domain appears on the DBL, the recursive DNS service blocks the malware from communicating with its C&C server, rendering it useless.
Why did blueAPACHE decide to expand its Internet offering with secure recursive DNS?
blueAPACHE expanded its Internet offering to proactively respond to the constantly evolving threat landscape of sophisticated cyber threats like zero-day malware, Trojans, and advanced persistent threats, recognizing that a broad-based, holistic and resilient approach to cyber security is needed beyond traditional firewalls and anti-malware tools.
What statistic does the article cite about spam in business email traffic?
According to the Internet Security Threat Report published by Symantec Corporation, each business user sent and received 42 emails a day on average, with spam accounting for more than half of inbound business email traffic in 2015.
Is the secure recursive DNS service meant to be a standalone security solution?
No, the article states that recursive DNS is not a standalone security solution by itself; integrating blacklisting adds another layer to existing solutions such as email security, next-generation firewalls, end point security, and zero trust networks to create a stronger, more scalable security posture.
How can a customer get secure recursive DNS added to their emPOWER Internet service?
Customers who would like secure recursive DNS added to their emPOWER Internet should contact blueAPACHE's account team via the contact page.
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bef56ba2a604e908fd7_blocked.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bf156ba2a604e90908f_DNS-Block-Page.png
DNS Block Page
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701b59b153d68a8eeb0e36_BBanner-1-Windows-10-is-out.-AI-is-in.-.avif
You’ve Invest in Security. So Why Are Breaches Still Happening?
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb807b7741bf53e298a_BBanner-1-Windows-10-is-out.-AI-is-in.-8.avif
EOFY 2026: The Reset Is Done – Now It’s About Getting Ahead
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d0_BBanner-2-When-support-ends-risk-begins-4.avif
Why Every Business Needs AI Guardrails
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d7_BBanner-2-When-support-ends-risk-begins-3.avif
Ransomware Incident Response: Why Paying the Ransom Is a Failure of Preparation
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb707b7741bf53e297d_BBanner-2-When-support-ends-risk-begins-1.avif
The 7 Cyber Truths Boards Must Act On In 2026
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29f9_BBanner-1-Windows-10-is-out.-AI-is-in.-7.avif
Reflecting on an Outstanding 2025 – Thank You for Your Partnership
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e2a0c_Procurement-Portal.avif
The blueAPACHE e-Store: IT purchasing made simple
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29ec_BBanner-1-Windows-10-is-out.-AI-is-in.-5.avif
Building Our Cyber Safe Culture: A Practical Guide for CSAM 2025
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.
Most ransomware including