Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Threat Protection
    Creating a Threat Protection Policy for Blocking DNS over HTTPS

    Creating a Threat Protection Policy for Blocking DNS over HTTPS

    Netskope recommends creating a security policy (i.e., [Utility] Block DNS over HTTPS) that blocks DNS operating over port 443 (HTTPS) due to its incompatibility for steering. This policy will block silently. Netskope recommends placing this policy with your other Threat Protection policies.

    Netskope recommended utility policies for Real-time Protection.

    Recommended Threat Protection Policy

    DNS over HTTPS is not a supported protocol for Netskope steering (CASB/NGSWG/NPA) and can be compromised by malicious actors. Therefore, Netskope recommends configuring a policy to steer and block this traffic.

    1. Go to Policies > Real-time Protection.
    2. Click New Policy and then Cloud App Access.
    3. On the Real-time Protection Policy page:
      • Source: Click X on the right to change scope to Any.
      • Destination: Ensure it’s Application or Cloud App, and select DNS over HTTPS. Ensure the Activities & Constraints is Any.
      • Profile & Action: Choose the following.
        • Action: Choose Block.
        • Template: Choose a custom template that doesn’t send a notification and blocks silently.
      • Set Policy: Enter a name for the policy.
      The configured DNS Over HTTPS utility policy #2 for Real-time Protection.

      To learn more about any of these fields: Real-time Protection Policies.

    4. Click Save and then Apply Changes.
    The blocked DNS over HTTPS event details in Application Events.
    In this Topic
    • Creating a Threat Protection Policy for Blocking DNS over HTTPS