Service Description
Netskope DNSaaS enables you to point your DNS traffic to Netskope for DNS resolution using Netskope Client, IPSec/GRE, and directly over the internet (Tunnel-less). This enables organizations to utilize DNS Content filtering to filter DNS traffic based on business categories, in addition to the DNS Security support based on their company policies and industry best practices.
Definitions and Units of Measure
A User is each individual that (a) is authorized by the Customer to use the Customer’s systems (including your network, cloud services, and Internet connections), and (b) whose use of such systems is monitored by, or accessed by use of, the Services.
Authenticated Traffic is traffic generated by a User or Device that has identity attached to it is Authenticated Traffic.
Unauthenticated Traffic is traffic generated by a User or Device that does not have identity attached to it is Unauthenticated Traffic.
A Device is any appliance or instance that generates traffic.
A Query is a request initiated by a Customer’s authenticated or unauthenticated user(s), device(s) or service to Netskope resolver requesting DNS related information required for DNS resolution.
Units of Measure
- User: Each User counts as one Subscription Unit and cannot be shared between multiple Users.
- Device: Each Device counts as one Subscription Unit and cannot be shared between multiple Devices.
- Query: One Query counts as one Customer-initiated request for DNS resolution, which can be generated by User or Device and be Authenticated Traffic or Unauthenticated Traffic.
Entitlement
Subscription Period: As set forth in a Customer’s order.
Licensing Models
- Authenticated Traffic: Each Subscription Unit entitles the Customer to one (1) authenticated User or Device with a fixed allocation of Queries per calendar month as defined in the applicable SKU description.
- Unauthenticated Traffic: Each Subscription Unit entitles the Customer to one (1) unauthenticated User or Device with a fixed allocation of Queries per calendar month as defined in the applicable SKU description.
Pooling: Query entitlement is pooled at the account level and can be shared across multiple Customer tenants. This is not enforced on a per-User or Device basis.
Non-Rollover: Any unused Query allocations at the end of the calendar month do not roll over to the subsequent period.
Add On Packages: Customers may license incremental Subscription Units to increase their entitlements for Queries (via add-on packages) at any time during the Subscription Period, by placing an additional Order.
Usage Monitoring: Netskope will monitor the Customer’s actual usage and notify a Customer when the average number of Queries per day exceeds the entitlement. Customers may request usage reports from their Account Team.
Measurement and Enforcement
Measurement Methodology: Netskope measures User and Device usage based on the number of unique Users and Devices observed over a rolling 90-day period.
For Queries, Netskope measures Query usage based on the number of unique Queries observed in a month, divides the total amount by the number of days that month to calculate the daily average. The daily average is compared to the Query entitlement as defined in the applicable SKU.
Customer Example
- A customer licenses 1,000 Subscription Units of NK-DNSAAS-AT. While in a given month (30 days), the total DNS queries generated across all 1,000 users is 175,000,000 queries.
- Step 1: Calculate daily average per unit: 175,000,000 ÷ 30 days = 5,833,333 queries/day across 1,000 users = 5,833 queries/user/day.
- Step 2: Compare to entitlement: The daily average of 5,833 queries/user/day exceeds the 5,000 query/user/day cap.
- Step 3: Calculate the required Subscription Units to cover usage: 175,000,000 total queries ÷ 30 days ÷ 5,000 queries/unit/day = 1,167 units required.
- The Customer must purchase 167 additional Subscription Units to remediate the overage.
Overage Notification: Netskope will continually monitor traffic throughput and notify Customers in case of any excess usage.
Service Limitations: Netskope reserves the right to limit functionality should usage exceed the entitled number of Queries.
Overage Remediation
If monthly usage has exceeded Query entitlement by more than 10% for any two (2) months during the Subscription Period, then within 30 days of notification, the Customer is required to:
- License additional add-on packages sufficient to cover the highest monthly usage during that period. Queries may be licensed in packs of fixed minimum quantities.
- Cease usage exceeding the licensed entitlement.
Customer Records: The Customer may be required to provide system data, audit logs, or written confirmation of the number of Queries generated upon reasonable request by Netskope.

