Some embodiments enhance the security of
domain name resolution and other DNS operations by automatically intercepting DNS operations, determining an associated device identity, or ascertaining an associated user identity, and enforcing security policies based at least on the DNS operations and based on at least one of the identities. Some protectable DNS operations include request resolution, reverse lookup from an
IP address to
a domain name, DNS
record access, mail
server mapping, redirection, forwarding, and DNS
record caching operations. Implementing the policy includes, for example, blocking a result requested by the DNS operation, permitting computation progress towards the requested result, permitting different results, modifying the DNS
record, or flushing the DNS record from a cache. In some embodiments, a DNS operation
security function utilizes or implements a
conditional access security function, providing, for example, secure conditional
domain name resolution.