Changelog
Follow up on the latest improvements and updates.
RSS
improved
fixed
Windows Roaming Client
RC Release Channels
Beta
09/30 September 30 – Windows Roaming Client v3.8.15 Beta
Version 3.8.15 of the Windows Roaming Client is now available on the
Beta channel
. To install, download the latest beta installer from the dashboard under Deployments → Roaming Clients → Beta Channel
.🛠️ Improvements
- Lower CPU Usage, Including on ARM64: The Roaming Client now reads device identity, OS version, and adapter DNS settings directly from Windows APIs instead of WMI. WMI Provider Host CPU usage stays low on all devices, including cellular-connected laptops, and startup is faster.
- Resilient Local Resolver Handling: The Roaming Client now tells confirmed answers apart from resolver errors and empty responses, and every local resolver check has a timeout. Internal name resolution stays accurate through resolver outages, sleep and wake, and network changes.
- Local Domain Fallback Control: The newLocalDomainFallbackEnabledsetting controls whether local-domain queries your internal resolvers can't answer go to DNSFilter or stay on your network. Use it for split-horizon domains and internal zones that should never resolve publicly.
🔒 VPN Compatibility
- Conflicting VPN Agents in Classic Mode: In Classic DNS Filtering,Disable Roaming Clients for Conflicting VPN Agentsnow applies to all devices, and VPN adapter traffic is left to the VPN.
- PreCheck on VPN Connections: PreCheck now gives the device's resolver its own response window, so queries over VPN tunnels resolve reliably even when the tunnel's resolver is slower than DNSFilter's policy check.
- Automatic DNS Restore: If a VPN connecting or disconnecting, or an unexpected shutdown, leaves network adapters pointed at the filtering proxy, the Service Manager restores DNS and re-registers the device automatically.
🪲 Bug Fixes
- ISP DNS interception:On networks where the ISP intercepts DNS, the Roaming Client moves the query to the next protocol in your configured order (for example, DNS-over-TLS) so sites load normally
- Active Directory:Domain-joined devices in Transparent Proxy and PreCheck modes now register their DNS records with the domain controller using secure dynamic updates
- Diagnostic Tool:SelectingOtheras the reason now lets you enter a custom description and run diagnostics
- Block Page:Blocked HTTPS sites now show the block page with no certificate warning on MSP organizations created after September 15
new
Web App
API
09/29 September 29 – Web Application and API Update
✨ What's New
Branding Settings Now Available to Additional MSPs
– MSPs without a custom domain configured now have access to the new Branding settings page, replacing the legacy Whitelabel form. Existing logos carry over automatically — no re-upload required.🛠️
Improvements
Query Log Pagination
– The Query Log now uses cursor-based pagination, replacing page-number paging. Navigation moves forward and back through results with stable, reliable loads.Grid Filter UX Cleanup
– Two filter improvements across deployment and policy grids: the Add Filter button now disables automatically once all available filters have been applied, and the redundant Filters option has been removed from grids where the search bar already covers all filtering (Policies, Allow List, Block List, and Universal Lists).Unblock Requests Category Data
– The Category column in the Unblock Requests grid now shows domain category information even when a domain was blocked for a non-category reason (such as a Block List, AppAware, or Security block), giving admins more context when reviewing requests.License Overage Banner Restored on Dashboards
– The license overage warning and critical banners are now visible on Custom Dashboards, restoring alert visibility that was lost when the legacy Overview page was retired.🪲
Bug Fixes
Block Page Preview Restored
– Resolved an issue where previewing a custom Block Page displayed the default DNSFilter block page instead of the configured one, omitting the organization's logo, name, and Unblock Request button.Block Page Editor False Unsaved Changes Warning
– Resolved an issue where opening any Block Page edit view immediately activated the Save and Discard buttons — even with no changes made — prompting an "unsaved changes" warning on every navigation attempt.Scheduled Reports Logo for Branding MSPs
– Resolved an issue where net-new MSPs using the Branding settings page saw the default DNSFilter logo on Scheduled Reports instead of their uploaded logo.Plus general performance and stability improvements across the dashboard.
new
fixed
improved
Mac Roaming Client
RC Release Channels
09/23 September 23 - macOS Roaming Client v2.4.6 Production
Version 2.4.6 of the macOS Roaming Client is now available on the
Production
channel. This release brings together every update from the 2.4 Beta series (v2.4.0 through v2.4.6). To install, download the latest production installer from the dashboard under Deployments → Roaming Clients
. Auto-upgrades will roll out gradually.⚠️ Action Required: Redeploy the Updated Certificate Profile
v2.4.6 checks for the new
DNSFilter Root CA G1
certificate. Devices that still have the previous certificate profile will show a Fix Installation Issues
prompt in the menu bar after upgrading. Filtering and protection keep working normally while the prompt is showing.
To clear the prompt, download the updated
Combined_Certificates.mobileconfig
(or the branded or white-label profile you deploy) from the Prerequisites section of the macOS Roaming Client install guide and push it through your MDM. The updated profile replaces the installed one in place. We recommend pushing it before auto-upgrade reaches your devices.⚠️
Minimum macOS Version:
The macOS Roaming Client now requires macOS 13 Ventura or later.✨ What's New
- IPv6 Support: Filtering and protection now cover IPv6 networks, so users on dual-stack and IPv6-only networks stay protected. Administrators can set upstream resolution to IPv4-only, IPv6-only, or automatic.
- Filtering Stays On Through a VPN (Opt-In): Devices using encrypted DNS now keep DNSFilter filtering on while a corporate VPN is connected, even when the tunnel blocks the DNS-over-TLS port. Filtering switches to DNS-over-HTTPS, so remote and hybrid users on VPN stay protected and keep encrypted DNS. To turn it on for an install, setENABLE_DOH_FALLBACK=true. The deployment guide covers setup and network requirements.
- Component Version Mismatch Detection: The Roaming Client now detects when the menu bar app, system extension, and daemon are running different versions, which can happen after upgrades or MDM-managed installs. When it finds a mismatch, it alerts the user, who can fix it from the menu.
- Modernized Configuration Architecture: The agent now uses a more resilientconfiguration.jsonformat in place of the legacydaemon.conf. Configuration changes apply more reliably without restarting the agent, and existing installations migrate automatically on upgrade. Upstream protocol order settings, including DNS-over-TLS, now apply as configured.
- Local Domains Stay Current: Changes to local domains and resolvers made in the dashboard now apply right away, with no daemon restart needed, and internal domains stay on their assigned local resolvers after restarts and upgrades.
🛠️ Improvements
- Every Certificate Root in One Profile: The macOS certificate profiles now install all DNSFilter roots in a single push, including DNSFilter Root CA G1.
- Travel Wi-Fi Keys Match the Docs: Install-time configuration keys now use the same Travel Wi-Fi names as the dashboard and documentation, and Travel Wi-Fi settings indns_agent.confapply at CLI install. Existing scripts that use the previous names keep working.
- More Resilient Connectivity: The agent's connection handling and upstream failover have been rebuilt, so devices stay filtered as networks change, with less need for a manual restart.
🪲 Bug Fixes
- Captive portals:Captive portal detection is more accurate, the Access Captive Network option clears once you're connected, and Travel Wi-Fi appears as expected when configured through JSON
- Site assignment:Changing a device's Site Key now properly updates its site and policy in the dashboard
- Menu bar:The menu bar icon stays responsive and shows the right state when there's no network connection, and Travel Wi-Fi mode stays in the menu after a reboot
- Diagnostics:Diagnostics are collected more securely and include more complete information
new
Web App
API
09/22 September 22 – Web Application and API Update
🛠️
Improvements
- "Blocked By" Column in Unblock Requests– The Active Requests and Request History grids now include a Blocked By column showing the reason each domain was blocked, consistent with the Query Log's Method column. The blocking reason is also visible in the approval drawer.
- Unblock Request Admin Email Improvements– Admin notification emails for unblock requests now include a direct link to the Unblock Requests page, with the subject line including the requester's organization name. Emails route to the correct MSP or organization view depending on which block page the request came from.
- Type-to-Confirm for Roaming Client Delete and Cleanup– Deleting Roaming Clients and running a cleanup deletion now require typing to confirm before the action completes, preventing accidental mass deletions and aligning with the destructive-action standard used elsewhere in the platform.
- Deployment Access Controls for Restricted Roles– Read-only and policy-only users now see deployment controls correctly scoped to their permissions across Sites, Relays, and Roaming Clients: Site Keys are hidden, Relay deployment controls and Site Keys are disabled, and Roaming Client installer access is restricted, each with a clear tooltip directing users to contact a dashboard admin.
- Last Logged In User and Friendly Name in CyberSight Top Clients– The Top Clients View All grids on CyberSight Activity Overview and AI Usage now show Last Logged In User by default and offer Friendly Name as an optional column — so admins can identify the person behind a Roaming Client without leaving the grid.
🪲
Bug Fixes
- Query Log FQDN Filter Now Matches Correctly– Resolved issue where the FQDN filter in the Query Log was matching against the Domain column instead of the FQDN column. Filtering by a specific subdomain now correctly returns matching results.
- Dashboard Requests Activity Chart Off by One Day– Resolved a timezone offset issue where the 7-day and 30-day Requests Activity chart on Dashboards showed zero traffic for the current day, with all buckets shifted by one day for users in UTC-negative timezones.
- Column Drag-to-Reorder Restored in Deployment Tables– Resolved an issue where dragging columns to reorder them in the Roaming Clients, Sites, and Relays grids either did nothing or moved the wrong column. Column reordering now works correctly across all deployment tables.
- CyberSight Timeline "Exclude Weekends" Filter– Resolved an issue where the Exclude Weekends toggle had no effect on the Activity Breakdown and Timeline widgets, which continued showing identical totals regardless of the setting.
- MCP Server Entitlement Cache After Plan Upgrade– Resolved an issue where users who upgraded from a plan without MCP Server access still received entitlement errors in a new session until reconnecting. The entitlement cache now reflects plan changes without requiring a manual reconnect.
- Sales Managed Plan Cascade on Plan Change– Resolved an issue where Sales Managed MSP client organizations were not automatically updated to the highest available plan when a plan change was made at the account level, leaving organizations on a plan that no longer existed on the account.
- Branding: Dashboard Name API Validation– Resolved an issue where the Dashboard Name field had no server-side character limit, allowing values set via API to exceed the 128-character maximum enforced in the UI, which could cause layout issues across login, browser tab, and report surfaces.
Plus general performance and stability improvements across the dashboard.
new
improved
fixed
Mac Roaming Client
RC Release Channels
Beta
09/16 September 16 – macOS Roaming Client v2.4.6 Beta
Version 2.4.6 of the macOS Roaming Client is now available on the
Beta channel
. To install, download the latest beta installer from the dashboard under Deployments → Roaming Clients → Beta Channel
.✨
What's New
Filtering Stays On Through a VPN (Opt-In)
– Devices using encrypted DNS now keep DNSFilter filtering enforced while a corporate VPN is connected, even when the tunnel blocks the DNS-over-TLS port. Filtering continues over DNS-over-HTTPS, so remote and hybrid users stay protected on VPN without giving up encrypted DNS. Turn it on per install with ENABLE_DOH_FALLBACK=true
; see the deployment guide for setup and network requirements.🛠️ Improvements
Every Certificate Root in One Profile
– The published macOS certificate profiles now install all DNSFilter roots in a single push, including the new DNSFilter Root CA G1. Re-download the profile you already deploy and push it, and it replaces the installed one in place.Travel Wi-Fi Keys Match the Docs
– Install-time configuration keys now use the same Travel Wi-Fi naming as the dashboard and documentation. Existing scripts keep working with the previous names.🪲 Bug Fixes
- Fixed an issue where deploying with a configuration override and no site key cleared the existing device configuration.
- Fixed an issue where the Diagnostic Tool failed on the first run after a clean install.
- Improved how diagnostics are collected and what the diagnostic bundle includes.
new
Web App
API
09/15 September 15 – Web Application and API Update
✨
What's New
Unblock Request Management — Now Generally Available
– Admins can now manage user-submitted unblock requests directly from the dashboard. The new Unblock Requests page provides a full request queue with tools to Allow or Deny submissions, threat-category warnings on risky domains, an Investigate Mode row action for quick Query Log scoping, and CSV export of active and historical requests.Redesigned Branding Experience for MSPs
– The Whitelabel settings page has been redesigned as a dedicated Branding page, with Logo, Favicon, Dashboard Name, and Subdomain URL now managed as individual, first-class branding objects. Net-new MSPs onboarded after September 15 configure a branded subdomain (yourdomain.app.dnsfilter.app) and are set up with current branding defaults without legacy Whitelabel configuration.🛠️
Improvements
Local Domains Copy Clarification
– In-app copy in the Local Domains and Resolvers section now clearly notes that Local Domains and Resolvers only apply in Classic DNS Filtering Mode — Roaming Clients configured in Custom or PreCheck mode do not require local domain configuration.Roaming Client Installer Access by Role
– Read-only and policy-only users now see the Roaming Client installer as disabled with a clear tooltip explaining that elevated permissions are required, rather than having full access to the installer download.🪲
Bug Fixes
Dashboard Deployment Widgets Now Respond to Site Filter
– Resolved an issue where the Roaming Clients Protected and Relays widgets on organization-level dashboards did not update when filtering by Site.MSP Custom Dashboard Filter Scope
– Resolved an issue where an organization filter applied on the MSP-level Custom Dashboard could carry over when navigating into an organization's dashboard, causing it to display filtered data rather than data scoped to that organization. Navigating to any organization dashboard now correctly scopes data to that organization.Plus general performance and stability improvements across the dashboard.
new
fixed
iOS Roaming Client
09/15 September 15 - iOS Roaming Client v1.4.5
A new version of the iOS Roaming Client is now available in the App Store and will begin rolling out to devices via Apple auto-updates today.
This release includes improvements to MDM configuration handling and device registration.
🛠️
Improvements
- Root certificates in the MDM profileThe.mobileconfigfile now includes the DNSFilter root certificates alongside the iOS Roaming Client configuration, so a single profile push installs both. Download the current file from the iOS Roaming Client deployment guide
- Reduced Background SyncRegistered devices now sync with the DNSFilter dashboard only when device state changes, rather than every 60 seconds
🪲
Bug Fixes
- Reinstalling no longer creates a duplicate recordReinstalling the iOS Roaming Client on a device now reuses that device's existing Roaming Client record instead of registering a new one. Records created before this release are not affected
- DNS over TLS (DoT) setting from MDMAdns_over_tls_enabledvalue offalseis now honored from first registration and persists across DNS extension restarts
- Live search domain updatesChanges todhcp_dns_search_domainsnow take effect within one configuration refresh, with no DNS extension restart required
- Last Logged in User on initial registrationThe value supplied inuserNamenow populates theLast Logged in Userfield as soon as a device registers
✨
What's New
DNSFilter MCP Server — Now Generally Available
– Connect an AI assistant to DNSFilter through the Model Context Protocol and work with your DNS data in natural language. A connected client can query DNS activity and threat data, manage policies and allow/block lists, and automate reports and investigations, without navigating the dashboard. Claude, ChatGPT, and Codex are all supported.Find it under
Integrations → AI Connectors
. Open the DNSFilter MCP Server card, copy the server URL, and follow the MCP Server setup guide to connect your client. Setup is admin-only, and once connected, the assistant sees exactly what the connecting user's permissions allow, nothing more. A connected client stays authorized for seven days before prompting to reconnect.Available on eligible plans. Check the setup guide for package eligibility.
new
Web App
API
09/08 September 8 – Web Application and API Update
🛠️
Improvements
- Sites Grid Edit Streamlined– Inline column editing has been removed from the Sites grid. All edits are made through the row Actions menu, keeping the editing experience consistent and intentional.
- CyberSight Top Applications Widget Clarification– A tooltip has been added to the Top Applications widget clarifying that usage time reflects only active foreground use, not background activity. This provides helpful context when comparing figures across CyberSight widgets.
- CyberSight Agent Stability and Data Accuracy– Several fixes to the Windows CyberSight agent addressing long-running issues: activity from administrator-level processes is now correctly recorded instead of being silently dropped; timestamps are no longer corrupted by malformed NTP responses; enabling CyberSight no longer overwrites Chrome or Edge managed extension policies; activity events are now correctly finalized on service shutdown instead of misattributing the entire offline period as active time; and the file parser no longer holds locks that blocked file deletion and app updates.
🪲
Bug Fixes
- Custom Dashboard Bookmarks Now Land on the Right Page– Resolved an issue where bookmarking a Custom Dashboard and logging in from that bookmark redirected to the Overview page instead. Custom Dashboard URLs now include the dashboard ID, making them fully bookmarkable as a login landing page.
- Roaming Client Export Row Limit– Resolved an issue where exporting Roaming Clients from the MSP level was capped at 999 rows, even when the account had thousands of endpoints. Exports now include all records as expected.
- Relay Row Selection– Resolved an issue where selecting any relay row crashed the Relays screen, replacing the grid with an error state. Row selection and bulk actions now work correctly.
- Users Page Policy Inheritance Text– Resolved an issue where the Policy/Schedule and Block Page columns on the Users page always showed "Inherit from Roaming Client," even for users in a Collection with its own applied policy. The columns now correctly show "Inherit from Collection" when applicable.
- Domain Report Long Policy Name Display– Resolved an issue where long policy names on the Domain Report's Categorization Summary and Policy Summary cards overflowed and became unreadable at standard screen widths. Policy names now truncate cleanly with an ellipsis.
Plus general performance and stability improvements across the dashboard.
new
Web App
API
09/01 September 1 – Web Application and API Update
✨
What's New
Customizable Dashboards Now the Default Experience
– The legacy Overview page has been retired and Dashboards is now the default landing view for all users. Existing links and bookmarks to the Overview page redirect to Dashboards automatically.🛠️
Improvements
Customizable Dashboard Filter Improvements
– The dashboard Filters drawer has been simplified and reorganized. Quick Filters and Advanced Filters have been merged into a single Filters experience, with filters now grouped by Source (Organizations, Sites, Roaming Clients/Relays, Users) and Traffic (Result). The time range control remains on the main dashboard view.Live Status Indicators on Deployment Widgets
– Dashboard widgets showing current deployment counts — Roaming Clients Protected, Sites Protected, Relays, Users, and Collections — now display a pulsating green dot to indicate they reflect live data and are not affected by the dashboard time range filter. Hovering the dot shows a tooltip confirming this.Top Level Domain Category Label
– Bare TLD entries (e.g. .ru, .xyz) in Allow/Block lists and the Query Log now display as "Top Level Domain" instead of "Uncategorized," making it easier to distinguish intentional TLD-level rules from genuinely uncategorized domains.🪲
Bug Fixes
Top Domains Widget Search Now Searches All Traffic
– Resolved an issue where the search box on the Top Domains dashboard widget only filtered the domains already loaded on screen, returning "No results" for any domain outside the top 20 even when traffic existed. The search now queries all traffic in the selected time range.Plus general performance and stability improvements across the dashboard.
Load More
→