惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
博客园 - 聂微东
人人都是产品经理
人人都是产品经理
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园_首页
量子位
阮一峰的网络日志
阮一峰的网络日志
酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hackread – Cybersecurity News, Data Breaches, AI and More
云风的 BLOG
云风的 BLOG
D
DataBreaches.Net
B
Blog
L
LangChain Blog
Apple Machine Learning Research
Apple Machine Learning Research
Vercel News
Vercel News
博客园 - 三生石上(FineUI控件)
爱范儿
爱范儿
Microsoft Azure Blog
Microsoft Azure Blog
IT之家
IT之家
aimingoo的专栏
aimingoo的专栏
B
Blog RSS Feed
H
Help Net Security
The Cloudflare Blog
U
Unit 42

Blog on Tailscale

Why built-in router and NAS VPNs fall short Tailscale Kubernetes Operator 1.102: In-cluster relays, IPv6, and certificates Tailcat: An open-source CLI for Tailscale’s WireGuard®, NAT traversal, and DERP Build with Tailscale using tsnet, APIs, and automated sharing Tailscale PAM beta: Just-in-time access, session auditing, and more Aperture GA: model tokens, MCP controls, Projects, and custom permissions TailscaleUp 2026: a preview of Tailscale’s product updates How Tailscale helped find the SQLite WAL-Reset bug How Tailscale and Aperture mitigate the lethal trifecta for AI agents Tailscale in the Hugging Face intrusion: The good news and the bad news Mike Shaver joins Tailscale as VP of Engineering What a $20 Claude Code or Codex subscription actually buys, per Aperture Access Home Assistant Remotely with Tailscale | Guide Audit AI agent requests, logs, and access with Aperture A no-nonsense explainer to Agentic AI Database, Kubernetes, and SSH access without passwords | Border0 + Tailscale Tailscale adds log streaming for Azure Blob Storage Build a flexible AI stack with Aperture More Tailscale tricks for your jailbroken Kindle Redundancy only matters if you can reach it Fixing my ridiculous fridge with a tiny Funnel site Canada’s Bill C-22 and the security cost of collecting more data Introducing: Aperture CLI Five TailscaleUp sessions I’d attend if I didn’t work here Bambuddy: self-hosted 3D printing beyond the vendor cloud Fixing Headlamp OIDC login with Tailscale and tsidp How Cleric uses tsnet to securely automate software operations Tailscale + Paperless-ngx: scan everything, expose nothing Aperture, now in beta, adds the controls teams need for AI agents This month at Tailscale for April 2026
Tailscale and Control D: DNS filtering for your tailnet
Kabir Sikand · 2026-08-28 · via Blog on Tailscale

Teams that want to block malicious, phishing, or unwanted destinations can set up DNS filtering rules in Control D and apply those rules to any groups, tags, or devices in their tailnet with a simple access control list (ACL) integration. And starting today, you don’t have to go through another procurement process to do so.

Tailscale dashboard showing a Create Rule dialog for blocking domains. The form displays gambling.com as the domain to block, United States as the source location, Block action to prevent domain resolution, Root Folder selection, and a comment field with 64 characters remaining. A cyan Create button is positioned at the bottom of the modal.

How it works

Add Control D as a nameserver in the Tailscale admin console, and head over to your Control D dashboard to find a default security rule (or create a custom rule). In your Tailscale ACL, map the users, groups, or devices to the Control D rule. Your devices will then send DNS queries through Control D over encrypted DNS, applying the filtering ruleset you’ve just set up.

Tailscale will bill you for the number of users you need DNS filtering for. No need to predict how many devices, serverless nodes, or other infrastructure you’re going to have. Just let us know the size of your organization, and we’ll send you a simple user-based bill at the end of the month.

You still manage DNS filtering rules inside Control D, whether through the Dashboard or API.

Tailscale control dashboard showing Profiles page with four profile collections: Family Profile with 11 filters and 11 services, Secure with 0 filters and services, Server with 0 filters and services, and Tailscale Default with 7 filters, 35 services, and 117 rules. Left sidebar contains navigation for Profiles, Endpoints, Analytics, and Preferences.

Why Control D?

Control D is one of the fastest and most reliable DNS filtering services we’ve tried out (under 7 ms in North America). We already have customers using their service, and when we met the team behind Control D, we knew they were onto something great.

Control D blends threat feeds, malicious domain and IP detection, and machine learning to block malware, phishing, and suspicious domains. It’s consistently ranked as one of the top DNS malware blockers. Control D lets you filter by content categories, choose from a maintained list of over 1,000 services and apps, and write custom rules to block, allow, or redirect anything else. It gives you the same kind of straightforward control over the public Internet that Tailscale gives you inside your tailnet. Filter by recognizable domains and write custom rules to block, allow, redirect, or reroute traffic using Control D managed domain lists.

To purchase DNS Filtering by Control D, come have a chat with us.