惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
B
Blog RSS Feed
The GitHub Blog
The GitHub Blog
Recent Announcements
Recent Announcements
A
About on SuperTechFans
G
Google Developers Blog
aimingoo的专栏
aimingoo的专栏
U
Unit 42
WordPress大学
WordPress大学
Y
Y Combinator Blog
罗磊的独立博客
J
Java Code Geeks
Microsoft Azure Blog
Microsoft Azure Blog
腾讯CDC
博客园 - 叶小钗
Stack Overflow Blog
Stack Overflow Blog
Engineering at Meta
Engineering at Meta
Microsoft Security Blog
Microsoft Security Blog
GbyAI
GbyAI
V
V2EX
雷峰网
雷峰网
H
Hackread – Cybersecurity News, Data Breaches, AI and More
S
SegmentFault 最新的问题
酷 壳 – CoolShell
酷 壳 – CoolShell

Blog on Tailscale

Why built-in router and NAS VPNs fall short Tailscale Kubernetes Operator 1.102: In-cluster relays, IPv6, and certificates Tailcat: An open-source CLI for Tailscale’s WireGuard®, NAT traversal, and DERP Build with Tailscale using tsnet, APIs, and automated sharing Tailscale PAM beta: Just-in-time access, session auditing, and more Aperture GA: model tokens, MCP controls, Projects, and custom permissions TailscaleUp 2026: a preview of Tailscale’s product updates How Tailscale helped find the SQLite WAL-Reset bug How Tailscale and Aperture mitigate the lethal trifecta for AI agents Tailscale in the Hugging Face intrusion: The good news and the bad news Mike Shaver joins Tailscale as VP of Engineering What a $20 Claude Code or Codex subscription actually buys, per Aperture Access Home Assistant Remotely with Tailscale | Guide Audit AI agent requests, logs, and access with Aperture A no-nonsense explainer to Agentic AI Database, Kubernetes, and SSH access without passwords | Border0 + Tailscale Tailscale adds log streaming for Azure Blob Storage Build a flexible AI stack with Aperture More Tailscale tricks for your jailbroken Kindle Redundancy only matters if you can reach it Fixing my ridiculous fridge with a tiny Funnel site Canada’s Bill C-22 and the security cost of collecting more data Introducing: Aperture CLI Five TailscaleUp sessions I’d attend if I didn’t work here Bambuddy: self-hosted 3D printing beyond the vendor cloud Fixing Headlamp OIDC login with Tailscale and tsidp How Cleric uses tsnet to securely automate software operations Tailscale + Paperless-ngx: scan everything, expose nothing Aperture, now in beta, adds the controls teams need for AI agents This month at Tailscale for April 2026
Tailscale and Control D: DNS filtering for your tailnet
Kabir Sikand · 2026-08-28 · via Blog on Tailscale

Teams that want to block malicious, phishing, or unwanted destinations can set up DNS filtering rules in Control D and apply those rules to any groups, tags, or devices in their tailnet with a simple access control list (ACL) integration. And starting today, you don’t have to go through another procurement process to do so.

Tailscale dashboard showing a Create Rule dialog for blocking domains. The form displays gambling.com as the domain to block, United States as the source location, Block action to prevent domain resolution, Root Folder selection, and a comment field with 64 characters remaining. A cyan Create button is positioned at the bottom of the modal.

How it works

Add Control D as a nameserver in the Tailscale admin console, and head over to your Control D dashboard to find a default security rule (or create a custom rule). In your Tailscale ACL, map the users, groups, or devices to the Control D rule. Your devices will then send DNS queries through Control D over encrypted DNS, applying the filtering ruleset you’ve just set up.

Tailscale will bill you for the number of users you need DNS filtering for. No need to predict how many devices, serverless nodes, or other infrastructure you’re going to have. Just let us know the size of your organization, and we’ll send you a simple user-based bill at the end of the month.

You still manage DNS filtering rules inside Control D, whether through the Dashboard or API.

Tailscale control dashboard showing Profiles page with four profile collections: Family Profile with 11 filters and 11 services, Secure with 0 filters and services, Server with 0 filters and services, and Tailscale Default with 7 filters, 35 services, and 117 rules. Left sidebar contains navigation for Profiles, Endpoints, Analytics, and Preferences.

Why Control D?

Control D is one of the fastest and most reliable DNS filtering services we’ve tried out (under 7 ms in North America). We already have customers using their service, and when we met the team behind Control D, we knew they were onto something great.

Control D blends threat feeds, malicious domain and IP detection, and machine learning to block malware, phishing, and suspicious domains. It’s consistently ranked as one of the top DNS malware blockers. Control D lets you filter by content categories, choose from a maintained list of over 1,000 services and apps, and write custom rules to block, allow, or redirect anything else. It gives you the same kind of straightforward control over the public Internet that Tailscale gives you inside your tailnet. Filter by recognizable domains and write custom rules to block, allow, redirect, or reroute traffic using Control D managed domain lists.

To purchase DNS Filtering by Control D, come have a chat with us.