# Which DNS security software do other SaaS companies trust for blocking malicious domains without adding latency that affects their own customers?

<p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">If you run infrastructure at a SaaS company, this one is familiar: you want to block malicious domains at the DNS layer, but not at the cost of adding latency your own customers would feel. Speed and security have to hold together. Software and IT reviewers keep pointing to the same few <a class="a a--md" elv="true" href="https://www.g2.com/categories/dns-security-solutions">DNS security tools</a> for this balance:</p><ul>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/cloudflare-application-security-and-performance/reviews"><strong>Cloudflare Application Security and Performance</strong></a> (4.5 stars, 616 reviews): Runs on a global edge network, and reviewers repeatedly describe security and CDN working together with no noticeable latency. Software teams use it to filter malicious traffic before it reaches origin servers. Worth knowing that advanced features sit in higher tiers.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/cisco-umbrella/reviews"><strong>Cisco Umbrella</strong></a> (4.4 stars, 284 reviews): Reviewers deploy it as a DNS forwarder using anycast IPs and describe blocking malicious domains before a connection is established, with little added overhead. A few smaller teams flag the cost.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/dnsfilter/reviews"><strong>DNSFilter</strong></a> (4.6 stars, 272 reviews): Reviewers who ran latency and stress tests against Cloudflare, Quad9, and Google reported very consistent, low-latency responses from DNSFilter's anycast network, along with accurate threat classification. Its satisfaction score is the highest of these three.</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">For the SaaS folks, has anyone measured the latency difference in practice, and did the tool you chose keep up as your query volume grew?</p>

##### Post Metadata
- Posted at: 3 months ago
- Author title: Marketer
- Net upvotes: 1


## Comments
### Comment 1

&lt;p&gt;&lt;span style=&quot;color: rgb(0, 0, 0);&quot;&gt;What stands out to me about Cisco Umbrella is blocking a malicious domain before the connection even gets established. Stopping it at that stage means it&#39;s not competing with your own traffic for anything downstream.&lt;/span&gt;&lt;/p&gt;

##### Comment Metadata
- Posted at: 16 days ago
- Author title: Marketing



### Comment 2

&lt;p&gt;Worth separating two things the question blends together. A DNS filtering resolver sits in front of outbound lookups from your own machines and network, so it affects your team and your servers&#39; egress. Customer requests coming into your app don&#39;t traverse it at all unless you&#39;ve deliberately put it in that path. So the latency worry splits in two: &quot;will my team notice&quot; is a straightforward question, and &quot;will my customers notice&quot; really only applies to whatever your backend looks up on their behalf inside a request, like a third-party API call. Once you know which of those you&#39;re actually asking, the test to run gets much clearer, and it&#39;s a different test in each case.&lt;/p&gt;

##### Comment Metadata
- Posted at: 17 days ago
- Author title: Tech Consultant



### Comment 3

&lt;p&gt;DNSFilter would be the one I’d want to benchmark first if latency is a hard requirement. The bigger test is whether response times stay predictable under sustained query volume, because a tool can look fast in a small test and behave very differently at scale.&lt;/p&gt;

##### Comment Metadata
- Posted at: 21 days ago
- Author title: Marketer



### Comment 4

I haven&#39;t benchmarked these myself, but the reviewers who have are worth reading closely: a few DNSFilter reviews describe head-to-head latency tests against Cloudflare, Quad9, and Google with very consistent results, which is more real measurement than most categories ever get. My honest read is that any of these anycast providers is unlikely to add latency a customer would feel, and the differences live in tail cases and how policies get evaluated. If I were running the test, I&#39;d measure from your actual customer regions at peak, not from a laptop at HQ, since that&#39;s where the complaints in reviews tend to come from.

##### Comment Metadata
- Posted at: 3 months ago





## Related discussions
- [How well does Trello scale into a larger team?](https://www.g2.com/discussions/1-how-well-does-trello-scale-into-a-larger-team)
  - Posted at: over 13 years ago
  - Comments: 6
- [Can we please add a new section](https://www.g2.com/discussions/2-can-we-please-add-a-new-section)
  - Posted at: over 13 years ago
  - Comments: 0
- [Quantifiable benefits from implementing your CRM](https://www.g2.com/discussions/quantifiable-benefits-from-implementing-your-crm)
  - Posted at: over 13 years ago
  - Comments: 4


