By category
Where blocking decisions came from.
- Phishing18
- Malware11
- C2 / Botnet9
- Ads & tracking5
- Cryptomining4
- Newly registered2
Repeat offenders
Domains blocked most often in 7 days.
| Domain | Category | Blocks | Last seen |
|---|---|---|---|
| phishing-demo.example | Phishing | 15 | 11:19 UTC |
| malware-sim.test | Malware | 9 | 11:12 UTC |
| c2-lab.test | C2 / Botnet | 6 | 11:04 UTC |
| mining-pool-demo.test | Cryptomining | 4 | 10:52 UTC |
| beacon-demo.example | C2 / Botnet | 3 | 10:41 UTC |
| login-verify-demo.test | Phishing | 3 | 11:19 UTC |
| tracker-demo.example | Ads & tracking | 3 | 11:10 UTC |
| fresh-domain-3f21.example | Newly registered | 2 | 09:58 UTC |
| metrics-demo.test | Ads & tracking | 2 | 11:12 UTC |
| dropper-demo.invalid | Malware | 1 | 11:12 UTC |
| payload-lab.test | Malware | 1 | 11:11 UTC |
Recent blocks
Select a row to see why it was blocked. Every domain here is a reserved demo name.
| Time | Domain | Client | Category | Intelligence source | Reason |
|---|---|---|---|---|---|
| 11:19:48 | phishing-demo.example | guest-laptop192.168.20.22 | Phishing | Phishing intelligence (demo) | Domain is on a phishing list |
| 11:19:02 | login-verify-demo.test | workstation-01192.168.10.24 | Phishing | Phishing intelligence (demo) | Domain is on a phishing list |
| 11:12:44 | dropper-demo.invalid | lab-thermostat192.168.30.5 | Malware | Malware domains (demo) | Domain is on a malware distribution list |
| 11:12:29 | metrics-demo.test | guest-phone192.168.20.7 | Ads & tracking | Advertising & tracking (demo) | Domain is an advertising or tracking endpoint |
| 11:11:34 | payload-lab.test | lab-build-01192.168.30.41 | Malware | Malware domains (demo) | Domain is on a malware distribution list |
| 11:10:20 | tracker-demo.example | guest-laptop192.168.20.22 | Ads & tracking | Advertising & tracking (demo) | Domain is an advertising or tracking endpoint |
| 11:07:02 | metrics-demo.test | guest-laptop192.168.20.22 | Ads & tracking | Advertising & tracking (demo) | Domain is an advertising or tracking endpoint |
Decision record
DNS Daddy records the evidence it used at the moment the decision is made.
Sequence
DNS event
invoice-check.example · A
Evidence
Synthetic phishing feed — Listed — phishing Google Safe Browsing — Malicious
Decision
Block — Standard policy
Response
NXDOMAIN
Evidence used
- Synthetic phishing feed2026-08-11 09:12 UTC
Threat feed · Listed — phishing
Present in the phishing category list loaded at the last feed refresh.
- Google Safe Browsing2026-08-11 10:48 UTC
External intelligence · Malicious
Cached verdict, read without waiting on the provider during resolution.
- Standard policy — phishing enabled2026-08-11 11:12 UTC
Policy rule · Block, respond NXDOMAIN
The policy assigned to Office LAN blocks the phishing category.
- Client
- 192.168.10.31 · laptop-02
- Network
- Office LAN
- Action
- Block
- DNS response
- NXDOMAIN
- Decided at
- 11:12:04 UTC
- Decision cost
- 1.4 ms
The lookup matched listed phishing evidence, the policy for this network blocks that category, and the configured block response is NXDOMAIN. DNS Daddy writes the evidence it used at the moment the decision is made, so the reason can be read back later without re-querying anything.
Demo intelligence is synthetic. Domains use reserved .example, .test and .invalid namespaces and are not real threat infrastructure. Behavioural detections are shown separately under Detections and never block on their own.