DNS filtering checklist for small teams: the free layer that blocks half the bad days

Every phishing link, every "your-invoice-is-here" domain and every sketchy redirect has to resolve through DNS before anything bad happens. Most small businesses leave that door wide open and spend their whole security budget on the rooms behind it. A filtering resolver — the kind free tiers of Cloudflare Gateway, Quad9 or CleanBrowsing offer — refuses to answer known-malicious and adult domains before the browser ever loads them. It is not antivirus and it will not save someone who pastes their password into a fake login page. But it kills a large share of drive-by and lure-traffic risk in one afternoon, for zero dollars, with no agent to install. This checklist is that afternoon.

1. Pick one filtering resolver and write down why

2. Set it on the router first — that covers guests and IoT for free

3. Turn on the category controls the tier already includes

4. Test the filter like you would test a fire alarm

5. Handle the laptops that leave the building

6. Log the exceptions before they become the back door

7. The quarterly five-minute re-check

DNS filtering for a small team is one free afternoon: choose one filtering resolver and write down why, set it in the router so guests and IoT inherit it, switch on the safe-search and new-domain controls the tier already includes, test the block from a wired machine, a guest phone and the printer, pin the resolver on the laptops that travel, log every exception with an owner, and re-run the five-minute test each quarter after anything touches the router. The Ops Starter Kit ($14) turns the exception log and the quarterly pass into fill-in-the-blank sheets, and the Automation Starter Pack ($19) schedules the recurring checks so the re-test happens without anyone remembering to remember.