In this article
IT admins, security analysts, MSP partners, and enterprise compliance teams use this article to connect and use the DNSFilter MCP connector with Claude and other MCP-compatible AI assistants.
The DNSFilter MCP connector enables natural language interaction with DNSFilter data and configuration directly inside an AI assistant. A single connector provides access to three capability areas: administrative operations, DNS reporting, and CyberSight behavioral telemetry. All access is governed by per-user OAuth, privacy settings enforced at the session level, and a confirmation gate on all write operations.
Prerequisites
The following requirements apply before connecting the DNSFilter MCP connector:
- A DNSFilter account with admin permissions or higher
- A Core, Plus, or Enterprise plan. Pro plan accounts do not have access to the MCP connector
- An MCP-compatible AI assistant (Claude or equivalent)
- A CyberSight subscription to access CyberSight behavioral telemetry
- If using Claude, admin permissions to add connectors. If this permission is not available, contact a Claude admin to complete the connection setup
✍️ If the account is on a Pro plan, the connector will appear to connect successfully but every request will return: "MCP access is not included in this organization's plan. Upgrade the plan to enable access." After upgrading to an eligible plan, disconnect and reconnect the connector in the AI client to restore access immediately. Without reconnecting, the previous plan restriction may remain in effect for up to 24 hours.
Connect the DNSFilter MCP connector
To connect the DNSFilter MCP connector:
- From the DNSFilter dashboard, navigate to Integrations
- Under AI Connectors, select DNSFilter MCP Server
- Copy the MCP Server URL:
https://mcp.dnsfilter.com/mcp - In Claude, navigate to Settings and select Connectors
- Select Add custom connector and paste the MCP Server URL
- Sign in with DNSFilter account credentials via OAuth
The connector is now active. All three capability areas are available within the same session.
✍️ If the DNSFilter account uses SSO, enter only the SSO key in the sign-in field, not the full SSO URL. For example, for the SSO URL https://app.dnsfilter.com/login/1234567890, enter only 1234567890.
✍️ If the account was recently upgraded from a Pro plan to an eligible plan, access to the MCP connector may take up to 24 hours to activate.
✍️ Re-authentication is required every 7 days. The connector will prompt for sign-in again at that interval.
Admin capability
The Admin capability provides natural language access to administrative operations in the DNSFilter account. Use this to look up organizations, configure policies, manage users and seats, update block page settings, troubleshoot deployments, and monitor account health.
Write operations require confirmation. Every admin action that modifies data, such as policy changes, Block List updates, or user management, displays a confirmation prompt before the change is made. No write operation runs without explicit approval in the conversation.
Example prompts:
- "Why was this domain blocked for user@example.com?"
- "Add domain.com to the Block List for the Acme organization"
- "Show me all Roaming Clients that haven't checked in for more than 7 days"
- "How many seats are available in our account?"
- "Update the block page message for the Acme organization"
✍️ The following actions are not available in the Admin capability: billing changes, SSO or SAML configuration, and organization creation or deletion.
DNS Reporting capability
The DNS Reporting capability provides natural language investigation and reporting over DNS query logs. Use this to look up recent query history by user or device, explain why a query was blocked or allowed, analyze query patterns, surface blocked request volume, and identify DNS anomalies.
The DNS Reporting capability is read-only. No write operations are available.
✍️ The DNS Reporting capability returns data in UTC time. The DNSFilter dashboard displays some data in local time. Results from the connector may appear to differ from the dashboard when time zones do not align. Adjust queries to account for the UTC offset when comparing connector results to dashboard data.
Example prompts:
- "Show me DNS traffic for user@example.com over the last 7 days"
- "Why was this domain blocked for device LAPTOP-001?"
- "What are the top blocked domains across the organization this month?"
- "Are there any unusual query patterns for this site in the last 24 hours?"
- "Show me the top categories for Site: HQ Network over the last 7 days"
CyberSight Reporting capability
The CyberSight Reporting capability provides natural language investigation and reporting over CyberSight behavioral telemetry. Use this to look up user and device activity, investigate traffic patterns, surface behavioral anomalies, and generate investigation summaries.
CyberSight subscription required. The connector checks for an active CyberSight entitlement on connection. CyberSight tools are not available to organizations without an active subscription.
Privacy mode is enforced automatically. The organization's privacy setting, Full Visibility, Device-Only, or Maximum Privacy, is applied on connection and enforced on every query. Privacy settings cannot be bypassed or overridden through the connector.
Query depth: DNS query log and CyberSight data is available for up to 30 days. Queries beyond 30 days may have degraded performance due to index lifecycle limits.
Example prompts:
- "What applications has this device been using most this week?"
- "Are there any users showing unusual after-hours activity?"
- "Generate an investigation summary for device: LAPTOP-001"
- "Show me streaming activity for user@example.com over the last 7 days"
- "Which users are showing the most risk this week?"
Governance and compliance
All access through the DNSFilter MCP connector is governed by an AI-approved endpoint model. Only endpoints explicitly approved for AI access are reachable through the connector. No other API surface is accessible.
Auditability: All read operations are instrumented. All write operations are logged and attributable to the authenticated user.
Write confirmation gate: No write operation runs without explicit in-conversation confirmation from the authenticated user. This applies to every Admin capability action, without exception.
Privacy enforcement: Privacy settings are applied on every connection. There are no exceptions, overrides, or elevated access paths through the connector.
MSP scoping: Each session is scoped to a single organization. MSP admins must select an organization context before querying data for that organization.
Comments
0 comments
Please sign in to leave a comment.