Protect remote workers on any network
A DoH profile, no client software.
Home Wi-Fi, hotels, airports. DoH and DoT endpoints and virtual sites extend policy to every device.
| Timestamp | Action | Site | Query Name | Source IP | Reason |
|---|---|---|---|---|---|
| 2026-09-15 19:03:10 | accept | vs-laptop-jlee | outlook.office365.com | doh | allow list |
| 2026-09-15 19:03:22 | block | vs-laptop-jlee | torrent-tracker.cc | doh | category: P2P |
| 2026-09-15 19:04:01 | threat | vs-laptop-jlee | invoice-view.click | doh | feed: malware-domains |
| 2026-09-15 19:04:37 | greywall | vs-laptop-jlee | newsletter-cdn.win | doh | first seen, held 24h |
The network you do not control is the one they use
The corporate resolver protects the office. The laptop at the kitchen table resolves through the ISP, the hotel captive portal or a public DoH provider. Roaming clients add software to maintain and a tunnel to keep up.
No resolver, no policy
Off the VPN the device uses whatever resolver the network hands it.
Agents bloat the endpoint
Another client to install, update and support on every laptop.
No record of the click
The phishing link opened at home is invisible to the office logs.
One profile, every network
Create a virtual site
A DoH address bound to a policy. The address identifies the device group and is handled as a credential.
Push the DoH profile
macOS, Windows, iOS, Android and ChromeOS accept a DoH profile through MDM. Browsers accept a custom provider.
Same policy, same log
The laptop resolves under the corporate policy wherever it is. Events carry the virtual site name.
Remote workforce controls
DoH virtual sites
Policy assignment without a static IP. One address per device group or per user.
MDM profiles
Encrypted DNS configured by the device manager. Nothing for the user to install or disable.
Full policy
Categories, lists, feeds and the Greywall apply to the roaming device exactly as in the office.
Per-device events
Traffic Logs show the virtual site on every lookup. The user who clicked is in the log.
Rotation
Rotate a virtual site by creating a new one and updating the profile. No downtime.
Global anycast
The Securd anycast network answers wherever the device connects.
The whole deployment is a URL
The virtual site URL goes into the MDM DoH profile. Rotate by issuing a new virtual site and updating the profile.
https://doh.securd.com/<virtual site address>- chatgpt.com
- claude.ai
- copilot.microsoft.com
- free-gpt-unlimited.xyz
Questions teams ask
Does this require a VPN?
No. The DoH profile applies on any network. The VPN remains for private application access.
What if the user changes the DNS setting?
Managed devices lock the profile through MDM. Unmanaged devices are not governed.
Does it work with Chrome and Firefox?
Both accept a custom DoH provider. The DoH page has the settings for browsers and operating systems.
Cover remote laptops without another agent
One virtual site, one MDM profile, and every device is under policy.