FortiGuard DNS vs. Third-Party DNS: Why New Deployments Should Look Beyond FortiGuard’s Resolver

FortiGuard DNS vs. Third-Party DNS: Why New Deployments Should Look Beyond FortiGuard’s Resolver

· json · rss
Subscribe:

About

FortiGuard DNS vs. Third-Party DNSFortiGuard DNS vs. Third-Party DNS: Why New Deployments Should Look Beyond FortiGuard’s Resolver

FortiGate offers strong DNS security capabilities, but that does not automatically make FortiGuard’s own DNS service the best default resolver choice for every new deployment.

When administrators evaluate DNS in a FortiGate environment, two different functions are often mixed together: DNS security enforcement and recursive DNS resolution. FortiGate provides DNS-layer protection through features such as DNS Filter, FortiGuard category-based filtering, botnet C&C domain blocking, static domain filters, safe search enforcement, and external block lists. At the same time, Fortinet also supports secure DNS connectivity over DNS over TLS (DoT) to FortiGuard secure DNS when FortiGuard Anycast is enabled.

The key point is that these are not the same architectural decision. You can absolutely use FortiGate as the policy enforcement and inspection layer without making FortiGuard’s own recursive DNS or secure DNS endpoints your primary resolver. That distinction is important because it allows organizations to keep FortiGate’s DNS security controls while still choosing a different upstream resolver for better resilience, privacy posture, or performance.


Recommendation: For most new deployments, use a third-party recursive DNS provider such as Cloudflare or Quad9, while keeping FortiGate DNS filtering enabled as the local enforcement layer.

Why the Resolver Choice Matters

Recursive DNS is foundational infrastructure. If the resolver path becomes unstable, users experience failed or delayed name resolution regardless of how strong the firewall policy is. Fortinet’s public DoT status page for FortiGuard secure DNS shows that the service has had recent incidents, including a DNS DoT query outage on May 28, 2026, and the page also shows that some regions had less than 100% uptime over the previous 60 days. That does not mean FortiGuard is unusable, but it does raise a valid operational concern when designing greenfield deployments.

In other words, FortiGuard security intelligence may be valuable, but upstream DNS resolution itself should still be chosen with reliability and operational independence in mind. Treating these as separate design decisions gives you more flexibility and reduces the chance that a FortiGuard Anycast or DoT issue will directly affect core DNS availability.


FortiGuard DNS: Strengths and Weaknesses

Pros

  • Native integration with FortiGate security policies and security profiles.
  • Support for DNS-layer controls such as FortiGuard category-based filtering, botnet C&C domain blocking, static domain filtering, safe search enforcement, DNS translation, and external IP block lists.
  • Operational simplicity for Fortinet-centric environments where administrators want enforcement and visibility in a single platform.
  • Support for secure DNS over TLS when FortiGuard Anycast is enabled.

Cons

  • Dependency on FortiGuard Anycast-backed secure DNS availability if used as the main upstream resolver path.
  • Recent public incident history on Fortinet’s DoT status page shows that outages and regional availability issues do occur.
  • Less flexibility than choosing a dedicated public recursive DNS provider whose primary mission is resolver performance, privacy, or threat blocking.

Why Third-Party DNS Is Often the Better Default

A stronger design for new deployments is to let a specialized resolver provider handle recursive DNS, while the FortiGate remains responsible for DNS inspection, policy enforcement, and logging. Because FortiGate DNS filtering operates on DNS traffic traversing the firewall or on the FortiGate’s own interface-based DNS service, you do not need to use FortiGuard’s resolver to benefit from FortiGate’s DNS security features.

This hybrid model gives you the best of both worlds: a dedicated upstream DNS service for stability and performance, plus FortiGate-based enforcement for local control and visibility. For most organizations, that is easier to operate, easier to troubleshoot, and easier to justify architecturally.


Cloudflare: Best for Performance and Simplicity

Cloudflare’s public resolver at 1.1.1.1 is positioned around speed, privacy, and easy deployment. Cloudflare documents support for both DoH and DoT, and it also offers 1.1.1.1 for Families variants that can block malware or malware plus adult content. Cloudflare states that these filtered variants use the same privacy commitments as the standard 1.1.1.1 resolver.

Cloudflare also has one of the strongest public performance stories. DNSPerf’s public resolver rankings currently place Cloudflare at the top of its published performance list, making it a strong candidate for organizations that care about low latency and broad global coverage.


Cloudflare Pros

  • Very strong public performance reputation.
  • Simple deployment with clear DoH and DoT support.
  • Optional malware blocking and family-safe filtering variants.
  • Documented privacy commitments backed by independent assessment.

Cloudflare Cons

  • The default service is primarily a fast, clean recursive resolver rather than a security-first resolver by default.
  • If stronger DNS-layer blocking is desired, administrators must deliberately choose the filtered variants instead of the standard addresses.

Quad9: Best for Security-First and Privacy-Focused Deployments

Quad9 is a Swiss-based nonprofit focused on privacy and security. Its main secure resolver at 9.9.9.9 blocks domains associated with malware, phishing, scams, and other malicious activity. Quad9 supports DoT, DoH, and DNSCrypt, and it also provides DNSSEC validation on its secure services.

Quad9’s privacy position is especially attractive for organizations that want their resolver choice to align with a stronger data-minimization approach. Quad9 states that it does not log end-user IP addresses and highlights its Swiss legal jurisdiction as part of its privacy model.


Quad9 Pros

  • Security-first default behavior with malicious-domain blocking built into the main service.
  • Strong privacy posture and Swiss nonprofit governance model.
  • Support for DoT, DoH, DNSCrypt, and DNSSEC validation.

Quad9 Cons

  • A more opinionated security-first service can occasionally introduce false positives or exception-handling overhead.
  • It is generally chosen more for privacy and security than for having the strongest public latency benchmark story.

Recommended Approach for New Deployments

For most new FortiGate deployments, the most balanced architecture is:


  • Use Cloudflare if your priority is performance, simplicity, and easy encrypted DNS rollout.
  • Use Quad9 if your priority is security-first blocking and stronger privacy posture.
  • Keep FortiGate DNS filtering enabled so the firewall remains your enforcement and visibility layer.
  • Avoid making FortiGuard secure DNS / DoT the default upstream dependency for every deployment unless you have validated the service stability for your regions and requirements.

Final Verdict

FortiGuard DNS is valuable as a DNS security and filtering layer, but third-party DNS should usually be the default recommendation for new deployments.

FortiGate should remain the platform for inspection, logging, and enforcement. Upstream recursive DNS should be provided by a specialized resolver such as Cloudflare or Quad9, depending on whether your priority is performance or security-first privacy.

Sources

Last reviewed: June 2026