The last layer before your traffic leaves the network.
Protocol Ward is a DNS resolver that runs on hardware you own. It blocks known-bad names, flags suspicious new ones on-device, and raises an alert when something on your network looks where nothing legitimate ever looks.
Every query is checked in memory against the blocklists and allowlists you configure. A blocklist hit is answered locally with the block response you choose, and the log names the list that matched. Allowlists win, so fixing a false positive takes one line in a file.
Behavioral detector
Names that miss every list are scored on-device from the hostname itself: how random it looks, how unusual its letter patterns are, digit density, consonant runs and length. Machine-generated names get flagged with the reasons behind the score. In the beta the detector flags and never blocks.
Decoys
Decoys are hostnames you plant that no legitimate client has a reason to resolve. A lookup is answered locally, is never forwarded, and raises a high-confidence alert naming the client that asked. Decoys never appear in an exported config.
Ward forwards the queries it decides to forward to the DNS-over-TLS upstreams you choose. Everything else happens on your machine. Detection runs locally, and there is no telemetry, cloud scoring or account. The same rule applies to every paid tier: those add signed feeds that your device pulls, plus opt-in alerts that carry alert metadata only and never your traffic.
Detectors produce a typed verdict with a score and reasons. Only Ward’s policy engine, a small, exhaustively cased state machine, turns a verdict into an action. A detector or a model cannot touch connection state directly.