Skip to content
Kestrel, the Protocol Ward mascot, in flight.

The last layer before your traffic leaves the network.

Protocol Ward is a DNS resolver that runs on hardware you own. It blocks known-bad names, flags suspicious new ones on-device, and raises an alert when something on your network looks where nothing legitimate ever looks.

Fast path: blocklists

Every query is checked in memory against the blocklists and allowlists you configure. A blocklist hit is answered locally with the block response you choose, and the log names the list that matched. Allowlists win, so fixing a false positive takes one line in a file.

Behavioral detector

Names that miss every list are scored on-device from the hostname itself: how random it looks, how unusual its letter patterns are, digit density, consonant runs and length. Machine-generated names get flagged with the reasons behind the score. In the beta the detector flags and never blocks.

Decoys

Decoys are hostnames you plant that no legitimate client has a reason to resolve. A lookup is answered locally, is never forwarded, and raises a high-confidence alert naming the client that asked. Decoys never appear in an exported config.

The demos run Ward’s real Go code, compiled to WebAssembly. Nothing you type leaves your browser. Try the behavioral detector demo or the decoys demo.

Ward forwards the queries it decides to forward to the DNS-over-TLS upstreams you choose. Everything else happens on your machine. Detection runs locally, and there is no telemetry, cloud scoring or account. The same rule applies to every paid tier: those add signed feeds that your device pulls, plus opt-in alerts that carry alert metadata only and never your traffic.

The AI classifies. Deterministic code decides.

Section titled “The AI classifies. Deterministic code decides.”

Detectors produce a typed verdict with a score and reasons. Only Ward’s policy engine, a small, exhaustively cased state machine, turns a verdict into an action. A detector or a model cannot touch connection state directly.

Terminal window
go install protocolward.ai/ward/cmd/ward@latest

Then follow the Quickstart. The source is on GitHub, licensed under Apache-2.0 and free for any use.