Blog

Fix the TLS 1.3 Hostname Visibility Gap with IP Categorization

Fix the TLS 1.3 Hostname Visibility Gap with IP Categorization

For years, security vendors made a quiet assumption: when a device on your network opens a TLS connection, the Server Name Indication (SNI) field in the ClientHello will tell you exactly where it's going. That hostname became the foundation of every DNS filter, every...

DNS Blocklist Feeds: How to Evaluate What You’re Actually Getting

DNS Blocklist Feeds: How to Evaluate What You’re Actually Getting

If you're evaluating DNS blocklist feeds, you already know what they do. This post skips the explainer and gets to the part that actually matters: how to tell whether the feed you're running—or considering—is actually any good. Most teams set up a DNS blocklist once...

alphaMountain Now Classifies 92 Web Filtering Categories

alphaMountain Now Classifies 92 Web Filtering Categories

Your DNS filter sees every query your network generates. But seeing a query and understanding it are two different things. Most URL classification systems were built around a specific assumption: the host being queried is a website, and the website has content worth...

The Ultimate Web Classification Guide (2026)

The Ultimate Web Classification Guide (2026)

**Updated for 2026 to include new categories: DNS Over HTTPS, Local/Non-Routable, Network Access/Captive Portal. If you manage a firewall rule-set, write secure-web-gateway policies, wrangle CASB shadow-IT reports, or simply lose sleep over which URLs your workforce...