A DNS firewall works outside the organization to block queries at the DNS level to prevent users and bots from reaching malicious sites. CIRA is a Canadian non-profit uniquely serving local organizations with cybersecurity solutions hosted in and peered to networks in Canada. We will use aggregate DNS data to review the threats we have seen in Canada. Using Kibana to analyze DNS queries for over 1,100,000 Canadian users, the presentation will:Review the most common threat-types and their frequency. Show the threat profiles of top-level domains (i.e. .CA versus .xyz).Compare the most visited and least visited domains and show what is learned by analyzing the long tail of low-volume domains.Show the geographic analysis of the threat origins, and how to detect anomalies. Observe some threat-peaks that the DNS data has detected before it hits security news (i.e. drive-by crypto-mining).Review the two new DNS tunnels (DoT and DoH) and their appropriate corporate use and risk impact in a cyber-secure network.