# Features

Everything GraceDNS does is configured per configuration, so different networks and devices can get different protection. Each feature below has its own page with the details and the honest limits.

**[Threat protection](threat-protection.md)**: blocks domains and server addresses known for malware, phishing and botnet activity, updated continuously from independent intelligence sources.

**[Rebind protection](rebind-protection.md)**: stops public domains from answering with private network addresses, a trick used to attack devices inside your network from the outside.

**[Custom rules](custom-rules.md)**: your own deny and allow lists. Entries cover subdomains automatically, and your allowlist always wins.

**[Network rules](network-rules.md)**: link office or home IP ranges to a configuration, and block answers that point into IP ranges you choose.

**[Block types](block-types.md)**: choose how a block looks, from an invisible failed lookup to a visible block page, per configuration and per rule.

**[Query logs](query-logs.md)**: off by default. When you enable them, choose blocked-only or full logging; logs are stored in the EU, in the region you select, for as long as you decide.

Back to [docs](../index.md).
