Guides / NextDNS

Detect AI tools with NextDNS, no IT department required

NextDNS is the DNS filter small teams actually run: a profile per office or device group, logs in the dashboard, CSV a click away. That is a complete shadow AI sensor for a company with zero security headcount.

Layer: DNS
Identity: profile and device name
Format: CSV log download
Best for: 5 to 200 people
Run a free audit on a NextDNS export
Why this pairing works

The lightest full audit loop in this series

No SIEM, no syslog collector, no console permissions ceremony. NextDNS plus the audit is two dashboards and one CSV.

Setup you already did

If NextDNS filters your office and laptops, the logging is on. There is nothing to deploy for the audit; the sensor has been recording since day one.

Devices, not directories

SMBs rarely run AD. NextDNS identities are profiles and device names, which is exactly the attribution a 40-person company needs: whose laptop, which office.

Free-tier friendly

Small networks produce small logs. A week of a 40-person office often fits the free preview's 5,000 lines, making the first audit genuinely $0.

The export

One CSV from the logs view

Open your profile's logs, set the time range, download CSV. The columns below are the ones the audit reads.

timestamp,domain,device_name,profile,status "2026-09-16T09:31:04Z","chatgpt.com","MacBook-Lena","Office","default" "2026-09-16T09:32:47Z","fonts.gstatic.com","MacBook-Lena","Office","default" "2026-09-16T09:35:12Z","midjourney.com","Studio-iMac-2","Office","default" "2026-09-16T09:38:03Z","remove.bg","Studio-iMac-2","Office","default" "2026-09-16T09:41:29Z","otter.ai","iPhone-Tom","Mobile","default" "2026-09-16T09:44:55Z","suno.com","MacBook-Dario","Office","default"

Device names become the per-source table. The Mobile profile row matters: that iPhone transcribes meetings wherever it is.

Columns the audit uses

  • domain: the matched hostname, the only required field.
  • device_name / profile: the identity pair; either alone still works.
  • timestamp: keeps windows comparable between runs.
  • status: default vs blocked, useful policy evidence if you already block lists.

Two settings worth checking first

  • Log retention: make sure it covers the window you want to audit before you assume a month exists.
  • Device naming: renaming "iPhone (2)" to a person's device now pays off in every future report.
Worked scenario

The 40-person agency's audit diary

A creative agency: designers, copywriters, two founders, no IT staff. NextDNS on the office network and company laptops. Sample data, real shape.

FRI 16:20

A client's procurement form asks: "List AI tools used in service delivery." The founders realize they genuinely do not know. The form is due Wednesday.

FRI 16:35

One founder downloads seven days of NextDNS logs: 4,100 lines. Under the free cap, so the first pass costs nothing.

FRI 16:50

Free preview: 14 AI tools across 6 categories, top five named, nine masked rows. Two tools flagged as training on user data. The named five include an image upscaler nobody admitted to and the transcription app on a founder's own phone.

MON 09:15

They buy one $99 report and re-upload a 30-day export, 16,800 lines. Full list: 19 tools. The per-device table shows the design studio's iMacs carrying most of the image-tool traffic, client work included. Exactly what the procurement form is asking about.

TUE

The founders sanction four tools with enterprise terms, drop two, and answer the client's form from the report CSV, with the PDF attached as evidence. Total spend: $99 and about two hours.

The client-questionnaire trigger is the most common SMB path to a first audit. The second most common: an invoice for an AI subscription nobody remembers approving.

Profiles as policy

Reading a profile-based report

NextDNS attribution is device-and-profile shaped. That maps to three useful readings.

Per device: habits

Studio-iMac-2 living on image AI is a workflow fact. The conversation is about client-work terms, not about a person's browsing.

Per profile: surfaces

Office vs Mobile vs Guests. A transcription tool on the Mobile profile means meetings are being recorded off-premises, which is its own policy line.

Across runs: drift

SMB tool adoption is word-of-mouth: one designer finds a tool, three more follow within a month. Monthly free previews catch the spread while it is still one conversation.

Output

What the report returns for a NextDNS export

Report sectionWith a NextDNS CSV
Summary tilesComplete totals: tools, high-risk, training exposure, abusive-purpose, unsanctioned.
Tool tableEvery matched domain with category, risk, sovereignty and dated training verdicts.
Per-source tableDevice names and profiles as sources, with tool counts and hits per device.
Sanctioned splitYour approved list against observed use; SMBs usually build the list from run one.
Blocked evidenceStatus column preserved if you already block categories or lists.
CSV + PDFFull-report tier: the PDF answers client questionnaires, the CSV feeds your own sheet.

The uploaded CSV is read once and discarded. Reports stay 90 days in your account, deletable earlier. Registration for the free tier needs only an email address.

Small-network edges

Details that matter at SMB scale

BYOD is half the story

  • Personal phones on office Wi-Fi appear under the office profile; personal laptops at home do not appear at all.
  • Say so in any client-facing answer: the audit covers the filtered surface, stated plainly.

Apple relay and DoH overlaps

  • Devices using a private relay or their own DoH bypass NextDNS for those apps.
  • Installed NextDNS apps and configured profiles keep coverage; spot-check a device if its rows look suspiciously empty.

Retention beats memory

  • Pick a log retention that covers your audit cadence, and export promptly.
  • A monthly preview habit costs ten minutes and keeps the window question moot.

When you outgrow this loop

  • Past a couple hundred devices, teams usually move to managed DNS with per-user identities.
  • The DNSFilter guide covers the MSP-managed version of the same audit.

See what a finished audit looks like

Three pages, sample data: tiles, the tool table with training verdicts, the per-source breakdown. If a client form is due Wednesday, this is your template answer.

Open the sample PDF
FAQ

NextDNS export questions

Where do I get the NextDNS CSV?

The logs view of your profile has a download option over a time range. One file per profile; upload them separately or concatenated.

We run several profiles. One audit or many?

Concatenate for one company-wide report, or run per profile for per-surface trends. Both fit the caps at SMB scale.

Is a week enough data?

For a first look, yes, and it usually fits the free tier. For client questionnaires and baselines, use 30 days in a full report.

Do device names appear in the report?

Yes, as sources in the per-device table, inside your account only. Rename devices in NextDNS first if you want the table readable.

What does the paid report cost an SMB?

$99 once for one report, no subscription. The agency scenario ran its entire compliance answer on one report; packs exist if audits become routine. See pricing.

Can NextDNS blocking replace the audit?

Blocking handles categories it knows; the audit inventories what actually happened, including embedded AI and new tools. Measure first, then tune blocking: the sequencing argument.

The routine

The ten-minute monthly habit

SMB security works when it fits inside existing habits. This one fits between coffee and stand-up on the first Monday.

Minute 0 to 3

Download last month's CSV from each profile. Same window every time: first to last of the month.

Minute 3 to 6

Upload, run the preview, screenshot the tiles into the ops channel. New tools since last month get a one-line mention.

Minute 6 to 10

If a tile turned red or a client form is pending, upgrade that run to a full report. Otherwise archive the preview PDF and done.

Three free previews a month is exactly a monthly cadence with two spares. The cap and the habit were made for each other.

Starter policy

A five-row AI policy the whole company reads

SMBs do not need a governance framework to act on their first report. They need five rows in the handbook.

RuleWhere the report feeds it
Client work goes only into sanctioned tools.The sanctioned split shows the gap between rule and reality each month.
The sanctioned list lives in the handbook, five tools max.Pick them from the tool table's low-risk, no-training rows.
Anything that records meetings needs a founder's sign-off.Transcription rows in the report, like the founder's own iPhone in the scenario.
New tool requests take one Slack message, answered in a day.Fast sanctioning is what keeps people from not asking.
The audit runs monthly and nobody gets ambushed by it.Per-device rows start coaching conversations, not disciplinary ones.

Building the sanctioned list properly, including what "enterprise tier with no-training terms" means, is covered on sanctioned vs unsanctioned AI.

Your first audit can be free and done today

Download a week of NextDNS logs and upload them. The agency answered a client questionnaire from a Friday-afternoon start.

Run the free audit