Control D Is Now Available Through Tailscale

Buy Control D directly through Tailscale and filter every device on your tailnet, with different policies by user, group, or tag.

Control D and Tailscale Partnership
💡
Control D can now be purchased directly through Tailscale. Point your tailnet at Control D and every device on it is filtered, with different policies for users, groups, and tags.

Teams have been running Control D natively on their tailnets for some years now. While Tailscale connects your devices into a private network and controls what they can reach inside it, Control D handles the other half, providing controls and filters for access to the public internet.

Running both meant managing two separate vendors and invoices. Today we're proud to make it official and partner with Tailscale. You can now buy Control D directly through them, and run it across every device on your tailnet from a single vendor.

How the Partnership Works

In Control D, a Profile is the set of rules you want enforced, and an Endpoint is a resolver that enforces one. Every Endpoint has a Resolver ID. Add Control D as a nameserver in the Tailscale admin console, paste the resolver ID in, switch on Override DNS servers, and every device on your tailnet resolves through it, with nothing to install and no network changes. Our docs cover the details.

What's new is the commercial side. Tailscale's team handles your day-to-day support, and ours behind them on anything deeper. Policy management stays where it is, in your Control D Dashboard and API.

What Control D Adds to Your Tailnet

Threats Stopped at the Resolver

Control D checks every query against curated threat feeds, then against the domains and IPs those campaigns are built on, so infrastructure caught once stays caught when it resurfaces under a new name. Unknown domains are scored by machine learning and blocked if they look high risk. Control D has consistently ranked first in independent malware filter tests, most recently with a 99.98% block rate.

Beyond malware and phishing, 20+ native content categories and over 1,000 services and apps can each be allowed, blocked, or redirected individually for granular policy control.

Policies That Follow Your Tailnet

Different parts of your tailnet can enforce different rules. In your tailnet policy file, nodeAttrs maps users, groups, or tags to a Control D Endpoint, so filtering inherits the structure you already built for network access. Tag a machine and its policy follows, without enrolling each device in Control D separately. Where a device inherits more than one tag, priority values decide which one wins.

This shares only device hostnames with Control D, and you control how much query data is kept.

More Than One Tailnet

Plenty of teams run several, whether that is production and staging, one per subsidiary, one per department/team, or one per client if you are an MSP. Organizations and Sub-Organizations give each its own policy scope, Shared Profiles push a common baseline across all of them, and delegated administration lets whoever runs one manage it without touching the others.

Getting Started

Already using Tailscale? Talk to the Tailscale sales team about adding Control D to your plan.