DNS filtering
Blocking access to malicious or unwanted destinations at the point where a name is looked up.
Almost every connection starts with a DNS lookup, which makes it an efficient chokepoint. Blocking the resolution of a known-bad domain stops a phishing page from loading and stops malware reaching its command and control server, without inspecting any traffic.
It is cheap, fast, and works off the corporate network, which makes it one of the better value controls for remote staff. It is not a substitute for endpoint protection, since attackers can use direct IP addresses or their own resolvers.
Where this comes up
DNS filtering sits inside our cybersecurity and threats work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.