You can confirm Cisco Umbrella is working in a few minutes using Cisco’s own test pages. From a device that should be protected, open welcome.umbrella.com. A success message means that device’s DNS requests are reaching Umbrella. An error means traffic is going to another DNS resolver.
Next, check that policies are enforced. Cisco provides safe test domains that should return an Umbrella block page: internetbadguys.com for phishing, examplemalwaredomain.com for malware and examplebotnetdomain.com for command-and-control. If one of these loads normally, the device is not covered or the policy is not applied as expected.
A few other checks help narrow down problems:
- On a laptop, open Cisco Secure Client and confirm the Umbrella module shows as active rather than disabled or unprotected.
- Run nslookup against 208.67.222.222 to see whether a firewall is blocking outbound DNS to Umbrella.
- In the Umbrella dashboard, use Activity Search to confirm the device’s requests are logged against the right identity and policy.
These test pages are designed for DNS-layer protection. Users covered only by SIG tunnels need proxy-specific tests instead.
If Umbrella is not working, the most common causes are local DNS overrides, VPN conflicts, browsers using their own DNS-over-HTTPS provider, or a firewall blocking ports 53 and 443 to Umbrella’s resolvers.