DNS protect feature in Sensor can be used to protect DNS servers from DoS spoof attack by forcing the DNS clients to use TCP instead of UDP as their transport protocol. Since TCP uses three-way-handshake, it is comparatively tough to launch spoofed attacks when TCP is used.
You can set the DNS protection mode, add to, or delete existing DNS spoof protection IP addresses from the protected server list using CLI commands.