Guides: Choosing a tier · DNS blocking · Whitelisting

DNS ad and tracker blocking

Filtering is what the security tier adds, and it is added at the one place every request passes through: the name lookup. Ads, trackers and known-malware domains are refused before your device ever opens a connection to them, on every app on the device — no browser extension, no per-app settings.

How it answers

What it does not see

DNS filtering is name-level, and the limits follow from that:

Nothing about your queries is kept

Query logging and statistics are disabled on the resolvers, on every tier, and that is tested rather than asserted: the infrastructure audit re-applies the setting, sends a real query, and requires that nothing was written. The full list of what is and is not stored is on what we log.

If a site you need is blocked

Two things are worth ruling out before you report it:

  1. The cache. A name may be answering from a cached entry that predates a list change, and a resolver loading new rules can return an empty answer that looks like a block. Re-run the lookup after a moment and see whether it settles.
  2. The device you are asking from. Ask from the device that has the problem, on its own resolver — a test from a different machine observes a different policy.

If it still fails, the exception request is the next step: Requesting a whitelist entry.

Previous: Choosing a tier.

󰣨 ymrtech@ymrtech | 󰌠 NixOS | 󰍢 UTF-8