Requesting a whitelist entry
Guides: Choosing a tier · DNS blocking · Whitelisting
Requesting a whitelist entry
A filter list will eventually block something you need — a vendor portal, a
work tool, a school or a bank host that happens to share a domain with an ad
network. The security tier takes an exception request for exactly that case.
Where the request goes
The portal’s filter-list page shows what was blocked for your device, and takes the request from there: the hostname, and a line on why you need it. It does not need to be a domain you can prove is broken from where you are sitting — the reason is what the entry is judged on.
What your request becomes
It is not an instant toggle. An entry is an exception to a security control, so it is reviewed and then applied the same way every other change to the service is: as a reviewed change to the fleet’s shared allowlist, merged, and deployed to the resolvers. Two consequences worth knowing before you submit:
- It is one line in a shared policy. The lists are declared in one place and deliberately not overridable per device, so an entry you ask for changes answers for every client on the tier, not only yours.
- It is not immediate. The request has to be reviewed and deployed, so a
reply takes longer than a page reload. If you need the site now, the
privacytier has no filtering at all — moving that device is the quick way to a working lookup, and the request still stands for everyone else.
There is a reserved domain for testing the path,
whitelist-test.ymrtech.com, which is already allowed. Use that one if you are
checking how the request flow behaves.
What gets an entry, and what does not
| The request | The answer |
|---|---|
| A vendor portal, a SaaS you use, a school or employer host, or the CDN one of those is served from | Reviewed on the host and the reason, and typically allowed. |
| An ad exchange, an analytics or telemetry network, a tracker | Refused. The block is the point of the tier. |
| A credential, authentication or banking host without a clear subscription context | Escalated to a person, not auto-refused. |
| Anything already answered by a different tier | Use that tier on that device — see Choosing a tier. |
After the entry lands
Check it from the failing device, on its own resolver: a test from a machine on a different tier, or one that is already exempt, observes the exemption rather than the policy. If the answer has not changed immediately, re-run it once — a resolver loading new rules can serve an empty answer that reads like a block (see DNS ad and tracker blocking).
Requests are answered on the address you registered with.
Previous: DNS ad and tracker blocking.