Guides: Choosing a tier · DNS blocking · Whitelisting

Requesting a whitelist entry

A filter list will eventually block something you need — a vendor portal, a work tool, a school or a bank host that happens to share a domain with an ad network. The security tier takes an exception request for exactly that case.

Where the request goes

The portal’s filter-list page shows what was blocked for your device, and takes the request from there: the hostname, and a line on why you need it. It does not need to be a domain you can prove is broken from where you are sitting — the reason is what the entry is judged on.

What your request becomes

It is not an instant toggle. An entry is an exception to a security control, so it is reviewed and then applied the same way every other change to the service is: as a reviewed change to the fleet’s shared allowlist, merged, and deployed to the resolvers. Two consequences worth knowing before you submit:

There is a reserved domain for testing the path, whitelist-test.ymrtech.com, which is already allowed. Use that one if you are checking how the request flow behaves.

What gets an entry, and what does not

The request The answer
A vendor portal, a SaaS you use, a school or employer host, or the CDN one of those is served from Reviewed on the host and the reason, and typically allowed.
An ad exchange, an analytics or telemetry network, a tracker Refused. The block is the point of the tier.
A credential, authentication or banking host without a clear subscription context Escalated to a person, not auto-refused.
Anything already answered by a different tier Use that tier on that device — see Choosing a tier.

After the entry lands

Check it from the failing device, on its own resolver: a test from a machine on a different tier, or one that is already exempt, observes the exemption rather than the policy. If the answer has not changed immediately, re-run it once — a resolver loading new rules can serve an empty answer that reads like a block (see DNS ad and tracker blocking).

Requests are answered on the address you registered with.

Previous: DNS ad and tracker blocking.

󰣨 ymrtech@ymrtech | 󰌠 NixOS | 󰍢 UTF-8