DNS FILTERING

DNS filtering with policy you can inspect and change.

QueryWarden combines managed domain sources with profiles, service categories, schedules, Safe Search, and scoped custom rules. The result is a DNS filter whose decision belongs to a defined endpoint and policy—not an unexplained global blocklist.

Threat, tracker, parental-domain, and Safe Search controls are available Custom allow and block rules support deliberate scope Profiles and timezone-aware policy schedules are available
DNS decision pathIllustrative request
Device
Private DoH
QueryWarden policy
Allowed destination
Policy checked before connectionDecision evidence is reviewable when the profile retains it.
POLICY MODEL

Start broad, then make exceptions narrowly.

Managed sources provide a practical protection baseline. QueryWarden then lets an account owner place devices into distinct profiles and make an exact, reviewable exception only where the requirement calls for one.

BUILT INTO THE PRODUCT

Controls you can use and verify.

Each capability below reflects the current public product, with beta and compatibility limits called out separately.

Managed filtering sources

Threat, ad and tracker, parental-domain, and service controls can make a decision before a destination is reached.

Profiles instead of one global switch

Different configured endpoints can use different protection, schedule, service, and privacy choices without sharing one public resolver credential.

Scoped custom decisions

Allow or block rules can be narrowed by hostname match, audience, and duration so a troubleshooting exception does not need to become permanent or account-wide.

Explainable outcomes

When eligible evidence is retained, QueryWarden can separate the recorded historical decision from rules that match the hostname now.

FIRST-PARTY PRODUCT EVIDENCE

Preview the effective policy before creating an exception.

The Domain Rules workspace exposes the current decision, hostname match, audience, duration, and reason in one flow. That helps keep a narrow troubleshooting change from becoming an unexplained permanent override.

QueryWarden Domain Rules workspace showing policy preview and scoped custom allow or block rule controls with synthetic data.Open full-size screenshot
Current QueryWarden Domain Rules interface captured with reserved example data. It demonstrates workflow, not a recommendation to allow a domain.
PREVIEW

Check the effective decision first

A preview shows whether managed protection, a service control, profile policy, or an existing custom rule already determines the result.

SCOPE

Choose hostname and audience deliberately

Exact and subdomain matches have different reach. Account, profile, or endpoint audience determines who receives the exception.

LIFETIME

Prefer a bounded change when possible

A temporary rule and recorded reason reduce the chance that a short investigation silently becomes permanent policy.

HOW IT WORKS

From setup to an explainable DNS decision.

QueryWarden applies policy at the recursive DNS layer, before a supported client connects to the requested domain.

  1. 01

    Choose the profile baseline

    Enable the protection and service controls appropriate for the endpoints assigned to that profile.

  2. 02

    Set schedule and privacy boundaries

    Choose when scheduled controls apply and whether domain history is Full, Anonymized, or Off within the available plan window.

  3. 03

    Preview a hostname before overriding it

    Inspect the effective decision and source, then choose the narrowest exact or subdomain match that solves the requirement.

  4. 04

    Verify with a fresh DNS request

    Generate uncached activity through the intended endpoint and confirm the new result without assuming that successful browsing proves the configured resolver was used.

CLEAR BOUNDARIES

Filtering is precise only within DNS visibility

A clear rule model reduces accidental scope, but DNS still sees hostnames rather than the complete content or intent of a connection.

  • DNS filtering cannot selectively remove every advertisement or tracker served from the same hostname as wanted content.
  • A custom allow rule bypasses the matching DNS block; it does not certify the destination or its future content as safe.
  • Safe Search enforcement and parental-domain controls are supporting controls, not a guarantee of age-appropriate content or complete child safety.
  • Household invitations and guardian roles remain roadmap work even though profiles, categories, rules, and schedules are implemented.
WHO AND HOW

Technical basis and product evidence

Published and reviewed by QueryWarden Engineering, Digiport OÜ. First-party review against the current public QueryWarden product, its documented deployment constraints, and the primary sources listed on this page. This is not an independent audit, certification, approval, or endorsement.

Product screenshots are deterministic captures of the current interface using synthetic accounts, devices, and reserved .test domains. External sources explain protocols and industry guidance; they do not verify QueryWarden implementation claims.

Last reviewed . Product availability can change; dashboard capability labels remain the source of truth. Review our Security & Trust disclosure.
QUESTIONS, ANSWERED

What to know before you change DNS.

Can I use different DNS filters for different devices?

Yes, when the account entitlement allows the required profiles and endpoints. Devices are assigned to profiles that carry their own protection, service, schedule, and privacy settings. Free currently includes one device and one profile.

Can QueryWarden allow one blocked domain?

Yes. A custom allow rule can be scoped to an exact hostname or a deliberate subdomain range, selected audience, and temporary or permanent duration. Review the security impact before saving it.

Does DNS filtering remove every ad?

No. It can block requests to matching ad and tracker domains, but it cannot reliably remove content served from an allowed first-party hostname or repair the layout left by blocked content.

START WITH THE AVAILABLE FREE PLAN

Build the first policy around one real device.

Create a Free account, connect one compatible endpoint, and verify the result before expanding the scope of any rule.