
What Is DNS Filtering, and How Does It Block Malicious Websites?
If you want to protect a whole household or a small office from phishing sites, malware downloads, and adult content, you do not need to install software on every device. You can change one setting, the DNS server, and get protection for everything on the network, from laptops to smart TVs. That is DNS filtering, and it is one of the simplest security upgrades available to homes and small businesses. This article explains how DNS filtering works, what it can and cannot block, which services offer it, how to set it up on a router or individual device, and how to test that it is working. If you are not sure where DNS settings live on your network, how to change DNS servers on your router is a useful companion.
What Is DNS Filtering?
DNS filtering is the practice of using a DNS resolver that refuses to resolve domains in categories you want to block. When a device asks for the address of a known phishing domain, the filtering resolver does not return the real IP. It returns an error or the address of a block page instead, so the browser never connects to the malicious server.
Filtering is usually delivered as a hosted service: you point your network at a provider's resolver, choose which categories to block, and the provider maintains the lists. This makes it different from a DNS firewall, which is a resolver-level policy engine that an organization runs and tunes itself with feeds and custom rules. Both use the same underlying idea, but DNS filtering is designed to be easy, with categories, dashboards, and sensible defaults.
How DNS Filtering Works
Every time you visit a website, your device first asks a resolver to translate the domain into an IP address. A filtering resolver adds one step to that process:
- Your device sends a query for
login-verify.example.netto the filtering resolver. - The resolver checks the domain against its categorized database. Providers build these from threat intelligence feeds, web crawlers, machine learning classifiers, and user reports.
- If the domain is allowed, the resolver resolves it normally and returns the real address.
- If the domain is blocked, the resolver returns one of the following instead:
- NXDOMAIN, telling the device the domain does not exist.
- A null address such as
0.0.0.0, so the connection goes nowhere. - The address of a block page, which tells the user why the site was blocked.
- The device never reaches the malicious server, so no page loads, no payload downloads, and no credentials are entered.
Because the decision is made before any connection, DNS filtering blocks threats across every app and protocol, not just web browsers. A malware sample trying to reach its server, an email link, and a smart TV app are all covered.
What a Blocked Response Looks Like
You can see filtering in action with dig. Quad9 offers a filtering resolver at 9.9.9.9 and an unfiltered one at 9.9.9.10, which makes it easy to compare:
dig @9.9.9.9 blocked-domain.example A +noall +comments +answer
dig @9.9.9.10 blocked-domain.example A +noall +comments +answer
For a domain on Quad9's threat list, the first command returns status: NXDOMAIN while the second returns the real address. Replace blocked-domain.example with a domain from a public phishing report to try it. Different providers signal blocks differently, so with Cloudflare's family resolvers you may see 0.0.0.0, and with block-page services you may see an IP belonging to the provider.
What DNS Filtering Can Block
Most services let you choose from categories like these:
| Category | Typical use |
|---|---|
| Malware and ransomware | Everyone. Usually on by default. |
| Phishing and scams | Everyone. Usually on by default. |
| Botnet command and control | Stops infected devices from receiving instructions |
| Newly registered domains | Many attacks use domains only days old |
| Cryptomining | Blocks in-browser mining scripts |
| Adult content | Families, schools, workplaces |
| Gambling, drugs, violence | Families and workplace policy |
| Social media, gaming, streaming | Productivity or screen-time rules |
| Ads and trackers | Privacy and faster page loads |
Many services also offer SafeSearch enforcement. They do this by answering lookups for search engines with the address of the provider's safe mode, for example by mapping www.google.com to forcesafesearch.google.com and YouTube to restrict.youtube.com. The search engine then serves filtered results no matter what the user's settings are.
Popular DNS Filtering Services
Free Public Filtering Resolvers
These require no account. You just set the resolver addresses:
| Service | Addresses | What it blocks |
|---|---|---|
| Quad9 | 9.9.9.9, 149.112.112.112 | Malware and phishing |
| Cloudflare for Families (malware) | 1.1.1.2, 1.0.0.2 | Malware |
| Cloudflare for Families (malware and adult) | 1.1.1.3, 1.0.0.3 | Malware and adult content |
| OpenDNS FamilyShield | 208.67.222.123, 208.67.220.123 | Adult content |
| CleanBrowsing Family | 185.228.168.168, 185.228.169.168 | Adult content, mixed content, and enforces SafeSearch |
| AdGuard DNS (default) | 94.140.14.14, 94.140.15.15 | Ads, trackers, and malicious domains |
For a deeper comparison of the big public resolvers on speed and privacy, see Cloudflare DNS vs Google Public DNS vs Quad9. Note that Google Public DNS does not filter.
Configurable Services
If you want to choose categories, add allowlists, and see reports, use a configurable service. Options such as NextDNS, Control D, Cisco Umbrella, Cloudflare Zero Trust Gateway, and the paid tiers of CleanBrowsing and AdGuard DNS give you a dashboard where you set policy per network or per device, plus logs showing what was blocked. Business plans add user-level policies through a lightweight agent, which keeps laptops protected when they leave the office.
Self-Hosted Filtering
If you prefer to keep everything on your own hardware, a local filtering resolver such as Pi-hole or AdGuard Home blocks domains using blocklists you choose. See how to block ads across your whole network with Pi-hole DNS for a full setup guide.
How to Set Up DNS Filtering
On Your Router (Protects the Whole Network)
Setting the filtering resolver on your router is the best option for a home or small office, because every device that gets its settings from the router via DHCP is covered automatically:
- Log in to your router's admin page.
- Find the DNS or WAN settings.
- Replace the existing DNS servers with the primary and secondary addresses of your chosen service.
- Save, then reconnect devices or restart them so they pick up the new settings.
On Individual Devices
On Windows, you can set the resolver from an elevated PowerShell prompt:
Get-NetAdapter
Set-DnsClientServerAddress -InterfaceAlias "Wi-Fi" -ServerAddresses ("1.1.1.3","1.0.0.3")
Clear-DnsClientCache
Get-NetAdapter lists your network interfaces so you can find the right InterfaceAlias, the second command sets Cloudflare's malware-and-adult filtering resolvers, and Clear-DnsClientCache flushes previously cached answers so blocking takes effect immediately.
On Linux systems using systemd-resolved, edit /etc/systemd/resolved.conf:
[Resolve]
DNS=9.9.9.9 149.112.112.112
DNSOverTLS=yes
Then apply it with sudo systemctl restart systemd-resolved and confirm with resolvectl status. Enabling DNS over TLS encrypts queries to the filtering resolver so nobody on the network path can see or alter them.
For step-by-step instructions on macOS, iPhone, and Android, see how to change DNS settings on Windows, Mac, iPhone, and Android. Android's Private DNS setting and iOS configuration profiles both let you use a filtering service's encrypted DNS hostname, which keeps filtering in place on mobile data too.
How to Test That Filtering Is Working
Once you have switched, check that devices are actually using the filtering resolver. This Python script, using dnspython, compares answers from a filtering resolver and an unfiltered one for a list of domains:
import dns.resolver
FILTERED = "9.9.9.9"
UNFILTERED = "9.9.9.10"
DOMAINS = ["example.com", "blocked-domain.example"]
def lookup(server, name):
r = dns.resolver.Resolver(configure=False)
r.nameservers = [server]
r.lifetime = 5
try:
return sorted(rr.to_text() for rr in r.resolve(name, "A"))
except dns.resolver.NXDOMAIN:
return ["NXDOMAIN"]
except dns.resolver.NoAnswer:
return ["NODATA"]
except Exception as exc:
return [f"error: {exc.__class__.__name__}"]
for domain in DOMAINS:
f, u = lookup(FILTERED, domain), lookup(UNFILTERED, domain)
status = "BLOCKED" if f != u else "same"
print(f"{domain}: filtered={f} unfiltered={u} [{status}]")
configure=False stops dnspython from reading the system resolver settings, so each lookup goes only to the server you name. A domain where the filtered answer is NXDOMAIN or 0.0.0.0 and the unfiltered answer is a real IP is being blocked. Many services also offer a test page on their website that shows whether your current connection is using them.
If a blocked site still loads, the device is probably bypassing the filter, or it has the real answer cached. Flush the cache using how to flush the DNS cache on Windows, macOS, and Linux and try again.
Limitations of DNS Filtering
DNS filtering is a strong first layer, but it is not a complete security solution:
- It can be bypassed. A user who changes their device's DNS settings, uses a VPN, or connects over mobile data skips your router's filter. Browsers with DNS over HTTPS enabled may send queries to their own resolver. Many filtering services publish encrypted DNS endpoints you can configure in the browser to close that gap.
- It works on whole domains only. It cannot block one page on a site while allowing the rest. Filtering
example-video.com/one-bad-videowithout blocking the whole site requires a web proxy. - It does not see content. A legitimate, trusted domain that has been compromised will not be blocked until the provider updates its lists.
- Direct IP connections skip it. Malware that connects to a hard-coded IP address never makes a DNS query.
- Local overrides win. Entries in the hosts file are used before DNS, so they can override filtering on that device.
- Overblocking happens. Shared hosting and CDN domains are sometimes miscategorized. Good services let you add allowlist entries.
Best Practices
- Filter at the router and also on mobile devices with encrypted DNS profiles.
- Block outbound DNS to other resolvers on business networks if your router or firewall supports it.
- Turn on malware, phishing, and newly registered domain blocking at minimum. These have the best protection-to-annoyance ratio.
- Use block pages for policy categories so users understand why a site is blocked, and NXDOMAIN for threats.
- Review the logs occasionally. Repeated blocks from one device can mean it is infected.
- Combine it with other protections, such as updated software, endpoint protection, and multi-factor authentication.
DNS Filtering FAQ
Usually not. Major filtering services run large anycast networks and often respond as fast as or faster than ISP resolvers. The category check adds negligible time to each lookup.
Basic malware and adult content filtering is free from services like Quad9, Cloudflare for Families, OpenDNS FamilyShield, and CleanBrowsing. Custom categories, dashboards, and per-user policies are usually paid features.
Yes, many services and self-hosted tools like Pi-hole block ad and tracker domains. Some ads are served from the same domain as the content, and those cannot be blocked by DNS alone.
A determined user can bypass it by changing device DNS settings, using a VPN, or using mobile data. Locking down device settings, using parental controls on the device, and blocking outbound DNS on the router make bypass harder.
DNS filtering usually means hosted services with pre-built categories for homes and businesses. A DNS firewall usually means resolver-level policy, often built on Response Policy Zones, that an organization runs and customizes itself.
Yes. The block happens at the DNS lookup, before any HTTPS connection begins. If the service redirects to a block page, though, the browser will usually show a certificate warning because the block page cannot present a valid certificate for the blocked domain.
Domains are sometimes miscategorized, or a site may have been compromised recently. Check the service's lookup tool to see the category, request a review, and add the domain to your allowlist if the service supports it.
Yes. DNS filtering stops connections to known bad domains, but it cannot inspect files, catch threats that arrive by USB or direct IP, or stop malware already running on a device.
Conclusion
DNS filtering is one of the highest-value, lowest-effort security measures you can add to a home or small business network. By pointing your router at a filtering resolver, you block known malware, phishing, and unwanted content on every device at once, before a single connection is made. Free services cover the essentials, and paid services add categories, reports, and per-device rules.
It works best as one layer among several. Pair it with encrypted DNS on mobile devices, keep an eye on bypass routes like VPNs and browser DoH, and keep endpoint protection and updates in place. Set it up once, test it with a few lookups, and it will quietly block threats in the background for years.
Here are some useful references for going deeper on DNS filtering:
- Cloudflare Learning Center: What is DNS filtering? — an overview of how DNS filtering works and where it fits.
- Cloudflare Developers: 1.1.1.1 for Families — addresses and setup for Cloudflare's filtering resolvers.
- Quad9: Quad9 Service Addresses — Quad9's filtered and unfiltered resolver addresses.
- Google Support: Lock SafeSearch for devices and networks you manage — how forced SafeSearch works via DNS.
- Pi-hole Documentation: Pi-hole Docs — setup and configuration for self-hosted DNS filtering.


