How it works
DNS filtering evaluates a requested domain against policy before returning its network address. A resolver can refuse domains associated with malware or a chosen content category. This happens at name lookup, rather than examining every sentence, image or file on the site.
A practical example
A household may select a filtered resolver to block known malicious destinations on connected devices. If one legitimate domain is misclassified, the whole service may stop working even though its other pages would be acceptable. Different resolver products use different lists.
What to check
Verify the exact resolver product and configure the intended devices or router. Use the provider’s harmless test page to confirm filtering, then check that important legitimate services work. Document exceptions carefully; browsers, VPNs or apps may use a different resolver.
Test filtering on the intended device and connection, because a browser or application may use a different resolver. A successful test on one phone does not establish coverage for every device.
Limits and safe use
DNS filtering is not a substitute for updates, safe sign-in or malware protection. A harmful page hosted on an allowed domain may remain reachable. Filtered DNS also does not automatically encrypt traffic or enforce a policy when a device changes networks or overrides its DNS settings.