What Network-Wide DNS Filtering Can—and Cannot—Protect You From

32 Hertz SOC Global Guardians logo

Written by

in

Advertisements, trackers, malicious websites, and unwanted online services are not limited to computers. Smart televisions, streaming devices, game consoles, phones, tablets, and other connected products may also contact numerous internet domains throughout the day.

A traditional browser extension can help on a computer, but many smart devices do not support browser extensions or security software. Network-wide DNS filtering offers another layer of protection by examining domain-name requests from devices using the network’s DNS server. AdGuard Home is one tool that can provide this type of filtering. However, it is important to understand both what DNS filtering can accomplish and where its protection ends.

What Is DNS?

DNS stands for Domain Name System. It works somewhat like an internet address book. When a device attempts to visit a website or connect to an online service, it usually starts by requesting the numerical IP address associated with a domain name. For example, a device may need DNS to learn where to find example.com.

A DNS filtering service checks the requested domain before returning an answer. If the domain matches an enabled blocking rule, the DNS server can refuse to resolve it. The device is then unable to make its normal connection to that domain.

This process is sometimes called DNS blocking or DNS sinkholing.

What Is AdGuard Home?

AdGuard Home is free, open-source software that runs on a device controlled by the user. It acts as a DNS server and can apply filtering rules to devices across a network. AdGuard describes it as network-wide software for blocking advertising and tracking domains. AdGuard Home overview

It can be installed on supported computers, small servers, and certain other platforms. A router can then be configured to provide the AdGuard Home server’s address to connected devices. According to AdGuard’s setup documentation, configuring DNS at the router can cover devices connected to that router without requiring each device to be configured separately. AdGuard Home getting-started guide

This can be especially useful for smart televisions, speakers, appliances, and other devices that cannot run a conventional content blocker.

What DNS Filtering Can Help Protect Against

Known Advertising and Tracking Domains

Many advertisements, analytics systems, and tracking services use domains that are separate from the website or application providing the desired content.

If one of those domains appears on an enabled blocklist, AdGuard Home can prevent the connection. This may reduce some advertising, tracking, telemetry, and unwanted background traffic.

Results will vary according to the selected filter lists, the devices being used, and the way each service delivers its content.

Known Malware and Phishing Domains

DNS filtering can block requests to domains identified by an enabled security list or protection feature. This can prevent a device from connecting normally to some known malware, phishing, fraud, or command-and-control infrastructure.

The protection is useful because the connection can be stopped before the website or remote service is reached. However, it depends on the malicious domain being recognized by the active rules.

AdGuard Home supports filtering features and customizable blocklists, including options intended to block phishing and malware domains. Official AdGuard Home repository

Devices That Cannot Run Security Extensions

A browser extension only protects the browser in which it is installed. DNS filtering can also affect smart televisions, streaming devices, game consoles, cameras, speakers, appliances, and other equipment using the filtered DNS server.

This does not make those devices secure, but it can reduce their ability to communicate with domains that have been blocked.

Consistent Rules Across a Network

Network-wide filtering provides one central place to manage DNS rules. Instead of configuring a separate blocker on every compatible device, an administrator can maintain a common filtering policy.

Exceptions can also be created when a legitimate service is incorrectly blocked.

Greater Visibility into DNS Activity

AdGuard Home provides statistics and a query log. These features can help an administrator understand which domains devices are requesting, which requests are being blocked, and whether an unexpected device or application is generating unusual DNS activity.

This information can be useful during troubleshooting or a security investigation. It is also sensitive because the requested domains may reveal information about household activity. Query logs should therefore be treated as private security records rather than material for public screenshots.

What DNS Filtering Cannot Protect Against

DNS filtering is one layer of defense. It is not a replacement for antivirus software, software updates, secure passwords, multifactor authentication, backups, firewalls, or safe browsing habits.

Advertisements Delivered from the Same Domain as the Content

A DNS server makes decisions at the domain level. It cannot normally block one part of a domain while allowing another part of the same domain.

For example, if a video and its advertisement come from the same domain, blocking the domain would also block the video. AdGuard’s documentation specifically lists YouTube and Twitch advertisements and sponsored posts on major social platforms as examples that DNS-level blocking may not remove. AdGuard Home FAQ

A browser-based content blocker can inspect page elements and individual web requests in ways that DNS filtering cannot.

Every Malicious Website

A domain may be newly created, previously unknown, or absent from the selected security lists. Attackers can also change domains quickly.

A successful DNS lookup therefore does not prove that a site is safe. Users should still examine links carefully and respond cautiously to login pages, downloads, attachments, and security warnings.

Malware Already Installed on a Device

DNS filtering may prevent some malware from contacting a known malicious domain, but it does not scan files, remove infections, examine running processes, or repair a compromised computer.

Endpoint security tools and a proper malware-investigation process are still required.

Connections Made Directly to IP Addresses

DNS filtering works when a device asks the DNS server to resolve a name. If software connects directly to an IP address, there may be no domain request for the filter to block.

A firewall or other network-security control may be required to restrict direct connections.

Devices That Bypass the Filter

Some applications and devices may use their own DNS provider, encrypted DNS configuration, VPN connection, cellular connection, or hard-coded network settings. Those requests may not pass through the local AdGuard Home server.

AdGuard’s troubleshooting guidance recommends confirming that a device is actually using AdGuard Home and that its requests appear in the query log. AdGuard Home FAQ

Traffic Contents

DNS filtering can see requested domain names, but it does not normally inspect the full contents of encrypted web traffic. It cannot determine whether a particular document, message, video, or file is safe simply because the domain was allowed.

Protection Away from the Network

A home DNS server normally protects devices while they are connected to the network configured to use it. A phone that switches to cellular service or another Wi-Fi network may no longer use the home DNS filter.

Extending DNS filtering outside the home requires additional configuration and introduces new security responsibilities.

A Safe Way to Experiment with AdGuard Home

Changes to DNS can affect the entire network. A careful test should begin with one noncritical device instead of immediately changing the router for every device.

1. Define the Goal

Decide what the experiment is intended to measure. Possible goals include:

  • Reducing requests to known advertising and tracking domains.
  • Adding protection against known malicious domains.
  • Observing the types of DNS requests made by a test device.
  • Identifying compatibility problems and false positives.
  • Determining whether DNS response performance remains acceptable.

2. Prepare a Recovery Plan

Record the original DNS settings privately before making changes. Know how to restore those settings if websites, applications, or devices stop working.

Keep the AdGuard Home administration interface restricted to trusted systems. AdGuard recommends choosing network interfaces and access settings carefully, particularly if a server might be accessible from outside the local network. AdGuard Home security guidance

3. Begin with One Test Device

Configure only one noncritical computer, phone, or other suitable device to use the AdGuard Home server.

Confirm that normal browsing and DNS resolution still work. Also confirm that the device’s requests appear in the AdGuard Home query log.

4. Establish a Short Baseline

Before enabling additional filtering, observe a limited baseline period. Record only the aggregate measurements needed for comparison.

Examples include:

  • Total DNS requests.
  • Number or percentage of blocked requests.
  • DNS errors.
  • Noticeable service failures.
  • Approximate DNS response performance.
  • Number of legitimate domains that required an exception.

Avoid keeping detailed logs longer than necessary for the experiment.

5. Enable a Conservative Set of Filters

Begin with a small, trusted collection of general and security-focused rules. Adding numerous overlapping lists immediately can increase false positives and make troubleshooting difficult.

Test commonly used websites, streaming services, smart-device applications, software updates, online games, and communication tools.

6. Investigate Problems Carefully

If an application stops working, do not automatically disable all filtering. Review the relevant requests and determine which domain was blocked.

Only allow a domain after understanding why the application needs it. An allowlist should not become a collection of unexplained exceptions.

7. Expand Gradually

If the test device works properly, add another device or a small group. Continue monitoring for unexpected behavior.

Router-wide deployment should occur only after the administrator understands how to restore the original DNS configuration.

Final Thoughts

Network-wide DNS filtering can reduce connections to known advertising, tracking, phishing, and malware-related domains. It can also provide useful visibility into DNS activity from devices that cannot run conventional security software. However, its limitations are equally important. It cannot inspect everything a device downloads, remove malware, block every advertisement, identify every new malicious domain, or protect devices that bypass the filtered DNS server.

AdGuard Home should therefore be treated as one part of a layered security strategy.