DNS filtering · 4 min read · Updated 2026-08-18
DNS Parental Controls: A Simple Guide for Parents
DNS parental controls work by filtering domain-name lookups. If a site or app cannot find the server name it needs, it usually cannot load. That is useful, private compared with screen-reading apps, and incomplete: it does not read messages, and it can be bypassed if the device stops using that DNS.
You do not need to become a network engineer to use DNS filtering well. You do need a plain-English picture of what a lookup is, why blocking a name often blocks an app, and why a second path to the internet — a VPN, another DNS setting, a spare tablet — sits outside that picture. This guide stays on that map.
DNS in one paragraph
When a phone loads a website or talks to an app, it usually starts with a name such as a shop’s domain or an API hostname. DNS is the phone book that turns that name into an address. A DNS-based parental control sits in that lookup step and can refuse to answer names you have chosen to block, or answer them in a way that goes nowhere useful.
That is different from antivirus, different from reading the page, and different from recording every tap. It is a gate on names.
What DNS filtering is good at
It is good at categories of websites: adult content, malware and phishing domains, gambling, and many social or streaming backends that still need ordinary hostnames. It can follow a laptop or phone off home Wi-Fi if the device itself is configured to use the filtered DNS on cellular as well.
It is also a comparatively private approach. You are not installing an app that screenshots the display or opens iMessage. You are deciding which names resolve. Many parents want that distinction made explicit.
Setup on modern phones is usually a profile or Private DNS setting, not a child-facing app that can be deleted from the home screen in one angry minute — though profiles can still be removed, which is why noticing when protection can no longer be verified matters.
Where DNS filtering is weak
If the device does not send lookups to your filtered DNS, the filter never sees them. That can happen with a VPN that uses its own DNS, with manual DNS changes, or with a device you never enrolled.
Some apps connect to addresses they already know, or use techniques that reduce fresh lookups. Encrypted DNS to another provider can also skip your rules if the operating system is pointed elsewhere.
DNS filtering does not see the text of a message, the inside of a photo, or which button someone tapped. If your goal is to read chats, this is the wrong tool — and that is a feature for families who do not want that.
How this compares with other parental controls
Apple Screen Time and Google Family Link are operating-system supervisors. They can limit apps, downtime, and purchases. They do not replace DNS category blocking, and DNS does not replace their app-install locks. Use them together when you can. Some families choose DNS specifically because they want parental controls without installing an app on the child’s phone.
Browser extensions only protect that browser. On-device monitoring apps can see more and cost more privacy. Generic parental-control products that filter only at a home router often fail the moment a child uses mobile data. That is not an OathSafe feature: OathSafe protection is configured on the child’s device, and you don’t need to change router settings. Device-level DNS is the usual answer to “it should still work at a friend’s house,” with the caveat that the device must keep the setting.
A realistic role for a family product
OathSafe is family internet protection for iPhone, iPad and Android. It uses DNS filtering to block unwanted online content and monitors whether that protection appears to stop. It can alert parents when protection cannot be verified, without reading their child's messages or browsing content.
That combination — filter plus a check that the filter still appears to be there — is the honest product shape. It is not omniscience. It is not a claim that VPNs cannot exist. It is a way to keep everyday internet use inside house rules, and to be told when the house rule may have stopped applying.
A parent checklist
- Enrol each child’s device you care about. You don’t need to configure the home router.
- Confirm Private DNS or the configuration profile after OS updates.
- Pair DNS rules with app-install restrictions where the OS allows it.
- Test a known blocked site on cellular data.
- Have a plan for spare devices and shared tablets.
- Treat VPN and DNS-change risks as limitations, not as personal failure.
Frequently asked questions
Does DNS filtering work on games and apps, or only websites?
Many apps still look up hostnames and will fail or degrade if those names are blocked. Some games and messaging apps are more resilient. Always test the apps your child actually uses.
Is DNS filtering the same as a firewall?
No. A firewall can block addresses and ports more broadly. DNS filtering is specifically about names. It is simpler to run on a phone; it is also easier to walk around if the phone stops using that DNS.
Will my child know DNS filtering is there?
They may notice blocked sites. They may not see a dedicated “spy” app. Privacy-respecting DNS tools still change what loads; they should not pretend to be invisible in a sneaky sense — house rules work better when they are spoken.