Denylist, allowlist and rewrites
Three pages hold your own rules. Each list takes up to 1,000 entries, and each entry can be switched off without deleting it.
Rule syntax
Section titled “Rule syntax”Denylist and allowlist entries are domain patterns:
| Pattern | Matches | Does not match |
|---|---|---|
example.com |
example.com and every name under it (ads.example.com, a.b.example.com) |
notexample.com |
=example.com |
exactly example.com |
www.example.com |
*.example.com |
names under example.com (ads.example.com) |
example.com itself |
A bare pattern covers the name and its subdomains because the resolver
checks the queried name and each parent: ads.example.com is checked
against ads.example.com, then example.com, then com.
Denylist
Section titled “Denylist”Blocks the names you list, for every device on the profile, with EDE 17 and
the extra text denylist: <pattern>. From the Logs page you can add a
name to the denylist in one click.
Allowlist
Section titled “Allowlist”Lets the names you list through, even when a blocklist, a parental category or service, or a security list would block them. Use it for false positives, sparingly: an allowlisted domain is not checked for malware or phishing. SafeSearch and YouTube restricted mode still apply to allowlisted names.
Rewrites
Section titled “Rewrites”Answer a name with records you choose instead of resolving it:
| Type | Value | Use |
|---|---|---|
A |
an IPv4 address | point nas.home.example at 192.168.1.20 |
AAAA |
an IPv6 address | the same for IPv6 |
CNAME |
another name | alias one name to another |
TXT |
text | verification records on a private name |
Rewrites are checked first, before the allowlist. Exact names win over wildcard ones.
Highest precedence first; the first match decides:
- Rewrites
- Allowlist
- Denylist
- Security lists
- Parental controls
- Blocklists
One exception: SafeSearch and YouTube restricted mode are applied to allowlisted names too. Operator-level blocks come before all of these. The full rules are on Policy order.