Skip to content

Denylist, allowlist and rewrites

Three pages hold your own rules. Each list takes up to 1,000 entries, and each entry can be switched off without deleting it.

Denylist and allowlist entries are domain patterns:

Pattern Matches Does not match
example.com example.com and every name under it (ads.example.com, a.b.example.com) notexample.com
=example.com exactly example.com www.example.com
*.example.com names under example.com (ads.example.com) example.com itself

A bare pattern covers the name and its subdomains because the resolver checks the queried name and each parent: ads.example.com is checked against ads.example.com, then example.com, then com.

Blocks the names you list, for every device on the profile, with EDE 17 and the extra text denylist: <pattern>. From the Logs page you can add a name to the denylist in one click.

Lets the names you list through, even when a blocklist, a parental category or service, or a security list would block them. Use it for false positives, sparingly: an allowlisted domain is not checked for malware or phishing. SafeSearch and YouTube restricted mode still apply to allowlisted names.

Answer a name with records you choose instead of resolving it:

Type Value Use
A an IPv4 address point nas.home.example at 192.168.1.20
AAAA an IPv6 address the same for IPv6
CNAME another name alias one name to another
TXT text verification records on a private name

Rewrites are checked first, before the allowlist. Exact names win over wildcard ones.

Highest precedence first; the first match decides:

  1. Rewrites
  2. Allowlist
  3. Denylist
  4. Security lists
  5. Parental controls
  6. Blocklists

One exception: SafeSearch and YouTube restricted mode are applied to allowlisted names too. Operator-level blocks come before all of these. The full rules are on Policy order.