Protective DNS
120M+ Domains
CIPA Compliant
1:1 Roaming
DNS-Layer Protection for K-12

CIPA-Compliant DNS Filter for Education

Every website visit begins with a DNS lookup — a device asking “where does this domain live?” A DNS filter answers that question selectively: safe domains resolve, restricted ones never do. For schools, it is the fastest route to CIPA-aligned filtering: no appliances, no browser plugins, protection in place in an afternoon.

Explore
Hours Typical deployment time
120M+ Domains behind decisions
0 Appliances required
1:1 Roaming client coverage
The Mechanism

Blocking at resolution: earlier is better

Most filtering approaches inspect traffic that is already flowing. DNS filtering intervenes a step earlier, at the moment of resolution — the restricted site is unreachable because the device never learns where it is. That earliness has practical consequences. There is no page partially loaded before a verdict, no dependence on a particular browser, and no measurable performance cost, because a DNS answer arrives in milliseconds either way.

Security teams call this pattern protective DNS, and it has become a baseline recommendation well beyond education: the same mechanism that stops a student reaching an adult site also stops a staff laptop resolving a phishing domain or malware command-and-control server. A school that deploys a DNS filter for CIPA reasons quietly gains a network-security layer in the same stroke.

The other consequence is universality. Anything that speaks DNS is covered — managed devices, teacher laptops, guest phones on student Wi-Fi, even printers and cameras that could never run a filtering agent. Point the network's DNS at the resolver and the whole building inherits the policy at once.

Two jobs, one lookup: the same resolution check that enforces student-safety categories also refuses phishing, malware and botnet domains for every device in the building — so the compliance project and the security hardening project turn out to be the same afternoon's work.

DNS Resolution Flow

Step 1: Device sends query — “Where is example-site.com?”
Step 2: Resolver checks 120M+ classified domains in 57+ categories
Step 3: Safe → resolves normally | Restricted → block page returned
Step 4: Decision logged — domain, category, group, timestamp for E-Rate evidence

Real-Time Category Lookup

Query: new-ai-essay-site.example — registered last week
Classification: AI Tools → Essay Writers & Paraphrasers (added during daily screening of ~300K new domains)
Middle-school policy: Does not resolve — block page returned
Query: state-library.example
Classification: Education · Government
Every policy: Resolves instantly
Classification Intelligence

A resolver is only as smart as its category data

Here is the honest truth about DNS filters: the mechanism is a commodity. Any resolver can refuse to answer. What separates a toy from a school-grade filter is the classification behind the refusal — how many domains it knows, how finely it categorizes them, and how quickly it learns about new ones.

Our resolver draws on the same database that powers our full CIPA content filtering: 120M+ domains, 57+ categories, multiple categories per domain, refreshed daily, with newly registered domains classified as they appear. The AI Tools Blocklist rides along too — 16,328+ AI-tool domains in 18 categories, from essay writers to deepfake and companion-chat tools, deliverable natively at the DNS layer as an RPZ/DNS blocklist for districts that run their own resolvers.

  • Same taxonomy as our web filtering — policies and reports translate directly
  • Policy by school, grade band or user group, at the resolver
  • SafeSearch enforceable at the DNS layer for major search engines
  • AI-tool categories toggleable per group, updated daily
Why Schools Choose It

What the DNS layer buys a school IT team

Districts with one network technician — or none — need filtering that mostly runs itself. This is the shape of it.

Live in hours, not semesters

Change the DNS settings on your network — typically a DHCP option or a firewall rule — and filtering is on. No appliance procurement, no SSL certificates pushed to devices, no re-cabling. Pilots often happen the same day as the first call.

No speed penalty

The filter adds a category check to a lookup that was happening anyway, so pages feel exactly as fast as before. During state testing windows, when the network is under the most load and scrutiny, that predictability matters.

Encryption is not an obstacle

HTTPS hides page content but not the DNS question that precedes it. A DNS filter enforces category policy on encrypted sites without decrypting anything — effective blocking with no intrusion into what students read or type on allowed sites.

Behind the Resolver

The dataset answering every lookup

Every “resolve or refuse” decision leans on classification work that never stops running.

120M+Classified domains
~300KNew domains screened per day
18AI-tool categories
DailyBlocklist & category updates
Step by Step

How DNS filtering works, in four moves

DNS filtering is disarmingly simple, which is exactly why school IT teams like it. The entire enforcement happens in the split second before a connection even exists.

1

A device asks for a domain

A student clicks a link. Before anything loads, the device sends a DNS query — “what is the address of this domain?” — to the resolver the school points it at. Every internet-connected device does this, from Chromebooks to lab desktops to the smart display in the front office.

2

The resolver checks categories

Our resolver looks the domain up against a classification database of 120M+ domains in 57+ categories, updated daily. The lookup happens at the resolver, so nothing needs to be installed on the network path and no traffic is decrypted.

3

Safe resolve; restricted block

If the domain's categories pass the policy for that school or group, the real address comes back and the page loads normally — students notice nothing. If a category is blocked, the resolver returns the address of a block page instead. The connection to the restricted site is never made.

4

Decision is logged

Each blocked resolution is recorded with its domain, category, group and timestamp — building the same style of category-level evidence that supports E-Rate certifications and answers parent questions with specifics.

Roaming clients: DNS filtering that rides along in 1:1 programs

Network-level DNS settings protect the building. A 1:1 program leaves the building every afternoon. The answer is a lightweight roaming client on each managed device that pins its DNS queries to your filtered resolver wherever the device connects — home Wi-Fi, a relative's house, a coffee shop, a hotspot. The client also closes the obvious workarounds. Students cannot sidestep policy by typing in a public resolver's address or using DNS-over-HTTPS to an unfiltered service, because the device's queries are locked to the filtered path. For the district, the certification story stays consistent: the technology protection measure follows the device, which is exactly the posture E-Rate reviewers like to see for take-home programs.

Deployment Patterns

How different schools actually deploy it

The same resolver and category data flex around very different institutions. These are the patterns we see most, and what each one takes to stand up.

Resolver
District
School
Library
Self-hosted DNS

The multi-building district

DNS forwarding at each site's firewall points every building at the filtered resolver, with per-building policies so the elementary campus runs tighter categories than the high school. Central IT sees one dashboard and one set of reports across all sites — and one place to grant an exception.

The small or independent school

One DHCP change on the main router, a starter policy from our K-12 templates, and filtering is live before dismissal. No dedicated network staff required; the head of school gets a monthly category summary that doubles as compliance evidence.

The library

Patron and staff networks get separate policies: the CIPA floor enforced on minors' access, with a documented, logged path for staff to lift the filter for adults engaged in lawful use. Public catalog terminals and patron Wi-Fi are covered by the same resolver settings.

Self-hosted resolvers

Keep your existing BIND or Windows DNS servers and feed them our category data and AI Tools Blocklist as an RPZ zone, refreshed daily. Enforcement stays entirely inside your infrastructure — a popular pattern where policy requires on-premise control.

Every device on the network

Guest phones, loaner laptops, IoT devices — anything using school DNS is inside the policy. That closes the classic gap where the filter only protected the devices IT happened to manage.

Security layer included

Malware, phishing, botnet and scam categories are blocked at resolution, cutting off threats before a connection exists. Protective DNS is one of the cheapest security wins available to a district.

Light on budget and staff: No hardware to buy, rack or refresh, and policy is a short set of category rules. For small districts and independent schools, DNS filtering is frequently the difference between compliance and a project that never starts. See pricing for how it scales.

Compliance

Does a DNS filter satisfy CIPA?

CIPA requires a technology protection measure that blocks obscene material, child sexual abuse material, and content harmful to minors. It is deliberately technology-neutral — it does not prescribe proxies, appliances or any specific mechanism. A DNS filter that reliably prevents minors from reaching the domains carrying that content, backed by classification broad enough to mean “reliably,” functions as that measure, and schools and libraries have long certified on this basis.

The strength of the certification rests on the same three legs as any filter: enforcement that is actually on for the devices in question, categories that genuinely cover the required content classes, and records that prove both after the fact. Category-level resolver logs provide the evidence; roaming clients extend the enforcement to take-home devices; and the compliance floor — the CIPA-mandated categories — stays locked for student groups regardless of what else a district tunes.

Remember, too, that the filter is one requirement among several: CIPA also expects an adopted internet safety policy, monitoring of minors' online use, and educating students about appropriate online behavior. Our CIPA-compliant web filter page walks through the full certification picture — audits, evidence and the E-Rate context — and applies whichever enforcement layer you choose. Many districts start at the DNS layer, certify with confidence, and add URL-level filtering later where instruction demands finer control.

CIPA Certification Checklist

  • Technology protection measure blocking required content classes
  • Category-level resolver logs for E-Rate evidence
  • Roaming clients extending enforcement to take-home devices
  • CIPA-mandated categories locked for student groups
  • Adopted internet safety policy
  • Monitoring of minors' online use
  • Student education about appropriate online behavior
Straight Talk

Where DNS filtering stops, and full web filtering continues

DNS filtering judges domains. It cannot see paths, pages or the content inside an allowed site. For many schools that trade-off is exactly right; for others it is only the first layer. You should know the difference before you buy either.

CapabilityDNS FilterFull Web Filtering
Block whole domains by category Yes, at resolution Yes
Deploy without appliances or agents on-network Hours More setup involved
Cover unmanaged and IoT devices Anything using school DNS Typically managed devices
Distinguish pages within one site Domain-level only URL- and path-aware
Apply granular in-site rules Beyond DNS's reach Yes
SafeSearch enforcement Via DNS for major engines Yes, with finer control
Category logs for E-Rate evidence Yes Yes, with page detail
How to decide: if your filtering questions are mostly “should this site be reachable at all?”, DNS answers them cleanly. If they are “which parts of this platform, for whom?”, you want the full stack — or DNS now with an upgrade path. Our guide comparing web filtering vs. DNS filtering works through the decision in detail, and our web filtering software for schools page shows what the fuller layer adds.

A Take-Home Chromebook's Evening

4:05 p.m., school bus Wi-Fi: roaming client sends DNS to our resolver — homework sites resolve, blocked categories do not.
7:40 p.m., home network: same client, same policy. The family router's DNS settings are irrelevant; the device carries its own.
Next morning: last night's activity appears in the district's category reports alongside on-campus traffic — one view, everywhere.
Day-to-Day

What running it actually feels like

After the first week, a DNS filter mostly disappears into the background — which is the point. The recurring work is small and predictable: skim the weekly category report for anomalies, action the occasional exception request from a teacher, and glance at blocked-resolution trends before board meetings. Because new domains are classified automatically and blocklists refresh daily, there is no list to maintain and no signature update to schedule.

The moments that used to consume days become minutes. A parent asks why a site was blocked: the log shows the domain, category and time. A teacher needs a site opened for one class: a scoped exception, applied at the resolver, live immediately. An E-Rate review letter arrives: export the category policy and the block logs for the funding year, and the enforcement half of the response is done.

  • Per-device policy that travels with the student
  • Blocks the use of unfiltered public resolvers and DoH bypasses
  • Off-campus activity appears in the same category reports
Questions

DNS filtering questions from school IT teams

Is a DNS filter enough for CIPA compliance on its own?
The filtering half, yes — when the resolver blocks the required content classes for minors and you can evidence it, it serves as the technology protection measure. CIPA compliance as a whole also needs your internet safety policy, monitoring and student education. The filter cannot write your policy, but its reports make the enforcement part of the certification concrete.
Will students notice any slowdown?
No. A DNS lookup happens before every page load regardless; the filter simply makes that lookup consult category data. Answers return in milliseconds, and allowed sites — the overwhelming majority of school traffic — load exactly as they always did. Districts typically see no measurable difference, even at peak morning login.
Can students bypass it with a public DNS server or DNS-over-HTTPS?
On the school network, resolver lockdown rules keep DNS traffic pointed at the filter, and known DoH endpoints and proxy categories are blocked. On managed 1:1 devices, the roaming client pins queries to the filtered path so switching resolvers in settings has no effect. No filter makes bypass impossible, but the practical routes are closed and attempts show up in your logs.
Does it work when students take devices home?
Yes, through the roaming client. The device carries its policy to any network — home broadband, hotspots, public Wi-Fi — and its activity flows into the same district reports as on-campus traffic. Families do not configure anything, and nothing they change on the home router affects the filtering.
Can we block a page within a site but allow the rest of it?
Not at the DNS layer — a resolver decides per domain, not per URL. You can block or allow whole domains and subdomains, which covers most school policy cleanly. When you need path-level nuance inside big platforms, that is the signal to pair or upgrade to full web filtering; the categories and policies carry over, so nothing is thrown away.
Can we run the blocklists on resolvers we already operate?
Yes. Districts that run their own BIND or Windows DNS infrastructure can consume our category data and AI Tools Blocklist as an RPZ/DNS blocklist feed, with CSV, hosts-file, firewall EDL and API formats available for adjacent systems. You keep your architecture; we keep the data fresh with daily updates.
What happens when a student hits a blocked domain?
The lookup returns our block page instead of the site, and the page says which category triggered the block. Students get an explanation rather than a browser error, teachers know it was policy and not an outage, and the event is logged with domain, category, group and time for reporting.

Filtered DNS by Friday

Tell us your network setup and 1:1 device mix, and we will map the fastest route to CIPA-aligned DNS filtering — including what to check before you certify.