DNS Firewall · Private Content Filtering

Content filtering that keeps browsing private

DNS Proxywall filters the web by domain name entirely on your own Windows machine. You get block-and-allow control over every browser and app — with no cloud provider logging your lookups, profiling your interests, or selling your data.

On your PC
filtering, rules and logs all stay on your own machine
No account
nothing to sign up for and nothing tracking you
0 third parties
your browsing is never sent to a filtering provider

Private by design

Most ways to filter the web quietly cost you your privacy. A cloud-based content filter — the hosted, third-party service you would point your DNS at instead of DNS Proxywall — routes every query you make through the provider’s own servers, usually tied to an account. Once your lookups are there, that provider may keep logs of them, run analytics on the data, build a profile of each user’s interests and habits, and even sell that information to third parties.

DNS Proxywall works the opposite way. It is software that runs entirely on your own Windows machine: the rule lists, the filtering decisions and the activity log all stay local, and you choose the upstream DNS resolver you trust. No third-party provider ever sees, logs, profiles or monetizes what your household or staff browse.

The privacy difference is structural, not a setting: there is simply no cloud service in the path to do the logging. The only place your filtering policy and history exist is the machine in front of you.

Filtering that lives on the machine

Browser extensions get removed and per-app settings get bypassed. DNS Proxywall does content filtering at the host level: its kernel-mode driver inspects the network traffic that carries the DNS protocol and matches each name against your rules, so it covers every program on the computer, on any network it connects to. Because the work happens locally on the DNS lookups in that traffic — not by inspecting page content and not in someone’s cloud — it is fast, lightweight and private.

You define the rules as an allow list (only the listed domains may resolve), a block list (the listed domains are denied), or a mix of both. Wildcards keep rules short, and category profiles let you keep several policies ready to switch between.

Ways to shape access — privately

Nothing leaves your machine

The rules, the filtering decisions and the activity log live only on your computer. There is no account, no cloud dashboard and nobody upstream building a picture of what you browse.

Block or allow by pattern

Write rules against domain names with wildcards, such as *.example.com, to cover a whole site at once. Combine block lists and allow lists to fit your policy.

Profiles for each context

Group related sites into named profiles by how you use them — a Work set, a Home set, a group you switch on or off temporarily, or a lockdown profile that allows a single site and blocks everything else. Activate whichever profile fits the moment.

Essentials, not trackers

The activity log shows every domain a page actually loads, so you can tell a site’s essential helpers — its content servers, APIs and sign-in — from the advertising and tracking domains it quietly pulls in, and allow only what the site genuinely needs.

Redirect with a host table

Map names to custom IP addresses in the permanent host address table — a wildcard-aware version of the Windows hosts file — to point a blocked name at an internal notice page or a safe address.

Filter by where a site is hosted

With Geo DNS, DNS Proxywall resolves the country behind each address and can block names that resolve to regions you would rather not reach — keeping connections to undesirable geographies off the machine.

Set up private content filtering in four steps

  1. Decide allow or block

    Choose whether to block known-bad categories, allow only an approved list, or combine both approaches.

  2. Write the rules

    Add domains as wildcard name-pattern rules and group them into a category profile — all kept on your machine.

  3. Add redirects where useful

    Point selected names at an internal page or safe address using the permanent host address table.

  4. Review locally

    Check the on-machine activity log to confirm the right names are filtered — nothing is uploaded to review it.

Cloud content filter vs. DNS Proxywall

Privacy question DNS Proxywall
Who sees your lookups? Only your own machine — nothing is routed through a filtering provider
Is there an account that can track you? No account is required
Where do the rules and logs live? On your computer, under your control
Can your interests be profiled and sold? No third party ever receives your browsing
Does it still filter every app? Yes — enforced machine-wide by the kernel-mode driver

Private content filtering questions

Is local content filtering more private than a cloud filtering service?

Yes. A cloud-based content filter is a hosted, third-party service you point your DNS at instead of DNS Proxywall, so every query is routed through the provider’s servers and usually tied to an account. That provider may keep logs, run analytics, build a profile of each user’s interests, and even sell the data to third parties. DNS Proxywall is software that runs entirely on your own machine: the rules, decisions and activity log stay local, and no third-party provider sees what is browsed.

Does DNS Proxywall log or send my browsing anywhere?

No. The activity log is written only on your own machine, and you can turn it off entirely. Nothing about your DNS lookups is sent to Verigio or to any filtering provider. You also choose which upstream DNS resolver to forward unrecognized names to, so you stay in control of where queries go.

Can I keep different policies for different situations?

Yes. Rules are organized into category profiles, so you can build a strict profile and a relaxed profile and switch between them. The number of profiles available depends on the edition.

Can I redirect a blocked site instead of just blocking it?

Yes. A permanent host address table lets you map domain names to specific IP addresses, similar to a Windows hosts file but with wildcard support, so you can point a name at an internal notice page or a safe address.

Does it filter every browser and app?

Yes. DNS Proxywall filters at the machine level through a kernel-mode driver that inspects the network traffic carrying the DNS protocol, so the policy applies to every browser and application that resolves names on that computer.

Filter the web without being watched

Block what you don’t want and keep your browsing on your own machine — no cloud, no account, no profiling.

Explore DNS Proxywall use cases

Notes:
* Windows® is a registered trademark of the Microsoft Corporation.