Solutions
Home & FamilyBusinessMSP / MSSP
Tools
Domain CheckerDNS Leak TestThreat Intel
Company
PricingGuidesDocsAboutContact
Home / Guides / Stop DNS bypass

How to stop devices bypassing DNS filtering.

DNS filtering only works for lookups that reach it. Here are the four common ways devices go around it, and how to close each one.

Set up · Updated September 30, 2026 · 7 min read

In shortBlock outbound port 53 and 853 to everything except your DNS servers. Turn off browser DNS-over-HTTPS by policy (Chrome and Edge: DnsOverHttpsMode = off). Let the network signal Firefox to turn off its automatic DoH, and answer "no such domain" for iCloud Private Relay. Then decide your VPN policy.

1. Hard-coded DNS servers

Some devices and apps ignore the DNS servers your network hands out and use their own, such as 8.8.8.8 or 1.1.1.1. The fix is a firewall rule:

  1. Allow outbound UDP and TCP port 53 only from your DNS servers (the firewall itself or your domain controllers) to the DNSAFE addresses.
  2. Block outbound port 53 from every other internal address.
  3. Also block outbound TCP 853 (DNS-over-TLS) except to dns.dnsafe.net, if you use it.

Some firewalls can instead redirect stray port-53 traffic to your DNS server (often called DNS interception or a port-forward NAT rule). That's friendlier than blocking, because the device still gets filtered answers.

2. Browsers' own encrypted DNS (DoH)

DNS-over-HTTPS sends lookups inside normal HTTPS traffic on port 443, so a port rule can't catch it. Handle it at the browser:

Chrome and Edge

Chrome only upgrades to DoH automatically when the system's DNS provider supports it, but users can pick their own provider in settings. On managed computers, set the DnsOverHttpsMode policy to off:

Firefox

Firefox checks a "canary" domain, use-application-dns.net. If the network's DNS says it doesn't exist, Firefox leaves its automatic DoH off. DNSAFE answers that way for every registered network, so this works without extra setup. It doesn't override a user who switched DoH on themselves, so on managed computers also set Firefox's DNSOverHTTPS policy to disabled and locked.

Known DoH providers

For extra coverage, block the hostnames of public DoH services at the DNS layer. With SafeSearch enforcement turned on for a network, DNSAFE blocks well-known DoH endpoints automatically.

3. iCloud Private Relay

On iPhones, iPads and Macs with iCloud+, Private Relay sends Safari traffic and its DNS through Apple's relays. Apple's guidance for networks that need filtering is to make mask.icloud.com and mask-h2.icloud.com fail to resolve (no answer, or "no such domain"). The device then tells the user that Private Relay is off for this network. Avoid silently dropping the traffic, which causes slow timeouts.

DNSAFE does this for networks with SafeSearch enforcement turned on. You can also add both names to your block list.

4. VPNs and proxies

A VPN app sends all traffic, including DNS, to its own servers. DNS filtering can't see inside it. Your options:

Try DNSAFE on your own network: 14 days free, no card, set up in minutes.

Start free trial

Check your work

  1. From a test device, run nslookup example.com 8.8.8.8. With the port-53 rule in place it should time out or be refused.
  2. Open Chrome's chrome://policy and confirm DnsOverHttpsMode shows off.
  3. Run the DNS leak test in each browser. Every one should show DNSAFE.

Frequently asked questions

Is DNS-over-HTTPS bad for businesses?

No, encryption is good. It becomes a problem when a browser sends lookups to a provider you didn't choose. The fix is to use encrypted DNS to your own filtering provider (DNSAFE supports DoH and DoT) and turn off the browser's own choice.

Will blocking iCloud Private Relay break iPhones?

No. Following Apple's guidance, the device shows a notice that Private Relay isn't available on this network and carries on without it. Everything else works normally.

Can I stop every possible bypass?

Not with DNS alone. A determined user with admin rights can install a VPN. The steps above close the common routes; device management and a firewall with application control close most of the rest.

Sources

Protect every device on your network.

Point your router or firewall at DNSAFE. 14 days free, no card.