October 3, 2026
How DNS filtering actually protects your family
DNS filtering stops dangerous sites before your browser ever connects to them. Here's what DNS is, how the blocking works under the hood, and why it catches more than a browser extension or antivirus app ever could.
What DNS actually does
Every time you type a web address, click a link, or open an app that talks to the internet, your device needs to turn a name like "example.com" into a number called an IP address, the actual location of the server that will answer the request. That translation step is called DNS, short for Domain Name System. It happens before anything else: before your browser opens a connection, before a single byte of the page loads, before you see anything at all.
Think of DNS as the phone book for the internet. You don't dial raw numbers to call someone, you look up their name and the phone book hands you the number. DNS does the same job for websites, except it runs automatically, in the background, every single time you visit anywhere. A single page load can trigger dozens of these lookups: one for the site itself, and more for every image, script, ad, and tracker embedded in it.
Under normal circumstances, your device sends that lookup to whatever DNS server it's configured to use. For most people, that's whatever their internet provider or router hands out by default, with no filtering or review of any kind. Whatever address you ask for, you get an answer.
How DNS-level blocking works
DNS filtering changes one thing: which DNS server answers the lookup, and what that server does before it answers. Instead of blindly translating any name to its address, a filtering DNS server checks the requested domain against lists of known-bad destinations: phishing pages, malware distribution sites, ad networks, tracking domains, and, if you choose to turn it on, adult content or gambling sites.
If the domain is on a blocklist, the server simply declines to hand back the real address. Instead, it returns nothing, or it returns the address of a clear warning page explaining what was blocked and why. Your device never learns where the dangerous site actually lives, so it has no way to connect to it. No connection means no page load, no script execution, no chance for anything on that site to reach your device at all.
If the domain is clean, the lookup resolves normally and the page loads exactly as it would without any filtering in place. This is the part people find surprising: filtering doesn't inspect or slow down the content of safe sites at all. It only ever makes a decision at the lookup stage, which happens in milliseconds, long before any images or scripts start downloading.
Koru Shield runs this filtering over DNS-over-HTTPS, which encrypts the lookup itself between your device and our servers. That matters for two separate reasons. First, it means nobody sitting on the network between you and us, including your ISP or anyone sharing your Wi-Fi, can read which sites you're looking up. Second, it means nobody can tamper with the lookup in transit and redirect you somewhere else without your knowledge.
Why this catches threats earlier than other tools
Most of the security tools people already have work much later in the process. A browser extension that blocks malicious sites only runs once the browser has already started loading the page, which means the connection has already been made and at least some content has already arrived. Antivirus software typically scans files after they've been downloaded to your device, catching a threat only once it's already sitting on your hard drive.
DNS filtering sits earlier in the chain than either of those. Because the block happens at the lookup stage, before any connection is opened, a malicious site is stopped before your device ever talks to it. There's no content to load, no script to execute, no file to scan, because the connection was never allowed to happen in the first place.
This earlier position also means DNS filtering protects every application on a device, not just the browser. Phishing links that arrive by text message, email client previews that fetch tracking pixels, apps that quietly phone home to ad networks, all of these make DNS lookups too, and all of them get the same check. A browser extension only ever protects the browser it's installed in. DNS filtering protects the device, and if it's configured at the router, every device on the network behind it.
What it catches
In practice, DNS filtering is effective against several overlapping categories of problem:
- Phishing. Fake login pages designed to steal passwords or payment details are usually hosted on domains that get flagged quickly once identified, letting a filtering service block them for everyone else.
- Malware. Many malicious programs need to contact a remote server after installation, either to download additional components or to send back stolen data. Blocking the DNS lookups those programs depend on can prevent that communication even if the malware is already present.
- Adult content and gambling. Families that want a household-wide content filter can turn this on as an optional category, applied to every device without installing anything on each one individually.
- Trackers. Many sites load code from third-party tracking domains that build advertising profiles based on your browsing. Blocking those domains at the DNS level stops the tracker's request from ever going out.
What DNS filtering doesn't replace
It's worth being direct about the limits here. DNS filtering works by domain name, so it can't inspect the content of a page that resolves to an allowed domain, and it can't catch a threat that arrives through a channel that doesn't involve a DNS lookup, such as a malicious file you already downloaded and opened. It also can't protect you on a network where your device isn't using the filtering DNS server, which is why encrypted, device-level configuration matters, so settings can't be silently overridden by an untrusted network.
That's why DNS filtering works best as a layer, not a replacement for every other precaution. It pairs well with normal good habits like keeping software updated and being skeptical of unexpected links, and it works happily alongside antivirus software, which is solving a different part of the problem. What DNS filtering adds is a layer that works before any of those other tools get a chance to act, quietly, on every device, without asking you to do anything after the initial setup.
Setting it up takes about a minute
Because this all happens at the DNS lookup stage, turning it on doesn't require installing an app on most devices. You change one setting, point your device at a filtering DNS server, and every lookup from that device is checked from then on. Koru Shield's guided setup walks through this for iPhone, Android, Windows, Mac, Linux, and routers, each taking about a minute per device.
Protect every device in about a minute.
Start free with always-on DNS filtering, no credit card required.