Back to Support
FAQ

How Content Filtering Works

Guardian-CORR inspects every DNS lookup leaving your home network and compares it against category rules. Here's the full path a request takes.

Filtering at the network level

Every time any device on your network looks up a website — every app, every ad, every background connection — that lookup passes through the gateway. The gateway compares the domain against your household's rules: category blocks, per-profile overrides, and individual allow/block entries. Blocked requests are answered with a stop signal instead of the real address, so the site simply never loads, on every device, with nothing installed.

Why DNS filtering is hard to bypass

Because the filtering happens on the path every connection must use, a child can't uninstall it, can't switch browsers to escape it, and can't open an incognito window around it. The gateway also detects and blocks known VPN and proxy services that try to route around it.

What it covers

Filtering applies to all devices on your Guardian Wi-Fi — phones, laptops, consoles, smart TVs — including devices that have no parental-control ecosystem of their own.

What it isn't

It's not spyware: we filter destinations, we don't read message contents. And it applies while a device is on your home network; for protection on cellular, pair with built-in OS controls.