Back to Support
FAQ

How VPN and Proxy Bypass Attempts Are Detected

Kids quickly learn that VPN apps promise to beat content filters. Here's how the gateway spots those attempts and what happens next.

The bypass playbook

Content-filtering workarounds all work the same way: route traffic somewhere else first, so the network can't see the real destination. Kids try VPN apps, free proxy sites, DNS-over-HTTPS, and mobile hotspots. DNS-level filtering at the gateway is uniquely positioned to catch this, because every connection — even one trying to hide — still has to leave through the gateway.

What the gateway does

  1. Blocks known VPN and proxy domains, so the apps and services themselves can't be reached or installed in the first place.
  2. Flags common VPN protocols and encrypted-DNS patterns on the network, catching tools that were sideloaded.
  3. Raises an alert for the household, and logs the attempt with the device and time, so you can act on the behavior, not just the traffic.

What alerts look like

A VPN attempt alert names the device and the profile, so you know who to talk to. The attempt itself is also visible in the activity log.

The honest limits

A determined teen with a cellular data plan can always leave your network entirely — that's a conversation, not a configuration. But on your home Wi-Fi, the common routes are closed.