← Back to home

Product

Web filtering | Browsing control on the endpoint

What is DNS web filtering?
It is browsing control applied at the point where the computer translates a domain name into an IP address. When the computer tries to resolve a domain included in the policy, resolution is blocked and the attempt is logged. Acting on the computer's DNS, it covers every browser and application, not just one.
Can I block a whole category?
Yes. Each policy lets you enable full categories (Malware and phishing, Adult content, Gambling and online betting, Social media), fed from public domain lists. You can also add your own blocked domains and allowed domains as exceptions.
Can the user bypass it by switching browsers?
No. Filtering is applied at the system's DNS resolution level, not inside a browser or as an extension, so switching browsers does not evade it. The policy can also block known DNS over HTTPS (DoH) endpoints so the browser cannot sidestep the filter on its own.
Does it help enforce acceptable use policies?
Yes. You define which categories and domains are not allowed under the customer's acceptable use policy, and the block report, with domain, computer and date, provides the record that the policy is being enforced.
Does it apply to every computer equally?
Not necessarily. There is a base policy per customer and you can create additional policies assigned to a computer, a security group or an Organizational Unit of the customer's Active Directory.
Do I need to install extra hardware on the customer's network?
No. Filtering runs inside the agent already installed on each computer. There is no appliance, no intermediate server, no router changes.
Does it work if the user takes the laptop home?
Yes. Since filtering lives on the computer, the policy applies on any network it connects to.
What happens if the computer loses connection with the panel?
It keeps enforcing the last policy and lists it downloaded.
Can I block a specific section of a site?
No. Whole domains are blocked. With HTTPS the rest of the address travels encrypted, so you can block an entire site but not a part of it.
Can I apply a different policy per area of the company?
Yes. Policies are assigned to a specific computer, an Active Directory security group or an Organizational Unit, and are resolved with a defined precedence order.
What happens if the agent stops working?
The computer recovers its original DNS configuration and keeps browsing. The filter goes down, connectivity does not.
Try KairosLink free for 14 days

All modules included. No credit card.