Pick the recipe that matches your real bypass pattern
Do not start with the most complex setup. Start with the weakest setup that would actually stop you during a weak moment. If that fails, move up one recipe.
| Situation | Start here | Move up when |
|---|---|---|
| You have never configured anything. | Recipe A | You can still install apps, switch browsers, or change settings. |
| You mostly bypass on one phone. | Recipe B or C | Mobile data, app installs, or account recovery still work. |
| You use a Windows or Mac laptop. | Recipe D or E | You still have admin or can install a browser/VPN. |
| You are technical and keep undoing filters. | Recipe F | You still control recovery, router, admin, or root. |
| You want whole-home coverage. | Recipe G | Phones, guests, IPv6, DoH, or hotspots bypass it. |
Recipe A: simple first setup
Use this if you need a maintainable first layer and are not ready for trusted-person lockout.
- Pick the device you use most often when bypassing.
- Finish the matching built-in setup in Guardrails.
- Remove extra browsers and apps you do not need.
- Turn on app-install approval or block new app installs.
- Add family-safe DNS on the device or router from Friction.
- Run Test your setup.
- If you can undo it alone, move to the trusted-person steps.
Recipe B: iPhone or iPad only
When this is not enough, the two things that make an iPhone materially stronger are allowlist mode and stopping the DNS profile being switched off.
- Open Settings -> Screen Time and turn Screen Time on.
- Turn on Content & Privacy Restrictions.
- Set Web Content to Limit Adult Websites, or use Only Approved Websites for whitelist mode. Older versions of iOS call that option Allowed Websites Only.
- Set Installing Apps to Don't Allow.
- Set Deleting Apps to Don't Allow if deleting a blocker or browser is a bypass.
- Set Account Changes, Passcode Changes, and Cellular Data Changes to Don't Allow where available.
- Remove browsers, VPNs, proxy apps, and apps with unfiltered embedded browsers that you do not need.
- Install a DNS profile only if you understand who can remove it. For stronger control, use supervision or MDM.
- Have the trusted person set the Screen Time passcode. When iOS offers Screen Time Passcode Recovery, enter the trusted person's Apple Account, never your own, and do not skip the prompt.
- Test on Wi-Fi, mobile data, Safari, every remaining browser, and in-app browsers.
Recipe C: Android phone or tablet
If you need this to genuinely hold rather than just slow you down, see locking Private DNS on Android. It is the strongest phone lock there is, and the most work to set up.
An adult cannot put their own Google Account under a trusted person's supervision, and a supervised user aged 18 or over can end supervision themselves. If you are an adult setting this up for yourself, skip the Family Link steps and build the recipe on the layers that do not depend on supervision: Private DNS, removing extra browsers and app stores, browser policy, router and DNS enforcement, and a trusted person holding your Google Account password and recovery codes.
- Set up Google Family Link with a parent or trusted-person account, if the daily user's account is eligible for supervision.
- Use the managed Google Account on the device. Remove extra Google accounts that can install apps or change settings.
- In Family Link, set Chrome and Web to Try to block explicit sites or Only allow approved sites.
- Require approval for new Google Play installs and purchases.
- Remove extra browsers, VPNs, proxy apps, Tor, alternate app stores, and remote desktop apps.
- Set Android Private DNS to a family-safe hostname if that fits your setup.
- Turn off developer options if enabled. If the phone is rooted, treat local controls as weak.
- Have the trusted person control the parent Google Account, password recovery, and backup codes.
- Test Chrome, any remaining browser, YouTube, Google Search, Wi-Fi, and mobile data.
Recipe D: Windows laptop or desktop
The account split does more than people expect on Windows, and the browser gap undoes it if you skip that step. See making DNS stick on Windows.
- Use a standard account for daily use.
- Create a separate administrator account for maintenance.
- Have the trusted person hold the administrator password if you need lockout.
- Use Microsoft Family Safety if Edge filtering is acceptable for your setup.
- Remove extra browsers or lock them down with browser policy.
- Block app installation from the daily account. A standard account stops installers that need administrator rights, but it does not stop per-user or portable installers: Chrome, Firefox, and many portable browsers install into your own profile without a prompt. Closing that gap needs app allowlisting, below.
- Set filtered DNS and flush DNS.
- Use AppLocker or App Control for Business if your skill level allows. It enforces on every edition now, including Home, but Home is harder to recover from if you get a rule wrong.
- Turn on device encryption and store the recovery key away from the daily user. Without encryption the administrator password is not a boundary at all: it is reset from recovery media in about ten minutes.
- Run the browser, install, DNS, and recovery tests.
Recipe E: Mac laptop or desktop
A Mac is the easiest device to hold a DNS setting on, and needs no supervision to do it. See making DNS stick on a Mac.
Unlike iPhone, the macOS web filter does not reach Chrome, Firefox, Edge, or Brave, and macOS cannot block app installs. Steps 1 and 5 below are worth doing, but on a Mac the layers that actually hold are DNS, router, and browser policy. See Mac Guardrails for the detail.
- Turn on Screen Time and Content & Privacy restrictions. Set a Screen Time passcode held by the trusted person, or the rest is advisory.
- Create a standard daily account.
- Keep a separate administrator account for maintenance.
- Have the trusted person hold the admin password and Screen Time passcode.
- Remove extra browsers, VPNs, proxy tools, package managers, and remote desktop tools you do not need.
- Use a DNS profile or MDM profile only when the removal path is controlled by the trusted person.
- Use browser policy for Chrome, Edge, or Firefox if those browsers remain installed.
- Store FileVault recovery keys away from the daily user if disk recovery is a bypass.
- Test installing apps, changing Screen Time, changing DNS, and recovering admin access.
Recipe F: technical user who keeps undoing filters
This recipe assumes you know enough to defeat ordinary blocks. The target is not more reminders. The target is removing unilateral control.
- Stop using an admin/root/sudo-capable account for daily browsing.
- Move administrator, root, owner, parent, router, DNS-dashboard, and MDM credentials to the trusted person.
- Remove saved passwords, recovery codes, screenshots, notes, exported vaults, and emergency kits from your own access.
- Disable or control browser DoH/DoT with policy.
- Use allowlists where blocklists fail.
- Enforce filtered DNS at the router and on mobile devices.
- Block or require approval for VPNs, proxies, Tor, alternate browsers, developer tools, package managers, and remote desktop tools.
- Handle factory reset and external boot paths with device management, disk encryption, recovery-key handoff, or physical controls.
- Use Recovery audit and Trusted person handoff worksheet.
- Run Test your setup and give the failed items to the trusted person to review.
Recipe G: whole-home router and DNS setup
- Choose one filtering provider or local resolver: OpenDNS FamilyShield, CleanBrowsing, 1.1.1.1 for Families, NextDNS, AdGuard Home, or Pi-hole with appropriate blocklists.
- Set router DHCP DNS to the chosen resolver.
- Set IPv6 DNS too, or disable IPv6 if you cannot secure it and you understand the tradeoff.
- Block or redirect outbound TCP/UDP port 53 from client networks.
- Block outbound port 853, TCP and UDP, if you do not want clients using DNS-over-TLS or DNS-over-QUIC.
- Disable browser DoH with browser policy where possible.
- Apply the same rules to guest Wi-Fi, IoT VLANs, and extra SSIDs.
- Have the trusted person own the router admin password, DNS dashboard, ISP account recovery, and Wi-Fi mesh app.
- Run DNS and network tests from every device type.