Choose a defined feature
A filtering DNS resolver can refuse known harmful domain lookups. It is a useful layer, but it does not inspect every downloaded file or guarantee that every scam site is blocked. Different resolver addresses from the same provider can offer different behaviour, so use the provider's current configuration instructions.
Quad9 publishes free-service configuration and diagnostic guidance. Review that documentation directly. Do not copy resolver addresses from a random social-media image or assume that a paid security subscription is required for this exercise.
Make a reversible test
- Record the test device's existing DNS settings and any required internal names. Choose a device where you can safely undo a change without interrupting other users.
- Configure the selected resolver through the supported device or browser controls. Identify whether the change applies to the whole operating system or only one browser.
- Use the provider's official harmless block-test domain and diagnostic procedure. Do not search for an actual phishing or malware site to prove the filter works.
- Check normal browsing and any required internal services. If a legitimate service stops working, verify the domain and the provider's support or false-positive process before overriding the protection.
Interpret a blocked result
The provider's documented test should behave as described for the filtering endpoint. A browser error alone is ambiguous: ordinary DNS failure, connectivity loss or a local filter can produce similar symptoms. Compare with a known working domain and use the resolver's diagnostic information.
If the test does not match expectations, inspect VPN DNS, browser secure-DNS choices and organisation policy. Another resolver may be handling the query even though you changed one system setting.
Avoid broad allowlisting
An exception should identify the necessary domain and a clear reason. Allowing every domain related to an application, or disabling all filtering permanently, can remove much more protection than intended. Document any temporary override and review it after troubleshooting.
Maintain realistic expectations
Filtering is strongest when combined with updates, account protection and a reporting routine. Keep the configuration record so another administrator can reproduce or reverse it. Retest after replacing the router or VPN, because the visible device setting may no longer describe the resolver actually in use.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.