Here's the thing about per-device parental controls: they're a game of whack-a-mole. You lock down the iPhone, your kid hops on the Xbox. You set up Family Link on the Android tablet, they watch YouTube on the smart TV in their room. Every device is a separate setup, a separate bypass risk, a separate thing to remember to update.

Router-level DNS filtering (the phonebook your router uses to find websites — by changing it, you can block bad ones before they load) is the one setting that covers all of them at once. One change at your router, and every phone, tablet, laptop, game console, and smart TV on your home network goes through the same content filter. No software to install on each device. No per-device configuration. No kid who can just "borrow dad's old tablet" to get around the rules.

This guide covers exactly how to do it with CyberDaddy DNS or another filtering DNS provider (DNS filter services — tools that block bad websites before they load), plus what DNS filtering can and can't do, and how CyberDaddy makes the whole setup guided.

Before you start

Have these ready:

  • Your router's admin password (check the sticker on the back of the router — it's labeled "Admin password" or "Login")
  • 10–15 minutes uninterrupted
  • Your router brand (Netgear, ASUS, Linksys, TP-Link, Xfinity, etc.) — steps vary slightly by brand

If you can't find your router admin password, call your internet provider — they can reset it.

1. How Router DNS Filtering Actually Works

Every time a device on your network tries to load a website or app — TikTok, YouTube, a gaming site, a news article — it first asks a DNS server (this is the filter's address — like changing which phonebook your router uses): "What's the IP address for this domain?" Your router tells devices which DNS server to use.

Normally, that DNS server is your ISP's default, which just answers every question without filtering anything. When you change your router's DNS to a filtering DNS service, requests go through that filter instead. The filter checks every domain against your household rules. If the domain is blocked, it returns nothing — and the app or website can't connect.

Why it covers everything

DNS is a universal protocol

Every networked device uses DNS. iPhones, Androids, Windows laptops, Chromebooks, PlayStation 5, Nintendo Switch, Roku, Fire TV, smart home devices — they all ask DNS before connecting to anything. Change DNS at the router, and you filter all of them with one setting.

2. Setting Up DNS Filtering

CyberDaddy's guided setup keeps this step parent-friendly: choose Home Internet DNS, follow the router prompts, and verify that filtering is actually active. If you use a standalone DNS provider instead, the same basic steps apply — configure categories, copy the DNS targets, and test the block before you hand the network back to your kids.

Step 1

Start with CyberDaddy guided setup

Open CyberDaddy's free setup, choose the home internet/router path, and keep the dashboard open. It will show the DNS targets and verification steps for the family profile you are protecting.

Step 2

Configure your blocklists and categories

In your CyberDaddy dashboard or DNS provider dashboard, enable the categories that match your household rules: adult content, malware, phishing, social media, gambling, gaming, VPN/proxy services, and other risky categories you want blocked at the network layer.

Step 3

Note your DNS IP addresses

Copy the primary and secondary DNS addresses shown by CyberDaddy or your chosen DNS provider. Those are the values you will enter in your router's DNS settings.

3. Changing Your Router's DNS Settings

Every router has a different admin interface (the settings page built into your router — usually at 192.168.1.1 in your browser), but the general steps are the same. You need to find the DNS settings and replace your ISP's default DNS with your filtering DNS addresses.

Step 4

Log into your router admin panel

On most home networks, the router admin is at 192.168.1.1 or 192.168.0.1. Open a browser on any device connected to your home Wi-Fi and type that address. The login is usually printed on the bottom of your router (default username/password). If you've never changed it, try admin/admin or admin/password.

Step 5

Find the DNS settings

Look for: WAN settings, Internet settings, Advanced settings, or DNS settings. The exact location depends on your router brand. Common locations:

Netgear: Advanced → Setup → Internet Setup
ASUS: WAN → Internet Connection → WAN DNS Setting
TP-Link: Advanced → Network → Internet → DNS
Eero: eero app → Settings → DNS
Google/Nest Wifi: Google Home app → Wifi → DNS
Step 6

Enter your filtering DNS IP addresses

Change DNS from "Automatic" or your ISP's addresses to the primary and secondary DNS addresses from CyberDaddy or your chosen provider. Save settings and restart your router. All devices should reconnect through the filtered DNS path within a few minutes.

Step 7

Verify it's working

Use the verification step in your CyberDaddy dashboard or DNS provider dashboard from a device on your network. Then try visiting a site you blocked — it should fail to load.

Want this set up for you, step by step?

CyberDaddy walks you through your specific router model, verifies your DNS is filtering, and confirms every device on your network is covered.

4. Setting Up Profiles Per Household Member

One of the most useful DNS-filtering features is profile-based rules: you can assign stricter filtering to kids' devices while keeping parent devices looser.

Step 8

Create a separate profile for kids' devices

In CyberDaddy or your DNS provider dashboard, create a kids' profile or group. Configure stricter rules — block social media, gaming sites, adult content, and more — and note the DNS addresses or install profile assigned to that kids' policy.

Step 9

Assign the kids' profile to specific devices

You have two options. Option A: configure the kids' devices to use the kids' profile DNS addresses directly in the device network settings (Settings → Wi-Fi → [network] → DNS on iPhone, or Private DNS on Android). Option B: in your router, use DHCP (your router's system for giving each device its network settings) reservations to assign specific IPs to kids' devices, then configure your router to send those IPs a different DNS server. The first method is simpler.

5. What DNS Filtering Can and Can't Do

DNS filtering is powerful, but it's important to understand its limits so you set realistic expectations and add other layers where needed.

What DNS CAN do

Block entire domains and categories — adult content, social media, gambling, gaming, VPN services, malware, phishing. Works on every device on your network. Logs what domains are being blocked and which devices are requesting them. Forces SafeSearch on Google, YouTube, and Bing. Can be configured per-device with separate profiles.

What DNS CANNOT do

Inspect page content within allowed domains. HTTPS traffic is encrypted — DNS can block youtube.com entirely, but if YouTube is allowed, DNS cannot filter which specific videos your child watches. For in-app filtering within allowed services, you need the service's own parental controls (YouTube Restricted Mode, etc.) layered on top of DNS.

What DNS CANNOT do

Control devices not on your Wi-Fi. Router DNS only applies to home network traffic. A phone on cellular data bypasses your router entirely. For mobile coverage outside the home, configure DNS filtering directly on the device with CyberDaddy DNS or your provider's device-specific settings (Private DNS on Android, configuration profile on iOS).

6. How Kids Bypass It and How to Close the Gaps

🔴 Bypass #1

Switch to cellular data

On a phone with a cellular plan, turning off Wi-Fi routes all traffic through the cellular carrier's network — which uses its own DNS and bypasses your router entirely. Fix: configure DNS filtering directly on the phone (Android Private DNS setting or iOS configuration profile) so it uses CyberDaddy DNS or your provider's filtered path on both Wi-Fi and cellular.

🔴 Bypass #2

Install a VPN app

A VPN tunnels traffic through a remote server and uses its own DNS, bypassing your router's DNS. Fix: enable VPN/proxy or bypass-method blocking in CyberDaddy DNS or your filtering provider. This blocks known VPN domains and DNS-over-HTTPS resolvers that could be used to bypass filtering. Also block VPN apps using Family Link (Android) or Screen Time (iOS).

🔴 Bypass #3

Manually change DNS on the device

On most devices, users can change the DNS server in network settings, overriding the router's DNS assignment. Fix: on iOS, use a configuration profile that enforces DNS-over-HTTPS or DNS-over-TLS — this cannot be removed without your Screen Time passcode. On Android, use the Managed Device option in Family Link for similar enforcement.

Frequently Asked Questions

How do I set up parental controls on my router?
The most effective method is changing your router's DNS to CyberDaddy DNS or your chosen filtering provider. Log into your router admin panel (usually 192.168.1.1 or 192.168.0.1), find DNS settings, and enter the DNS addresses shown in your CyberDaddy dashboard or provider dashboard. Every device on your home Wi-Fi is then filtered according to that household policy.
Does router DNS filtering block content on phones and tablets too?
Yes — any device on your home Wi-Fi uses the router's DNS, including phones, tablets, laptops, game consoles, and smart TVs. No software required on each device. The gap: phones on cellular data bypass the router. Configure DNS filtering directly on those devices for full coverage.
What can DNS filtering block and what can it not block?
DNS filtering can block entire domains and categories — adult content, social media, gambling, gaming, VPN services. It cannot inspect the content within pages of allowed domains (HTTPS traffic is encrypted). For filtering content within allowed services (like specific YouTube videos), you need the service's own parental controls on top of DNS.
Can my kid bypass router DNS filtering?
Common bypasses: switching to cellular data, using a VPN app, or changing the device's DNS settings manually. To reduce those gaps: enable VPN/proxy blocking in CyberDaddy DNS or your filtering provider, configure per-device DNS enforcement (iOS config profile, Android Private DNS), and combine with app-level controls (Screen Time, Family Link) that block VPN apps.
Do I need a separate DNS provider account?
Not for CyberDaddy DNS. CyberDaddy can guide the router setup and verify whether the protected DNS path is active. If your family already uses a separate DNS provider, you can still follow the same router steps with that provider's addresses during migration.

Router DNS is the foundation.

CyberDaddy builds on top of it — guiding you through the setup, verifying every device is covered, and giving you one dashboard to see what's being blocked and what's getting through.

Not ready yet? Get the free setup checklist by email: