What Is It

What Is DNS over HTTPS, and Why Does It Break Parental Controls?

KidMoat5 min read

DNS over HTTPS — usually written DoH — is a setting inside Chrome, Firefox and Edge that sends the browser's address lookups to its own servers instead of the phone's. It exists for a good reason: on a public network it stops strangers seeing which sites you visit.

It also switches off most parental control filtering, and this is the part worth knowing: nothing appears to break. The app keeps reporting, the limits still show, the dashboard stays green. The filtering has simply stopped seeing the traffic it is meant to filter.

No app is installed. No permission is granted. It is a toggle in a settings menu, and plenty of children find it by accident.


How filtering normally works

When a phone opens a website it first asks "what address is this name?" — a DNS lookup. Almost every on-device parental control filter works by watching those lookups and refusing the ones on a blocklist.

That works because, normally, the whole phone asks the same resolver.

DoH changes who gets asked. The browser stops using the phone's resolver and talks to its own over an encrypted connection that looks like ordinary web traffic. The filter is still running. It is simply no longer being consulted, and it has no way of knowing that.

There is a matching version called DNS over TLS (DoT) which does the same thing on port 853.


Why "the app said everything was fine" happens

This is the failure mode, and it is worth being precise about because it is not what parents expect.

A filter that has been bypassed does not report an error. Reports continue, because screen time is measured separately from filtering — the app can still see that the browser was open for two hours. What it can no longer see is where the browser went.

So the dashboard shows a plausible, complete-looking picture with the important part missing. A parent checking it has no reason to doubt it.


How to check

On the phone, look for Chrome's setting. Chrome → Settings → Privacy and security → Use secure DNS. If it is on and set to a provider rather than "your current service provider", the browser is doing its own lookups.

Firefox has the same thing under Settings → Privacy and security → DNS over HTTPS.

Check for a key icon in the status bar as well. That is a VPN rather than DoH, but it produces the same blind spot and is the more common cause — here is what to do if a VPN has appeared.

Then test it properly. Try to open something you know is blocked, on the child's phone, in whichever browser they actually use. It is the only check that tells you about the setup you have rather than the one you think you have.


What survives it

Two things are needed. A filter that intercepts DNS for the whole device rather than inside one browser, and something that specifically handles the DoH route.

KidMoat does both. It filters at the DNS level on the device, so it applies to whatever browser is open — including one installed five minutes ago, which is the other common way around a browser-specific filter. And it blocks the public DoH provider domains, so a browser that tries to use them cannot reach them and falls back to the resolver the filter can see. DNS-over-TLS on port 853 is refused, so that route falls back the same way.

The effect is that switching on secure DNS, or installing a different browser, does not open a hole.

Where this genuinely stops: no DNS-based filter — ours or anyone's — reaches inside a browser embedded in another app, like the one TikTok or Instagram opens for a link. That is a real limit of the technique rather than a gap in a product, and any page claiming otherwise is selling you something. A device the child fully administers can also be reset. What good filtering does is remove the casual routes and tell you when protection is switched off, which KidMoat reports rather than hiding.


Worth saying out loud

Your child switching this on is usually not an attack on you. Privacy settings are recommended constantly online, "secure DNS" sounds obviously good, and a fourteen- year-old turning on something labelled secure is behaving reasonably.

The conversation that works is about what it does — including that it hands their whole browsing history to whichever company runs that resolver, which is a fact about being used rather than a rule you are imposing.


Related Posts

See how KidMoat works

Set the day’s limit together, keep distractions out of study hours, and switch to Exam Day in one tap. Works whether the phone is theirs or yours.

See how it works