Web Filtering
Overview
KidMoat's web filtering protects your child from inappropriate content across all browsers on their device. Filtering works through a local VPN service — no traffic leaves the device for processing.
Content Filter Levels
Choose a filter strength based on your child's age and maturity:
| Level | Blocks | Best For |
|---|---|---|
| Strict | Adult content, violence, gambling, social media, dating, drugs | Ages 6-9 |
| Moderate | Adult content, violence, gambling, drugs | Ages 10-13 |
| Light | Adult content only | Ages 14+ |
It Holds Up Against The Usual Workarounds
Filtering happens at the DNS level, so it applies in every browser on the device rather than only the one you set up. Two common ways around a DNS filter are handled deliberately:
- DNS-over-HTTPS (DoH): Chrome and Firefox can send DNS queries over HTTPS to their own providers, which would route straight past a local filter. KidMoat sinkholes the public DoH provider domains, so the browser falls back to the system resolver — which the filter sees.
- DNS-over-TLS (DoT): connections on port 853 are refused, so the device falls back the same way.
A child who changes their DNS settings or turns on a browser's secure-DNS option does not get around the filter.
What this is not: KidMoat does not force SafeSearch or YouTube Restricted Mode. A blocked site is blocked outright; a permitted search engine returns its normal results. If you want Google or YouTube filtered at the results level, set that on the account itself — it is not something KidMoat does for you.
Custom Block and Allow Lists
Fine-tune the filter with your own rules:
Block List
Add specific websites or domains that should always be blocked, even if they pass the category filter:
- Enter the domain (e.g.,
example.com) - Blocks all pages on that domain
- Useful for specific sites you've identified as problematic
Allow List
Add websites that should always be accessible, even if the category filter would block them:
- Enter the domain (e.g.,
khanacademy.org) - Overrides the category filter for that domain
- Useful for educational sites that might be caught by strict filtering
How It Works
- The child device runs a local VPN service (no internet traffic is routed externally)
- DNS requests are intercepted and checked against the filter rules
- Blocked requests show a friendly "This site is blocked" page
- All browsing activity is logged and visible to the parent
The VPN-based filter works across all browsers and apps that make web requests. It does not decrypt HTTPS traffic — filtering is done at the DNS level for privacy.