Skip to content
Tabaa

Why are DNS filtering and VPN blocking not enough to stop porn?

Published 27 August 2026 - last updated 27 August 2026

Because DNS only refuses site names, and it hangs on a network or on a setting the person holding the device can change. Switching from Wi-Fi to mobile data, editing Private DNS, a browser with encrypted DNS built in, or any VPN gets past it in minutes. It stops no app from opening and never reaches inside a second space. Tabaa pins the filtering into the device's own system with Device Owner privilege, and locks the setting.

What does DNS filtering actually do?

DNS is the internet's address book: when you type the name of a site, your device asks a DNS server for its numeric address. Filtering by DNS means that server refuses to translate the names of pornographic sites, so the site does not open. That is real and it works, but notice the limits the companies themselves publish. CleanBrowsing describes its product as DNS filtering that secures your network. OpenDNS puts installation on the router forward as its recommended option. And NextDNS says all of this happens at the DNS level, not on your device. That last sentence is the whole subject: the protection is tied to a network or to a setting, not to the device.

How does DNS filtering get bypassed in minutes?

  • Mobile data instead of Wi-Fi. Blocking on the router ends at the front door: the Wi-Fi goes off, the SIM takes over, and all the filtering is gone without anyone having changed a single setting.
  • Changing the Private DNS setting. It sits in Android's own settings for anyone to open and type in a different server, after which the device asks an unfiltered resolver on any network at all.
  • A browser with encrypted DNS built in (DNS over HTTPS). The browser makes its own lookups over port 443 without ever passing through the server the router filters, so the block never sees them.
  • Any VPN app. All the device's traffic runs through an encrypted tunnel, and the router and the local DNS see nothing.
  • And above all of that: DNS blocks names, not apps. An app installed on the device still opens, there is no time limit, and there is no control at all over when the device itself may be used.

Not one of these steps needs technical skill. They all come up in the first page of search results, and any teenager or adult with a motive will find them in minutes.

The gap nobody talks about: second spaces and accounts

This is the most dangerous point in the whole subject, and it is written down in the companies' own documentation. Second space, a cloned profile and guest mode are all, underneath, additional users in Android, and Android's own documentation says that one user cannot reach another user's app data. Which means the app installed on your side does not exist at all in the new space, and therefore blocks nothing in it:

  • Google documents explicitly that a child's Family Link settings do not apply to any other user profile you add on the same device, and it advises the parent to put a lock on that other profile himself.
  • Qustodio says in its help center that Android's multi-user feature and guest mode can be used to bypass its protection, and asks the parent to switch that feature off by hand in Android's settings.
  • And in Tabaa: adding a new user, switching users and removing them are locked by default, the work profile is locked on every supported version, and cloned profiles and private space are locked by the Android 15 and newer restrictions. There is no room on the phone that slips out of the policy.

The same story goes for accounts: Tabaa's protection is bound to the device rather than to an account, so you can add or switch Google accounts as you like without anything in the protection changing, and Tabaa does not touch accounts in the first place. The full comparison is in Tabaa or Google Family Link.

And blocking content inside the apps themselves?

Most content today does not open in a browser: it opens in a miniature browser embedded inside the app (a WebView), or in a video player inside a game or a chat app. And this is exactly where the differences show. Google confines Family Link's filtering to Google's own apps - Search, Chrome and YouTube - and says in as many words that Family Link does not block inappropriate content but rather offers filtering options, that those filters are not perfect and explicit content sometimes gets through, and that the child may have other browsers to which Chrome's settings will not apply.

In Tabaa the filtering does not belong to an app: the Private DNS setting is pinned in the device's system to the filtered Tabaa server over DNS over TLS, the setting is locked so it is not available for the phone holder to change, and it is re-asserted every 3 seconds. The result is that every DNS query on the device passes through the filter: the browser, the browser embedded inside any app, and the apps running in the background. Nothing has to deal with Tabaa in order to be filtered, and there is a fixed floor of 118 domains that no supervisor is permitted to lift.

What about blockers that run as a local VPN or on an Accessibility service?

That is a second category of solution, apps such as BlockerX among them, filtering through a local VPN on the device. BlockerX states in its Google Play description that it uses VpnService, the Accessibility service and the draw-over-other-apps permission. That is a better step than filtering at the router, because it sees all of the device's traffic, but the fundamental problem is still there: the owner of the device is the one who installed the app. The FAQ on BlockerX's own site walks through the removal path step by step (settings, then privacy and security, then device administrators, then turn the privilege off and delete), and its Play listing says what happens on deletion is a notification sent to the accountability partner. Notice after the event, not prevention. The detailed comparison is in Tabaa or BlockerX.

And there is a second cost to the Accessibility service that goes unmentioned: that permission lets an app read everything on your screen, which is why some banking and payment apps limit what they do, or refuse to run, when another app on the phone is holding it. InstaPay and the National Bank of Egypt app have published updates that talk about the app behaving differently on devices where advanced system permissions have been granted. Tabaa does not ask for the Accessibility service at all, nor for a notification-reader service, it installs no VPN on the phone, and it asks for no camera, no microphone, no SMS, no contacts and no files.

What does protection that really closes these gaps look like?

The principle is simple: the protection has to be carried out in the operating system itself, and its key has to be outside the user's hands. That is what Tabaa does with Device Owner privilege: the disallowed app is suspended by the system itself, not by an app sitting there looking at the screen. Which is why the block holds on any launcher, for any user on the phone, on Wi-Fi and on mobile data, and with any SIM. A disallowed app closes within about a third of a second of being opened, any change the supervisor makes reaches the phone within about 3 seconds, and on top of that 47 VPN, proxy, Tor and DNS-changer packages are blocked in every mode and suspended even when they were preinstalled, while the default list of blocked apps holds 32 apps, 11 of them unofficial forks of Telegram, because blocking the official app means nothing if the modified one gets through. And on the computer, Tabaa for Windows blocks at the firewall any DNS query outside the Tabaa server, which is what closes the question of encrypted DNS inside the browser, and Android emulators with it.

Bypass methodDNS filtering alone (router or NextDNS)An on-device blocker (local VPN or Accessibility service)Tabaa (Device Owner)
Switching from Wi-Fi to mobile dataBypasses router filtering entirelyNo: the app runs on the device, not on the networkNo: the filtering is in the device's system, working on both networks and with any SIM
Changing the Private DNS setting from settingsBypasses itDepends on the app and how it worksNo: the setting is pinned and locked, and re-checked every 3 seconds
A browser with encrypted DNS built inBypasses router filteringDepends on the appNo: a browser that is not allowed does not open at all
Running a VPN or DNS-changer appBypasses itThe user can stop the VPN connection himself from Android's settingsNo: 47 VPN, proxy, Tor and DNS-changer packages are blocked in every mode
A second space or an extra user on the same phoneNetwork filtering stays in place, but it is still only refusing namesThe app is not installed in the new space, so it blocks nothing thereNo: adding and switching users are locked, and the work profile is locked
A cloned profile or private space (Android 15 and newer)Outside its scopeOutside its scopeNo: both are locked by the Android 15 restrictions
Content inside a browser embedded in an app (WebView)Filtered only while the device is on that same networkDepends on the appFiltered: every DNS query on the device passes through the filter
Deleting the blocking tool itselfEasy: one setting changedPossible: turn off the device-administrator privilege in settings, then deleteNot possible for the phone holder: removal only by a factory reset with the supervisor's key
An Android emulator on the computerUsually outside its scopeOutside its scopeThe Windows default list holds 44 programs, 13 of them Android emulators

Does that mean DNS filtering is worthless?

No. As a cheap first layer for a whole house it is excellent, and Tabaa itself uses DNS filtering as one of its layers. The entire difference is in who is able to lift it: with the free solutions the user lifts it himself in a minute, and in Tabaa it is pinned with a privilege the person holding the device does not have, and its key is with a supervisor you choose and trust, as we explain in the guide on getting a friend to supervise your phone.

And because honesty matters more than slogans, here are the limits of our own DNS layer too. It needs Android 9 or newer, because the Private DNS setting does not exist in the system before that. An app carrying an encrypted DNS server inside its own code can route around it, which is exactly why the list of 47 packages and the lock on the VPN setting sit underneath it. And on Windows, if the filtering server itself has not answered for 30 seconds, the firewall deliberately relaxes so the machine is not left with no internet at all, and locks again the moment the server answers. We are not going to tell you that getting past it is impossible. We are going to tell you exactly what is locked, and how.

And if you are still comparing the solutions against each other, start from Arabic and foreign porn blockers compared or the guide to the best Arabic-language blocker for adults, and installation begins from the install page.

Common questions

So are NextDNS and router blocking a waste of time?
No. They are a cheap, fast first layer and they cover every device in the house. But these companies describe themselves precisely: the filtering is at DNS level, not at device level, and OpenDNS itself recommends installing on the router. Which means the protection ends at the edge of that network, and is bypassed by mobile data or by changing a single setting.
Does Tabaa not use DNS filtering itself?
It does, but pinned into the system rather than into an app: the Private DNS setting is pointed at the filtered Tabaa server over DNS over TLS, the setting itself is locked so the person holding the phone cannot change it, and it is re-asserted every 3 seconds. This filtering needs Android 9 or newer, because the Private DNS setting does not exist in the system before that.
Does the block hold if someone opens a second space or clones an app?
Adding a new user to the phone, switching between users and removing them are locked in Tabaa by default, and that is what covers the second space, because underneath it is an additional Android user. The work profile is locked on every supported version, and cloned profiles and private space are locked by the Android 15 and newer restrictions.
And what is the answer on the computer?
Tabaa for Windows filters DNS on three layers: browser policy, the DNS setting on every network adapter, and a rule in the Windows firewall that refuses any DNS query outside the Tabaa server. On top of that it blocks VPN and proxy programs. The default list holds 44 programs, 13 of them Android emulators, at 100 EGP a month.
What if the person just uses somebody else's device?
No system anywhere controls a device it is not installed on, and anyone who tells you otherwise is overselling. That is exactly why the accountability model, with a human supervisor the person trusts, matters more than any technology: the technology closes the gaps, and the human relationship carries the decision.