July 2026 · 5 min
I run a small DNS filter for ads and malware, and the first week broke three things: a bank app, a game launcher, and my doorbell. The lesson: start in monitor-only mode and allowlist before you blocklist.
My steady setup is two lists (one ads, one malware), client names per device so I can see who asks what, and a one-tap bypass SSID for guests. Complaints dropped to zero, blocked queries sit near eleven percent, and nobody in the house knows it exists — which is the whole point.