Parental Controls Explained: Windows, Browsers, Routers, DNS, and HOSTS
Quick Answer Parental controls are settings and tools that help parents manage what children can access, which applications they can use, and when they can u...
Quick Answer
Parental controls are settings and tools that help parents manage what children can access, which applications they can use, and when they can use their devices. Online child protection is broader: it also includes privacy settings, safe communication, age-appropriate services, and teaching children how to respond to harmful content or suspicious contact.
For a Windows computer, a practical starting point is a separate standard user account, Microsoft Family Safety, and appropriate browser restrictions. Add router filtering or family DNS to cover compatible devices on the home network. Use third-party software when you need additional browser or device coverage. A HOSTS file can block a few specific hostnames, but it is not a complete parental-control system.
How Parental Controls Work
Different controls act at different points. Combining them helps address gaps that a single setting cannot cover.
| Control | What it does | Main limitation |
|---|---|---|
| Device and account controls | Apply restrictions to a child’s account, applications, or device usage. | Coverage depends on the operating system, account, and permissions. |
| Browser controls | Filter websites or restrict browsing within a supported browser or supervised profile. | Other browsers or unmanaged profiles may fall outside the controls. |
| Search filtering | Reduce explicit results from a particular search service. | Does not prevent direct access to every unsuitable website. |
| Router controls | Apply network schedules, device rules, or website restrictions. | Only affect traffic passing through that router. |
| DNS filtering | Block domain-name lookups associated with selected categories. | Cannot reliably distinguish individual pages or posts on the same domain. |
| HOSTS entries | Override name resolution for specified hostnames on one computer. | Require manual maintenance and provide no category filtering or time limits. |
DNS, the Domain Name System, translates names such as a website’s hostname into network addresses. A filtering DNS service can refuse or alter the answer for a blocked domain. It does not need to decrypt the website’s content to perform this domain-level filtering.
Before You Begin
- List the devices, browsers, applications, and networks the child uses.
- Decide whether the goal is content filtering, screen-time management, purchase approval, communication restrictions, or a combination.
- Keep a separate parent administrator account and protect its password and recovery methods.
- Explain the rules and any activity reporting to the child in age-appropriate language.
- Record existing router and DNS settings before changing them.
- Keep school websites, accessibility tools, and necessary communication services available.
- Use supported operating systems and current browser versions.
1. Set Up Parental Controls on Windows
Create and connect the child’s account
Microsoft Family Safety uses a family group with an adult organizer and family members. Device connection and the correct child account are essential for restrictions to apply. Microsoft recommends that the child’s Windows account be a standard user; family features may not work properly when the child is an administrator. :chatgpt-content-reference{index="0"}
- Sign in to Microsoft Family Safety using the parent’s Microsoft account.
- Create the family group if necessary and add the child’s Microsoft account. Complete any required invitation or parental-consent steps.
- On the child’s Windows PC, open Settings > Accounts. Locate the family or other-user settings; wording varies by Windows version.
- Add or allow the child’s account on the computer.
- Confirm that the child has a standard account while the parent retains a working administrator account.
- Sign in to Windows with the child’s account while connected to the internet. Confirm that the PC appears among the child’s connected devices.
Configure screen time and applications
In the Family Safety dashboard, select the child and the Windows device or platform. Enable screen-time limits, then set the allowed hours and daily allowance. These are separate settings: a permitted time window controls when the device can be used, while an allowance controls how long. :chatgpt-content-reference{index="1"}
Review app and game restrictions separately. Block unsuitable applications and configure supported age restrictions. Website filtering alone does not control every installed application. :chatgpt-content-reference{index="2"}
Enable website filtering in Microsoft Edge
- Select the child in Family Safety and open the Edge or web-and-search settings.
- Enable Filter inappropriate websites and searches.
- Add specific allowed or blocked websites.
- For a more restricted browsing setup, consider Only use allowed websites, then add the sites the child needs.
- Make sure the child uses Edge while signed in with the supervised Microsoft account.
Microsoft currently documents Edge as the supported browser for its web filtering. Unsupported browsers may be blocked when filtering is enabled; manually allowing another browser does not extend Edge’s filtering to it. :chatgpt-content-reference{index="3"}
Verify: From the child’s account, temporarily block a harmless website and confirm that access is denied. Confirm that a required school website works. Test a short screen-time limit when no important work is open.
Undo: Remove the temporary website rule or restore the previous schedule from the parent dashboard. Troubleshoot individual restrictions before removing the child from the family group.
2. Configure Browser and Search Controls
Google Chrome and Family Link
Google Family Link can manage website restrictions for a child signed in to Chrome with a supervised Google Account.
- Open Family Link and select the child.
- Open Controls > Google Chrome and Web.
- Select the appropriate setting: allow sites with exceptions, try to block explicit sites, or allow only approved sites.
- Add specific approved or blocked sites under the site-management settings.
Windows limitation: Google states that children using Windows, macOS, or Linux can sign out of Chrome, switch profiles, or use another browser where these Chrome restrictions do not apply. Family Link’s Chrome controls therefore do not provide complete Windows device supervision. Incognito is disabled within the supervised Chrome session, but that does not secure other profiles.
Verify: Test a harmless blocked site in the supervised profile, then check whether other available profiles or browsers remain unrestricted. Remove the test rule afterward. :chatgpt-content-reference{index="4"}
Google SafeSearch
Set SafeSearch to Filter when the goal is filtering explicit Google Search results. The Blur option can still show explicit text and links. Use the parent-managed setting where available, and check whether the setting is locked.
SafeSearch affects Google Search; it does not filter every website, other search engines, or content inside unrelated applications. :chatgpt-content-reference{index="5"}
Browser extensions
A website-blocking extension can help with a small list of sites or distractions. Before relying on it, check whether the child can remove it, disable it, switch profiles, or use another browser. Review its permissions and privacy policy, particularly if it requests access to browsing activity.
Private browsing and malware protection should not be treated as substitutes for parental controls.
3. Configure Parental Controls on the Router
A router can provide useful household coverage for computers, tablets, consoles, and televisions. Depending on the model, it may support website categories, individual blocks, child profiles, or internet schedules.
Router-only protection has limits: it does not control offline computer use, and it does not follow a device onto mobile data, a hotspot, or another Wi-Fi network.
General setup procedure
- Identify the router’s exact model and hardware version.
- Open its official management application or documented local administration address.
- Sign in with the router administrator account and record the current settings.
- Locate Parental Controls, Family, or the equivalent section.
- Create a child profile and assign the correct devices.
- Apply the available website rules and schedules, then save.
For example, TP-Link documents a Tether workflow for supported HomeShield/HomeCare routers using the Family tab, profile creation, device assignment, and content or time controls. Features vary by model, and some advanced options require a subscription. :chatgpt-content-reference{index="6"}
Verify: Check an assigned device and an unassigned parent device separately. Confirm that the intended restriction applies only where expected. Check the router’s time zone before testing schedules.
Device identification: A changing private or randomized MAC address can affect rules tied to a device address. Follow the router vendor’s guidance; if necessary, use a stable address specifically for the trusted home network. Avoid disabling privacy features indiscriminately on public networks. :chatgpt-content-reference{index="7"}
Undo: Disable the affected profile or remove its rule. Restore recorded settings if necessary; a factory reset should not be the first troubleshooting step.
4. Use Family DNS Filtering
Family DNS is useful when the router lacks content categories or when you want an additional domain-filtering layer.
Example: Cloudflare 1.1.1.1 for Families
For Cloudflare’s malware and adult-content filtering, use the following resolver addresses:
| Protocol | First resolver | Second resolver |
|---|---|---|
| IPv4 | 1.1.1.3 | 1.0.0.3 |
| IPv6 | 2606:4700:4700::1113 | 2606:4700:4700::1003 |
These differ from Cloudflare’s ordinary unfiltered resolvers and its malware-only service. For compatible encrypted-DNS clients, the family DNS-over-HTTPS endpoint is:
https://family.cloudflare-dns.com/dns-query
For a compatible DNS-over-TLS client, the hostname is:
family.cloudflare-dns.com
These values are configuration entries, not shell commands. :chatgpt-content-reference{index="8"}
Apply the settings to the router
- Open the router’s DNS settings. Depending on the model, these may be under Internet, WAN, LAN/DHCP, or IPv6.
- Enter both filtered IPv4 resolvers.
- If IPv6 is enabled, configure the filtered IPv6 resolvers as supported by the router.
- Check whether the router forwards DNS itself or distributes DNS addresses to clients through DHCP, the service that automatically supplies network settings.
- Save the settings and reconnect a test device so it receives updated network information.
The required menu and whether WAN and LAN settings must both change depend on the router. Follow its manual. :chatgpt-content-reference{index="9"}
Do not mix a filtered resolver with an unfiltered alternate. Clients may use either server, so the unfiltered address can undermine the intended policy.
Verify filtering safely
Use Cloudflare’s documented test addresses rather than visiting real harmful websites:
With the corresponding filter active, the test site should be inaccessible. A DNS or connection error can be the expected outcome; a branded block page is not required. Also confirm that ordinary websites load. :chatgpt-content-reference{index="10"}
Test every browser used by the child. A browser’s custom secure-DNS provider, a VPN, a proxy, or manually assigned DNS can take traffic outside the intended filtering path.
Keep encrypted DNS aligned with the policy
DNS over HTTPS and DNS over TLS encrypt DNS traffic. Encryption is compatible with parental filtering when the selected resolver applies the intended restrictions. Where supported, configure the filtered encrypted endpoint instead of assuming that all secure DNS must be disabled.
Advanced routers may restrict external DNS traffic, but blocking traditional DNS alone does not control all HTTPS-based DNS or VPN traffic. Use supported router and endpoint policies for stronger enforcement; avoid blocking broad categories of encrypted traffic without understanding the impact.
Undo: Restore the original DNS addresses or automatic DNS mode, reconnect affected clients, and repeat normal browsing tests.
5. Optional PowerShell Configuration for One Windows PC
The following example changes DNS for one selected network adapter. It does not create screen-time limits, enforce browser policies, or configure the router.
Environment: Windows 11, Windows PowerShell. Open PowerShell using Run as administrator for the configuration and rollback steps.
Inspect the adapters
Get-DnsClientServerAddress
This read-only command lists interface names, interface indexes, address families, and configured DNS servers. Identify the active Wi-Fi or Ethernet adapter and save its current information. :chatgpt-content-reference{index="11"}
Apply the family resolvers
Enter the verified interface index when prompted. Run the IPv6 portion only if IPv6 is enabled on that adapter.
[uint32]$interfaceIndex = Read-Host "Enter the verified interface index"
Get-DnsClientServerAddress -InterfaceIndex $interfaceIndex -AddressFamily IPv4 |
Set-DnsClientServerAddress -ServerAddresses @("1.1.1.3", "1.0.0.3") -ErrorAction Stop
Get-DnsClientServerAddress -InterfaceIndex $interfaceIndex -AddressFamily IPv6 |
Set-DnsClientServerAddress -ServerAddresses @("2606:4700:4700::1113", "2606:4700:4700::1003") -ErrorAction Stop
Get-DnsClientServerAddress -InterfaceIndex $interfaceIndex
The interface index selects the adapter. The address-family filter separates IPv4 and IPv6 settings. Setting explicit resolver addresses overrides automatically supplied DNS for the affected configuration. :chatgpt-content-reference{index="12"}
Confirm that the final output contains the intended addresses. If a step fails, inspect the resulting settings before continuing because an earlier step may already have succeeded.
Clear Windows’ cached DNS answers, then close and reopen the browser:
ipconfig /flushdns
This clears the Windows DNS resolver cache; it does not configure filtering or clear every application’s separate cache. Repeat the safe DNS tests above. :chatgpt-content-reference{index="13"}
Roll back the adapter change
If both address families previously used automatic DNS, run the following in the same elevated PowerShell session:
Set-DnsClientServerAddress -InterfaceIndex $interfaceIndex -ResetServerAddresses
ipconfig /flushdns
If either family previously used manual DNS, restore its recorded addresses instead of applying a blanket reset. In a new PowerShell session, identify and set the correct interface index again before running rollback commands. :chatgpt-content-reference{index="14"}
Check other adapters separately. Configuring Wi-Fi does not automatically configure Ethernet, VPN adapters, or an application’s independent DNS resolver.
6. Block Specific Hostnames with the Windows HOSTS File
The HOSTS file maps hostnames to addresses locally. Its usual location is C:\Windows\System32\drivers\etc\hosts; the Windows installation directory can differ. It has no filename extension. :chatgpt-content-reference{index="15"}
- Copy the existing HOSTS file to a safe backup location.
- Open Notepad as administrator.
- Open the HOSTS file, selecting All files if necessary.
- Add the following demonstration entries:
# Temporary website-blocking test
0.0.0.0 example.com
0.0.0.0 www.example.com
Save the file without adding .txt. Clear the Windows DNS cache using the earlier command and reopen the browser.
Verify: The listed hostnames should fail to open in a browser that uses Windows name resolution. If they still load, check the saved filename, cached connections, and whether the application resolves names through a different path.
Undo: Remove only the added test lines, save, flush the DNS cache, and reopen the browser. Restore the backup only if it will not overwrite other legitimate changes.
HOSTS-file limitations
- Entries match hostnames, not entire categories.
- Blocking a domain does not automatically block every subdomain.
- Wildcard entries and URL paths are not supported.
- There are no schedules, age ratings, purchase approvals, or activity reports.
- A user with administrator access can change the file.
- Applications using independent resolution or proxy services may not follow the local mapping.
Use HOSTS entries for a small supplementary block list. Large downloaded lists need maintenance and can block shared services used by legitimate applications.
7. Third-Party Options
| Option | Useful capability | What to check |
|---|---|---|
| Qustodio | Installed parental-control software with website reporting and blocking. Its documented Windows browser support includes Chrome, Firefox, and Edge. | Current system requirements, subscription features, required permissions, and supported browsers. Qustodio does not support Linux. |
| NextDNS | Configurable DNS filtering with category controls, SafeSearch enforcement, and scheduled access options. | Correct profile deployment, current plan limits, logging preferences, and whether every intended device uses the profile. |
Qustodio requires its child-device software for protection; its parent dashboard alone does not protect the child’s PC. NextDNS operates at the DNS layer, so its service-access schedules should not be confused with measuring and limiting total device screen time. :chatgpt-content-reference{index="16"}
Before committing to a product, test the functions you need on the actual device and browser. Review how it handles installation permissions, uninstall protection, false positives, activity retention, and access away from home. Features and licensing can differ by platform and plan.
Rollback: Use the vendor’s documented removal process. Restore any DNS, browser, or network settings changed during installation, then confirm normal connectivity.
8. Additional Protection Options
- iPhone and iPad: Use Apple’s family and parental-control settings for supported app, website, time, and privacy restrictions. Available controls depend on the device, software, age, and region. :chatgpt-content-reference{index="17"}
- Individual applications: Review the child settings inside video services, games, consoles, messaging tools, and social platforms. Network filtering cannot replace account-specific privacy or communication settings.
- ISP filtering: Check whether the internet provider offers a household content filter and confirm its scope before relying on it.
- Separate child network: Where supported, a dedicated Wi-Fi network can simplify applying different DNS and access policies. Verify that the router actually supports separate policies for that network.
- Shared spaces and regular conversations: Explain how to report upsetting content, unwanted contact, scams, and requests for personal information.
Troubleshooting Parental Controls
| Problem | What to check | Next action |
|---|---|---|
| A blocked website still opens | Account, browser profile, exact hostname, DNS settings, VPN or proxy, and cached connections. | Identify which control should block it. Test that control with a harmless site and verify its scope. |
| Filtering works in only one browser | Supported-browser requirements and browser-specific secure DNS. | Align browser settings with the intended policy or use compatible endpoint filtering. |
| Home Wi-Fi is filtered but mobile data is not | Whether filtering exists only on the home router. | Configure suitable device-level protection and test it away from home. |
| Only some home devices are filtered | Profile assignments, guest networks, manual DNS, IPv6 DNS, and changing device addresses. | Correct the affected device’s assignment or resolver configuration. |
| All websites stop loading after a change | DNS typing errors and resolver reachability. | Restore the recorded DNS settings, reconnect, and test ordinary browsing. |
| A school website is blocked | Which product or layer is blocking it and whether additional service domains are involved. | Add a narrow exception where supported or request recategorization. |
| Screen-time limits do not apply | The child’s Windows account, connected device, selected schedule, and administrator status. | Correct the account or device setup and retest a short limit. |
| HOSTS changes have no effect | File extension, exact hostname, saved contents, and application resolution behavior. | Correct the file and retest after clearing caches and restarting the application. |
Change one setting at a time. Record the result so you can identify the effective control and undo changes that do not help.
Frequently Asked Questions
Can parental controls read every private message?
No. Website or DNS filtering does not provide access to every message’s contents. Monitoring capabilities depend on the application, operating system, permissions, and product. Check the specific feature documentation and explain any monitoring to the child.
Can different children have different restrictions on the same PC?
Use a separate supervised Windows account for each child. A router generally identifies the device rather than the person currently using it, so one router profile cannot reliably distinguish siblings sharing a computer.
Do parental controls replace antivirus protection?
No. Content restrictions and malware protection address different problems. Keep operating-system security, application updates, and appropriate malware protection enabled.
Can a filter block one unsuitable video while allowing the rest of a website?
DNS and HOSTS blocking cannot reliably make that distinction when videos share the same domain. Use the platform’s own age, content, or supervised-account controls where available.
What should happen when a child needs an exception?
Provide a clear approval process. Check the requested site or application, grant the narrowest useful exception, and review temporary permissions afterward. Avoid sharing the parent administrator password to resolve a single block.
Sources
- Microsoft Support: Set up Microsoft Family Safety, Connect a device, and Set screen-time limits.
- Microsoft Support: Filter websites and searches and Block or unblock applications.
- Google Help: Chrome and your child’s Google Account and SafeSearch settings and limitations.
- TP-Link: Router parental controls through Tether and HomeShield plans and subscriptions.
- Cloudflare: Family DNS addresses, encrypted endpoints, and test sites and Router DNS configuration.
- Microsoft Learn: Get-DnsClientServerAddress, Set-DnsClientServerAddress, and ipconfig.
- Microsoft Support: Windows HOSTS file format and recovery.
- Vendor documentation: Qustodio supported platforms and browsers, NextDNS features, and Apple parental controls for iPhone and iPad.
Was this guide useful?
Your answer helps us keep BISONKB accurate and practical.