Handing a child a tablet or a phone raises an immediate question for most parents: how much of what happens on it can you actually control from the home network? Marketing around routers and filtering apps suggests you can supervise almost everything from one screen. The reality is more mixed. Some controls are genuinely useful, some are trivially sidestepped, and a few offer mainly a false sense of safety. This guide sets out what network-level filtering does, what device-level controls add, and where both quietly stop working, so you can pick a setup that fits your household rather than a wishlist.
Two places a control can live
Every parental control sits in one of two places. Network controls run on the router, the box every device connects through, so a single rule can reach every phone, console and laptop in the house at once. Device controls run on the gadget itself, through tools such as Apple Screen Time, Google Family Link or Microsoft Family Safety, and they travel with the device when it leaves your wifi.
The trade-off is real. A router rule is set once and covers newcomers automatically, but it is coarse and blind to what happens inside an app. A device rule can see individual apps, screen time and content ratings because it works from inside the operating system, yet it must be installed on each gadget and can be undone by a child who knows the passcode. The router also decides which wifi generation each device uses, the ground the explainer on how wifi standards differ lays out.
DNS-based filtering
Most router-level and third-party filters work through DNS, the system that turns a name such as example.com into a numeric address. When a device wants a site, it first asks a resolver for that address. A filtering resolver checks the name against category lists and simply refuses to answer for anything flagged as adult, gambling or malware, so the page never loads. Services like this are cheap or free, apply to the whole network, and need no software on the child’s device.
The method has clear edges. It blocks whole domains, not parts of them, so it cannot hide one video on a site you otherwise allow. It also depends on the device using your chosen resolver. A phone set to a different DNS server, or one that quietly sends lookups over an encrypted channel, walks straight past the filter. Every extra lookup also adds a small delay before a page starts, the kind of latency the guide on what ping and jitter measure explains.
How the options compare
Set side by side, the three main approaches trade coverage against precision, and each fails in a different way once a child pushes back.
| Approach | Where it runs | Best at | Main weakness |
|---|---|---|---|
| Router controls | The router | Covering every device at once | Blind inside encrypted apps |
| Device controls | The phone or tablet | App limits that follow the child | Installed and locked per device |
| DNS filtering | A chosen resolver | Blocking whole categories cheaply | Bypassed by other or encrypted DNS |
| Time schedules | Router or device account | Enforcing offline hours | Second devices and mobile data |
Time limits and schedules
Cutting access by the clock is often more effective than blocking content. Most modern routers let you group devices and pause their internet on a schedule, so a child’s tablet goes offline at bedtime while the rest of the house stays connected. Because the rule targets the device rather than a website, it does not care what the child is trying to reach; the connection simply stops.
Schedules are still coarse. They act per device, so a determined child with a second gadget, or one who switches to mobile data, keeps going. Rules that follow the child rather than the hardware, set through a device-level account, hold up better here. Grouping matters too, because a single profile can span both radio bands, the split the guide on choosing between wifi bands covers.
What encryption hides from a filter
A decade ago a network filter could read the full web address and even page text, because traffic travelled in the clear. Almost all traffic is now encrypted with HTTPS. The router can still see the domain a device connects to, but not the specific page, the search terms or anything typed into a form. Keyword filtering on the network, the sort that promises to block rude words anywhere, barely functions as a result.
Encrypted DNS goes a step further. When a browser sends its name lookups over HTTPS, the router no longer sees even the domain, so DNS filtering on your own equipment is bypassed unless you specifically block that feature. This is why serious setups pair a filtering resolver with a rule that forces every device to use it and shuts off the encrypted alternatives.
The limits every filter shares
No filter understands context. It cannot tell homework research about drugs from a child seeking them, and it cannot read tone in a chat. Category lists overblock useful pages and underblock new ones, and they lag behind sites that move or rename. Treating any filter as a substitute for conversation tends to end badly, because the tool blocks pages while the questions behind them stay unanswered.
Bypasses are the other constant. A VPN tunnels every request past your resolver, mobile data skips the home network entirely, and a borrowed login opens doors you closed. Putting younger children’s gadgets on their own restricted network, kept apart from the main one, limits the damage, an approach the guide on how guest networks keep devices apart describes.
Choosing a setup that holds
For a young child with one device, a device-level account such as Screen Time or Family Link usually does more than any router rule, because it limits apps and follows the tablet to a friend’s house. Add a filtering resolver on the router as a second layer for the whole home, and set offline hours for the bedtime problem. That combination covers the common cases without pretending to be watertight.
For teenagers, accept that motivated bypassing will win, and lean on transparency instead. Agreed schedules, shared family accounts and open discussion outlast technical blocks that a curious mind unpicks in an afternoon. The network layer is a guardrail, useful for nudging behaviour and catching accidents, not a wall. Reading its limits honestly is what stops it from becoming a false comfort that no one is really watching.
Frequently asked questions
How do I set up parental controls on my router?
Sign in to the router’s admin page or companion app, usually reached through an address printed on the router or the maker’s own app. Look for a section named parental controls, family or access. From there you can create a profile per child, assign their devices, set offline schedules and, on many models, pick a filtering DNS service. Save the profile, then test from the child’s device that a blocked category actually fails to load.
Can I block websites on my whole network?
Yes, at the domain level. A filtering DNS service or a router blocklist stops every device on the network from resolving named sites or whole categories, with no software on each gadget. It cannot block part of a site or read inside encrypted pages, and it fails if a device uses its own DNS or an encrypted lookup. Forcing all devices onto your resolver closes most of those gaps.
Do parental controls actually work?
They work as a layer, not a guarantee. For younger children with a single device, app limits and schedules genuinely shape usage. For older children, VPNs, mobile data and spare gadgets defeat most network blocks, so the value shifts toward agreed rules and conversation. Used honestly, controls catch accidents and enforce bedtimes; treated as total protection, they give parents a confidence the technology cannot actually earn.
