What is a Blocklist?

How DNS Blocklists Prevent Access to Unwanted Content

A blocklist is a list of domains that a DNS filter denies resolution for, preventing users from accessing those sites. Blocklists are the foundation of DNS-based content filtering.

Explore Free DNS Filters

Step 1: What is a Blocklist?

A blocklist (also called a denylist or blacklist) is a curated list of domain names that a DNS filter refuses to resolve. When a user tries to visit a blocked domain, the resolver returns an NXDOMAIN response or redirects to a block page.

Blocklists are the opposite of allowlists — where allowlists define what's explicitly permitted, blocklists define what's explicitly denied.

Modern DNS filtering services maintain blocklists containing millions of domains, organized into categories like adult content, malware, phishing, gambling, and social media.

Step 2: How Blocklists Are Built and Maintained

Building accurate blocklists requires continuous analysis of the internet's domain landscape:

  • Automated crawling: Bots scan websites and classify content based on text, images, and behavioral patterns
  • Threat intelligence feeds: Security researchers share lists of known malware, phishing, and botnet domains
  • Machine learning: CleanBrowsing's Categorify engine uses AI to classify domains into 26+ content categories
  • Community reporting: Users report miscategorized or newly malicious domains for review
  • Continuous updates: New domains are registered daily — blocklists must be updated in real time to remain effective

Step 3: Types of Blocklists

DNS blocklists fall into two main categories:

  • Security blocklists: Domains associated with malware distribution, phishing, ransomware command-and-control servers, and botnets. CleanBrowsing's free Security Filter uses these
  • Content blocklists: Domains categorized by content type — adult, gambling, social media, streaming, etc. These are used for parental controls, workplace policies, and CIPA compliance

Organizations can also maintain custom blocklists to block specific domains unique to their needs, managed through the CleanBrowsing dashboard or API.

Step 4: Managing Blocklists with CleanBrowsing

CleanBrowsing combines curated blocklists with Categorify to deliver real-time filtering across 26+ categories. Paid plans allow you to customize which categories are blocked per profile, add custom blocked domains, and manage everything via the API.

For organizations running their own DNS infrastructure, CleanBrowsing also offers an RPZ feed that integrates directly with your resolvers. On the authoritative DNS side, NOC.org manages DNS records and zones — while CleanBrowsing's recursive resolver enforces access controls.

Start filtering with curated blocklists

Explore Free DNS Filters