Discussions

Ask a Question

Request: Add Control D macOS GUI Setup Utility to Homebrew Casks

The title says it all. This would be especially useful to handle upgrades, since the GUI tool does not have an auto-update feature.

Can you add a 3rd filter party?

Hello.
Greetings.
Would it be possible to add a third-party gambling blocklist?
Specifically this one:

Feature Request: Per-Rule Block Response Override in Custom Rules

Problem:
The Block Response setting is currently global to the Profile. This creates issues when different blocked endpoints require different handling—such as returning ⁠NXDOMAIN⁠ to prevent socket timeouts on specific services, or sinkholing a domain to an internal IP (block page) without forcing that behavior across the entire Profile.

Add filter category for guns/violence

Would be great for schools and younger children.

Feature Request: [CTRLD] Allow Overriding "LAN queries will be handled solely by the OS resolver" Behavior

It would be nice if there was a flag/etc to override this behavior and specify a specific upstream for LAN Queries (specifically, bare host queries without a domain - e.g. machine1, machines2). For my use case, all bare queries should go to dnsmasq on a router listening on port 53053. CTRLD lives in a docker container on a separate VM, and all clients point to that address:53.

Add DFBPlay.tv as Video Service

DFBPlay.tv streams the matches of the DFB Pokal for free in foreign countries outside of Germany like UK. I implemented the needed rules successfully as my custom rule i want to share.

Integration with Apple iOS Shortcuts

I find myself needing to temporarily disable the active endpoint to perform an action which may otherwise be blocked.

Live Microsoft FTP

I am writing because it is not possible to log in to access files on Live Microsoft FTP because two domains that would allow logging in are blocked and not even enabled in Services...

Answered

ControlD leaks to Datacamp and Barry lies

For few weeks now I noted Datacamp DNS server on leak test which fails, it comes and goes. DNS rebind test pass.
Barry said first time - ‘Australia Datacamp IP addresses on the DNS leak test when Control D is enabled is normal. This just means your DNS queries are being handled by Control D’s Sydney servers’

But 2 days later Barry says – ‘ This IP doesn't belong to Control D's network. It could be a server from your ISP or another DNS provider configured on your device or router.’

So it is ether ControlD leak test false negative or Barry lies or both.

anyone else noted Datacamp ?

Ability to Place Profiles in Monitoring Mode While Enabling Full Analytics

Currently, when a Control D profile is used in a "monitoring mode" (where traffic is fully allowed), the analytics dashboard only displays the raw domains visited. While explicitly adding Native Services in "Bypass/Allow" mode maps service names to the analytics logs, this metadata is entirely missing for native Web Filtering Categories.I would like to request that Web Filtering Categories also be mapped and displayed within profile analytics when running a passive monitoring policy. This could be achieved by introducing an explicit "Allow/Monitor" action state directly within the Native Categories settings, or by creating a dedicated global "Monitoring Mode" switch at the profile level.
Secondary Benefit: Introducing an explicit "Allow" action for Native Categories would also provide helpful, granular override capabilities for administrators utilizing a strict, block-by-default profile posture.