Advanced rules creation guide

Control D can be configured in a variety of different ways to allow for complex behaviors

Matching Order

When an Endpoint receives a DNS query, Control D applies the Profiles enforced on that Endpoint. If more than one Profile is enforced, their settings are combined into one policy before rule matching begins.

For Custom Rules, Services, Filters, and the Default Rule, priority runs from highest to lowest:

  1. Custom Rules: A matching enabled rule can Block, Bypass, or Redirect the domain. It takes priority over Service Rules, Filters, and the Default Rule.
  2. Service Rules: If no Custom Rule matches, a configured Service can Block, Bypass, or Redirect its domains. Service Rules take priority over Filters and the Default Rule.
  3. Filters: If neither a Custom Rule nor a Service Rule matches, enabled Filters can block the domain.
  4. Default Rule: If none of those matches, use the Default Rule: Bypass for normal DNS resolution, Block, or Redirect.

Geo Custom Rules, if configured, are evaluated after domain-based Custom Rules and before Service Rules.

A higher-priority rule wins because of where it matches, not because Block is stronger than Bypass or Redirect. For example, a Custom Rule set to Bypass takes priority over a Service Rule set to Block for the same domain.

This is the priority between these rule categories, not a list of every DNS-processing step. Profile Options, such as Block DNS Attacks and DNSSEC validation, can also affect a query or its response. Bypass should not be read as “disable every protection.”

Explicit Bypass versus Default Bypass

These are different:

  • A Custom Rule or Service Rule set to Bypass is an explicit match. It prevents lower-priority Service Rules or Filters from deciding the action for that domain.
  • A Default Rule set to Bypass is only the fallback for an otherwise unmatched query. It does not cancel Custom Rules, Service Rules, or Filters.

Turning a Service Rule off is also different from setting it to Bypass. With the rule off, the domain can still be blocked by a Filter or affected by the Default Rule.

When Custom Rules overlap

A plain domain rule applies to that domain and its subdomains. Among eligible plain domain rules, the most specific domain wins:

  • example.com set to Block blocks example.com and its subdomains.
  • Adding shop.example.com set to Bypass allows that subdomain while the parent rule still covers the rest.

Plain domain matches take priority over wildcard rules. For example, example.com set to Block takes priority over *.example.com set to Bypass for shop.example.com. Use the plain shop.example.com rule for that exception.

If only wildcard rules match, Control D compares their specificity. Avoid conflicting wildcard patterns with equal specificity rather than relying on the order they appear in the dashboard.

Only enabled, unexpired rules that apply to the query can match. See Custom Rules for supported rule syntax.

Multiple Enforced Profiles

Multiple Enforced Profiles follow the same category priority as a single Profile. Control D does not finish every rule in Profile 1 before starting Profile 2.

For example:

  • Profile 1 enables a Filter that blocks example.com.
  • Profile 2 has a Custom Rule that bypasses example.com.
  • The Custom Rule wins because Custom Rules take priority over Filters, even though it comes from Profile 2.

When two Profiles configure the same Custom Rule or Service, the earlier Profile normally supplies the action. This is different from two distinct domain rules, where domain specificity decides the match. Organization Global Profile overrides can replace an inherited setting; they do not rearrange the category order above.

Profile Options use the first enforced Profile that defines each option. An option missing from an earlier Profile can still be supplied by a later one.

Default Rules across Profiles

Normally, the first Default Rule set to Block or Redirect supplies the combined policy's fallback. A Default Rule set to Bypass does not prevent a later Profile from supplying that fallback. Explicit overrides can change which Default Rule is selected.

The combined Default Rule is still evaluated last. Setting Profile 1's Default Rule to Block or Redirect does not discard Profile 2's Custom Rules, Services, or Filters.

Common Examples

Redirect everything except selected domains

Set the Default Rule to Redirect, then set a Custom Rule or Service Rule to Bypass for traffic that should connect directly, such as a banking service or game.

The explicit Bypass rule wins over the Default Rule. Other domains use Redirect only if no higher-priority Custom Rule, Service Rule, or Filter matches. An enabled Filter can still block a domain before the Default Rule is reached.

See Default Rule for redirection modes and compatibility warnings.

Allow a Service but block one of its domains

A Service groups related domains under one action. Setting the Service to Bypass allows its matching domains even when a Filter would otherwise block them.

To block a particular domain within that Service, add a Block Custom Rule for that domain. The Custom Rule wins over the Service Rule. Be aware that blocking a dependency can stop part of the Service from working.

Block by default and allow selected destinations

Set the Default Rule to Block, then add Bypass Custom Rules or Service Rules for the destinations you need.

The explicit rules match before the Default Rule. Anything that does not match an earlier rule remains blocked. Include the dependencies those services need, not only the domain shown in the browser's address bar.


Did this page help you?