How Control D Handles False Positives
How Control D prevents, reviews, and quickly resolves false-positive blocks.
TLDR
- A single quotable false-positive rate is difficult to define because traffic and policy choices vary between networks.
- Control D handles more than 100,000 DNS queries per second and receives only a few false-positive reports in a typical week. Reported false positives are very rare at this scale.
- No filtering system can guarantee zero false positives, so Control D provides several ways to resolve them quickly.
- Domain Test and the Activity Log let you create a BYPASS rule immediately. Eligible Domain Test reports are queued for human review right away.
- Custom Block Pages let staff request access to a blocked domain or follow an organization's own access-request process.
Why We Do Not Quote a Single False-Positive Rate
A query-level percentage sounds precise, but it does not describe every deployment. The result depends on which Filters and modes are enabled, the domains a network accesses, and whether a user reports an unwanted block.
Control D processes more than 100,000 DNS queries per second while receiving only a few false-positive reports in a typical week. This shows that reported false positives are rare, but a report count is not the same as a complete measurement of every blocked query. We therefore focus on keeping false positives low and making the exceptions fast to diagnose and resolve.
Resolve a False Positive
Domain Test
Use Domain Test when you know the domain or URL that is failing.
- Select the affected Endpoint.
- Enter the domain or URL and select Check Domain.
- Review the verdict and the Filter, Service, or rule that caused it.
- If Domain Test shows an eligible Control D Filter or Service block, select Report False Positive.
- Add a short comment describing what should work and what the block breaks, then select Send.
Reports are queued for human review right away. When a Control D-managed Filter or Service is incorrect, many valid reports are resolved within 15–20 minutes if the issue is straightforward.
You do not have to wait for the global classification to change. Select Create a rule to bypass this domain immediately in the report form. After sending the report, review the prefilled BYPASS Custom Rule, select the destination Profile, and save it.
Activity Log
A website or application may depend on several domains. If the main domain is not blocked, use the Activity Log to reproduce the issue and find the exact blocked hostname. Full Analytics must be enabled on the Endpoint to view individual queries.
Select the edit action on a blocked query to open a prefilled BYPASS Custom Rule. You can also select multiple queries and add rules for them together. Review the affected Profile and save the rule to restore access.
If the Activity Log does not show the failing query, follow Collect Activity Log to confirm whether the request is reaching Control D before treating the problem as a false positive.
Custom Block Pages
Organizations can use Custom Block Pages to give staff a clear response when a domain is blocked.
With the default request option, staff can select Request Unblock, enter their name and reason, and submit the request to the account owner or organization administrators. The recipient gets the blocked domain and a direct path to create an exception in the affected Profile.
Organizations can instead configure a custom link to send staff into an existing ticketing or access-request workflow. This keeps the approval decision with the people who own the organization's policy.
What Happens to a Report
A Domain Test false-positive report includes the domain, the Control D Filter or Service that caused the verdict, the submitter's comment, and the relevant account, Endpoint, and configuration context needed to investigate the issue.
A human reviews the report rather than removing the domain automatically. If the domain is genuinely misclassified or incorrectly included in a Service, Control D updates the managed data. The reporter can use a BYPASS rule immediately while that review takes place.
Blocks Control D Does Not Manage
Third-Party Filters
Control D does not maintain the contents of third-party Filters. Report the domain to the blocklist maintainer and use a BYPASS Custom Rule if you need a local exception. Domain Test does not offer a Control D false-positive report for these lists.
Your Own Profile Rules
If Domain Test identifies a Custom Rule or Default Rule, edit the Profile that created the block. This is your own policy, so Control D cannot change it automatically through a false-positive report.
Free DNS Reports
For a Control D-managed Free DNS resolver, test the domain with the Free DNS Link Checker on the Free DNS page. If the result is blocked, use Report False Positive and provide a short explanation.
If you selected a community-maintained Free DNS blocklist, report the issue to that list's maintainer instead.
Report Only What Is Needed
Do not include passwords, access tokens, full URLs containing private query values, or other sensitive information in a report. The domain and a short description of the expected behavior are normally enough.
Updated about 4 hours ago
