KNOWLEDGE
Why DNS protection isn't everything — and how to really secure your home network
AdGuard Home protects well — but not against everything. What DNS filters can't do, which 4 layers of protection actually help, and how to make your home network more robust step by step.
You've set up AdGuard Home. Filter lists active, statistics running, phishing domains getting blocked. That's a real step forward — and the right one. But DNS protection has limits you should know about. Not to discourage you, but so you know where to go next.
What DNS protection actually does
A quick reminder: every time someone at home visits a website, your device asks a DNS server for the address. A DNS filter like AdGuard Home checks this request and blocks it if the domain is on a blocklist — before the connection is even established.
What a good DNS filter catches
Yes: Known phishing sites, malware domains, tracking networks, advertising, command-and-control domains from malware.
Condition: The domain must already be known as harmful and listed in a filter list.
For a deeper introduction, we recommend our article Internet Shield: Why your router is the first line of defence.
The 4 limits of DNS filters
1. Only known domains are blocked
DNS protection works like a blocklist. What's not on it gets through. A brand-new phishing domain registered yesterday isn't on any filter list yet. Statistically, many attackers today use domains that are only a few hours old — deliberately, before they become known.
2. No protection within allowed sites
YouTube running? YouTube ads run too — because they're served from the same domain. An attacker who compromises a legitimate site via a hacked ad banner uses a domain your filter knows and allows. DNS only sees the domain name, not what's behind it.
3. Direct IP connections bypass DNS entirely
Malware that's been specifically developed often connects directly via IP addresses — without a DNS request. Your filter simply doesn't see this. The same applies to apps with their own DNS resolver built in that bypass your local filter.
⚠️ Note:
A device that sends DNS requests directly to an external server (e.g. 8.8.8.8) bypasses your AdGuard Home completely. This sometimes happens automatically with certain apps — without you noticing.
4. Compromised legitimate websites
If a normally trustworthy website is hacked and delivers malware, DNS doesn't help. The domain is known, the filter allows it — the malicious code runs in the browser anyway.
What would be more robust: 4 layers of protection
DNS filter is Layer 1. Three more layers close the gaps:
Layer 2 — Strengthen router firewall: Blocks suspicious connection patterns and prevents apps from bypassing your DNS filter. Costs a one-off 20 minutes.
Layer 3 — Encrypted DNS (DoH/DoT): Prevents your internet provider from reading your DNS requests. DNSSEC additionally verifies that responses haven't been tampered with.
Layer 4 — Browser hardening: uBlock Origin blocks at content level what DNS filters can't. HTTPS-only prevents unencrypted connections. Secure DNS in the browser prevents DNS bypass even without network-level changes.
💡 Tip:
All 4 layers together require no great expertise — and no second router or additional hardware. What you need: a calm hour and a clear guide.
How much effort is this?
| Layer | One-off effort | What it delivers |
|---|---|---|
| DNS filter | ✓ already set up | Known malicious domains blocked |
| Router firewall | ~20 minutes | DNS bypass prevented |
| Encrypted DNS | ~15 minutes | Eavesdrop-proof, tamper-proof |
| Browser hardening | ~20 minutes | Content filter, HTTPS enforcement |
| Bonus: endpoint | ~10 minutes | Malware scan, password manager |
For anyone who wants to set up all 4 layers: the NUNIVIA Protection Wall guides you through every step — with concrete settings for Fritz!Box and other routers and a function test at the end. Requires AdGuard Home (from the Home Guide).
Really secure your home network — all 4 layers
Router firewall, encrypted DNS, browser hardening: the NUNIVIA Security Guide walks you through all 4 protection layers — with screenshots and a function test.
To the NUNIVIA Security GuideHaven't set up your own filter yet?
The Security Guide builds on AdGuard Home. Start with the Home Guide — the Security Guide is the natural next step.
View NUNIVIA Home Guide