In this article
Block Pages display when a user attempts to visit a domain that is restricted by the Filtering Policy assigned to a Site or Roaming Client.
From the DNSFilter dashboard, customize a Block Page's appearance, behavior, and notifications. For troubleshooting and email notification configuration, see Block Page administrator notifications.
Block Page types
Hosted Block Pages
Blocked HTTP and HTTPS requests are sent to a hosted, preformatted Block Page.
- Fully customizable
- Can display organization information
- Include an embedded form for user notifications
- Support multiple languages based on the browser language, including English, Spanish, Portuguese, Turkish, Ukrainian, Italian, Russian, French, Czech, German, and Hebrew
External Block Pages
Blocked HTTP and HTTPS requests are sent to a specific public or private URL using a 302 redirect.
- Redirect users with a 302 response to a defined URL
- Allow full customization of the Block Page appearance
- Include identifiers in the URL: IP address, blocked domain, Filtering Policy, and categories
- Can point to a local resource, such as
http://office.local/block.html, or a public resource, such ashttp://validdomain.com/block.html
Prerequisites
To ensure Block Pages display correctly on HTTPS sites, install the SSL Certificate.
- The certificate installs automatically with Windows Roaming Client deployments
- Without the certificate, HTTPS sites return error pages but remain blocked
Add a Block Page
Assign Block Pages to the appropriate attribute after configuration, such as a Site, User, or Roaming Client. If not assigned, the default DNSFilter Block Page displays.
Create a Hosted Block Page
To create a hosted Block Page:
- From the DNSFilter dashboard, navigate to Policies and select Block Pages.
- Select Add Block Page.
- Under General Settings, enter a Name as the internal identifier for the Block Page.
- Under Configuration, select Hosted (Recommended) as the Page Type.
- Configure any of the following optional settings:
- Organization Name: Displayed name of the organization responsible for the block
- Notice Email: Address to receive user notifications. Entering an email address enables the option for end users to request a domain be unblocked. Leaving this field blank disables this option
- Custom Logo: Upload a logo, maximum width 500px. Leave blank to display no logo
-
Optional: select Preview to see what the Block Page looks like for end users.
Preview becomes available after an Organization Name and a Custom Logo are added.
- Select Save Block Page.
The Block Page is now available in the Assigned Block Page dropdown menu.
Create an External Block Page
To create an external Block Page:
- From the DNSFilter dashboard, navigate to Policies and select Block Pages.
- Select Add Block Page.
- Under General Settings, enter a Name as the internal identifier for the Block Page.
- Under Configuration, select External (Advanced) as the Page Type.
- Enter the 302 Redirect (URL).
- Select Save Block Page.
The Block Page is now available in the Assigned Block Page dropdown menu.
Test a Block Page
After applying a Filtering Policy and Block Page to a Site, test the configuration:
- Use DNSFilter test domains
- Attempt to access a blocked category or a domain on the Block List
Related Resources
- Troubleshoot issues with Block Pages not loading in Chrome
- Adjust Ad and Tracker settings to prevent NODATA responses
- Why Block Pages display “network filtering policy” instead of a category
- Block Page admin settings and block notification errors
Comments
6 comments
Minetta Gould I am trying to use an external block page and while it goes to the correct page I am not seeing the parameters that should be passed of IP, domain, categories and policy. I have read where it is automatically passed but I do not see this data even used wireshark and burp suite to see if I could see it. Do you have any other guidance I could look at regarding this topic. It looks very straightforward and minimal information.
Thanks
Hi Jennifer Kendall , thanks for reaching out! It sounds like your external block page is redirecting correctly, but the expected parameters (IP, domain, categories, and policy) aren’t being passed. We’ve tested this setup in different configurations—both with a Roaming Client and a direct DNS/site configuration—and in both cases, the parameters were passed as expected.
A few things to check: Some security applications or browser settings might be blocking the URL redirect, flagging it as a potential security risk (e.g., cross-site scripting or phishing protection).
Though this article is framed around blocked DNS traffic, the same security applications could be blocking this info from passing through with your external block page, so it could be a helpful reference point. It’s also worth reviewing your block page configuration to ensure the external URL is set correctly and hasn’t been reverted.
If everything looks right on your end and the issue persists, we recommend reaching out to our support team for a deeper technical review. Hope this helps, and feel free to reach out anytime!
Hi Minetta Gould, thank you for the response. Yes, I figured based on your docs it should just show up. Maybe we are not creating the page correctly so the information has a place to land so to speak. I will see what I can do to test again since this is on an page created in Tines automation which is acting as the block page.
Anyway thanks for your response.
Of course! Sorry there wasn't a more clear answer on our end. I hope the tests are successful!
Has the "Block Page Bypass" feature been fixed for the security issues yet? Last I chatted with your team on restoring this feature was on March 20, 2025 @ 10:53 AM PST. That was a great feature to have. We have visiting vendors or consultants on our campus that get blocked to their company websites, when they are joining the school's unified wifi signal.
Thanks for checking in on this, IT DEPARTMENT! Block Page Bypass is still unavailable while we work on a secure replacement — no timeline to share just yet, but it’s on our radar.
In the meantime, for visiting vendors or consultants getting blocked on campus Wi-Fi, the quickest workaround is a temporary Allow List exception in the filtering policy assigned to that network. Policy changes apply within seconds, so it’s pretty low-friction to add and remove as needed.
Here’s how:
example.com)— don’t enter a full URL or path.When the vendor no longer needs access, remove the entry from the same Allow List.
Please sign in to leave a comment.