Takes 5–15 minutes. Works on every phone, tablet, and computer on your network.
📱
iPhone5 min · this device
🤖
Android5 min · this device
📡
Home Router10 min · all devices
Best protection: set up your home router (covers every device) and each phone (follows you on cellular). If your router won't let you change DNS, the per-device paths protect everyone in the home.
📲 Step 1 — Install the DNS Filter
This installs a privacy-preserving DNS filter directly on your iPhone. It blocks adult content at the network level — before pages even load.
The wizard walks you through installing the profile and setting your accountability partner's removal password.
🔒 Step 2 — Lock it with Screen Time
Screen Time adds a second lock so the DNS filter can't be deleted without your accountability partner's Screen Time PIN.
iOS 17 / 18 Note: Apple moved the VPN restriction in the last two updates. If you can't find it under Content & Privacy Restrictions → Network, follow the new path below.
Open Settings → Screen Time
If Screen Time isn't on, tap "Turn On Screen Time" → "This is My iPhone"
Tap Content & Privacy Restrictions → toggle it ON
Tap Allowed Apps
This is where Apple moved VPN controls in iOS 17+
Find VPN in the list → toggle it OFF
If you don't see it, tap "Content Restrictions" → "Network" → "VPN" → "Don't Allow"
Go back to Content & Privacy → tap Content Restrictions
Tap Web Content → select Limit Adult Websites
Back in Screen Time → tap Change Screen Time Passcode
Your accountability partner sets this. You should NOT know this code.
Supervised device note: Some VPN and network restrictions only appear on supervised (MDM-managed) devices. If you're on a personal iPhone and don't see the VPN toggle, the DNS filter profile alone still provides strong protection — the removal password on the profile is your primary lock.
✅ Step 3 — Verify it's working
Open Settings → VPN & Device Management — you should see "Breaking Chains — Family DNS Filter" listed
Open Safari and try navigating to a known adult site — it should show a blocked page
Your accountability partner sends you the filter link — you're live
✓ The filter works on WiFi and cellular data. It follows you everywhere your phone goes.
Android 9 and newer has a filter built in. One setting locks down your whole phone, on WiFi and cellular, before any page loads.
Open Settings → Network & Internet (on Samsung: Connections → More connection settings)
Tap Private DNS
Select Private DNS provider hostname
Enter the hostname below, then tap Save
Enter this exact hostname:
Private DNS hostnamefamily-filter-dns.cleanbrowsing.org
✓ Encrypted, no app to install, and it filters adult content everywhere your phone goes.
🔒 Step 2 — Lock it so it can't be removed
Private DNS alone is strong, but a second lock keeps it from being switched off in a weak moment.
Set a screen lock (PIN or fingerprint) your accountability partner controls, or
Have your partner manage the phone with Google Family Link — they approve any change to Settings
On Samsung, you can also restrict Settings changes inside Secure Folder / Restrictions
Honest note: Android does not lock network settings as tightly as a supervised iPhone. The always-on filter plus your accountability partner being notified is the real protection. Family Link is the strongest lock available.
✅ Step 3 — Verify it's working
Open Chrome and try a known adult site — it should fail to load or show a blocked page
Confirm Settings → Private DNS still shows the hostname above
Your accountability partner is now in the loop — you're live
Older Android (before 9) has no Private DNS. Use the home router path below so the filter is applied for the whole house, or ask Wisdom for a DNS app option.
Select your brand below. If you're not sure, check the label on the bottom or back of your router — the brand and model number are printed there.
🟠
EeroAmazon
🔵
GoogleNest / WiFi Pro
⚫
NetgearOrbi / Nighthawk
⚫
ASUSZenWiFi / RT
🔴
TP-LinkArcher / Deco
🔵
LinksysVelop / EA
⚪
XfinityComcast
🔵
SpectrumISP Router
🌐
AT&T / Fios / CoxISP gateway
📶
5G Home / StarlinkWireless gateway
📦
Other / ISPUnknown brand
📸
Not sure? Upload a photo of your router
Wisdom will identify it and give you the right steps
🟠 Eero (Amazon) Setup
Eero uses the iPhone app — no browser login needed. Takes about 3 minutes.
🌐 Frontier Fiber users: Use the Eero app only — not the MyFrontier app. MyFrontier is just for your account and billing. Your Eero controls all the routing.
Open the Eero app on your iPhone (download from the App Store if needed)
Tap the menu icon (☰) in the top-left corner → tap Settings
Tap Network Settings → tap DNS
Tap Custom DNS and enter the Breaking Chains DNS servers below:
Enter these DNS servers in Eero:
Primary DNS185.228.168.168
Secondary DNS185.228.169.168
Tap Save — Eero will restart briefly
Open any browser on any device at home and try a known adult site — it should be blocked
Eero does NOT natively support DNS-over-HTTPS. The IP method above still filters all traffic — it's strong protection for every device on your network.
🔵 Google / Nest WiFi Setup
Google WiFi is app-controlled. All settings live in Google Home.
Open the Google Home app on your iPhone
Tap your WiFi network → tap Settings (gear icon)
Tap Advanced Networking → tap DNS
Switch from "Automatic" to Custom and enter:
Primary DNS185.228.168.168
Secondary DNS185.228.169.168
Tap Save
Test on any device connected to your Google WiFi
If you have a Nest WiFi Pro (Wi-Fi 6E), the DNS setting may be under Settings → Advanced inside the Google Home app.
⚫ Netgear (Orbi / Nighthawk) Setup
Netgear routers have a web-based admin panel. You'll need to be on your home WiFi.
Log in (default: admin / admin, or check router label)
In left sidebar → click WAN
Scroll to WAN DNS Setting section
Set Connect to DNS Server automatically to No
Enter the DNS servers:
DNS Server 1185.228.168.168
DNS Server 2185.228.169.168
Click Apply at the bottom of the page
Test on any connected device
ASUS ZenWiFi models also support DNS-over-TLS — if you see that option, set the server hostname to family-filter-dns.cleanbrowsing.org for encrypted filtering.
🔴 TP-Link (Archer / Deco) Setup
Deco uses the Deco app. Archer routers have a web admin panel.
Go to Connectivity → Internet Settings (or Local Network → DHCP)
Find Static DNS — enter the servers below
Static DNS 1185.228.168.168
Static DNS 2185.228.169.168
Click OK then Apply — router reconnects in ~30 seconds
Velop (Linksys app): Open Linksys app → tap WiFi name → DNS → Custom → enter the IPs above.
⚪ Xfinity (Comcast) Setup
Xfinity gateway routers (the combo modem+router Comcast provides) have limited DNS customization. The easiest path is to use the Xfinity app or put the gateway in Bridge Mode and add your own router.
Option A — Xfinity App (easiest):
Open the Xfinity app → tap WiFi
Tap See Network → Edit WiFi
Look for DNS settings — if available, enter the servers below
Log in (check label on the back — usually admin/password)
Go to Gateway → Connection → Wi-Fi
Look for DNS under Advanced settings
Primary DNS185.228.168.168
Secondary DNS185.228.169.168
If Xfinity doesn't let you change DNS on the gateway, set up each device instead (iPhone profile or Android Private DNS) which protects every device regardless of the router.
🔵 Spectrum (Charter) Setup
Spectrum's provided routers often don't allow DNS customization. The most reliable approach: set up each device (iPhone profile or Android Private DNS), which works regardless of your ISP's router.
Log in (check the label on the back of your Spectrum router — usually admin/admin or admin/password)
Look for Advanced Settings → DNS or WAN → DNS
If DNS customization is available, enter:
Primary DNS185.228.168.168
Secondary DNS185.228.169.168
If Spectrum's router won't let you change DNS, buy your own router (~$60 for a TP-Link Archer) and plug it into the Spectrum modem. You'll have full DNS control and better performance.
📦 Generic / ISP Router Setup
Most routers have a web admin panel. Here's the universal approach:
Find your router's admin address — usually printed on the label on the bottom or back. Common addresses:
Log in — credentials are on the router label. Common defaults: admin / admin, admin / password, or admin / 1234
Look for one of these menu names: Internet, WAN, Advanced, Network, or DNS Settings
Find the DNS field — switch from Automatic/DHCP to Manual / Custom
Enter the Breaking Chains DNS servers:
Primary DNS185.228.168.168
Secondary DNS185.228.169.168
Save / Apply and wait for the router to reconnect (~30 seconds)
On any device connected to your WiFi, open a browser and try a known adult site — it should be blocked
🌐 AT&T, Verizon Fios, Cox & similar ISP gateways
Most of these gateways (AT&T BGW210/BGW320, some Verizon Fios, Cox Panoramic) do not let you change DNS in their settings. That's normal. You have two reliable ways to get full protection.
Option A — Protect every device (covers the whole home, no router access needed):
Set the filter on each phone and computer. This protects everyone regardless of what the gateway allows, and it follows phones onto cellular too.
On a Mac or Windows PC, set DNS to 185.228.168.168 / 185.228.169.168 in network settings. Ask Wisdom below for click-by-click.
Option B — Add your own router (best whole-home fix):
Put the ISP gateway in IP Passthrough (AT&T) or Bridge mode (Cox / Fios)
Plug in your own router (an Eero or TP-Link Archer, ~$60)
Set the Breaking Chains DNS on that router, then follow its card above
DNS for your own router:
Primary DNS185.228.168.168
Secondary DNS185.228.169.168
Not sure if yours allows DNS changes? Tap a card to try the admin panel, or upload a photo and Wisdom will tell you which option fits your exact gateway.
📶 T-Mobile / Verizon 5G Home & Starlink
Wireless gateways (T-Mobile 5G Home Internet, Verizon 5G Home, Starlink) generally do not support custom DNS on the gateway itself. The reliable path is per-device protection.
This covers every phone in the home and keeps working when you leave the house. Set the same DNS (185.228.168.168 / 185.228.169.168) on any Mac or Windows computer.
Advanced — add your own router:
T-Mobile / Verizon 5G: some models let you run your own router behind them in bridge/AP mode
Starlink: use the Ethernet adapter and put the Starlink router in Bypass mode, then add your own router
Set the Breaking Chains DNS on that router and follow its card above
Tell Wisdom your exact gateway and it will confirm whether bridge mode is supported.