Choose your device.

Mac

A profile, installed with one click. Done in two minutes, with your own password.

What it does

  • Sends all DNS queries encrypted (DNS over HTTPS) to Cloudflare for Families. Adult and malware sites will not open, in any browser or app.
  • Turns on Apple's “Limit Adult Websites” filter.
  • Turns off iCloud Private Relay, which would get around the DNS filter.
  • Chrome, Brave, Edge and Firefox: no private windows, no guest mode, secure DNS fixed to Cloudflare for Families, SafeSearch in Chrome and Edge.

What it cannot do

  • Private browsing in Safari stays available. Apple only lets device management (MDM) turn it off, not a profile you install yourself. The DNS filter still works in private windows.
  • Whoever knows the administrator password can remove the profile.
  • A VPN, a second user with administrator rights, starting from another drive or a freshly set-up Mac get around the protection.
  • On Wi-Fi with a sign-in page (hotel, train) the sign-in may get stuck.

Who holds the key

You. With your password you can also remove the profile again. If you want only your anchor to be able to undo it, take the optional stricter step below.

How to

  1. Download the profile. On this Mac: Download Mac profile
  2. Install. Open System Settings > General > Device Management (older macOS: Privacy & Security > Profiles), double-click “Consurgam Schutz (Mac)”, choose “Install”. You type your password.
  3. Check. Restart your browsers and open nudity.testcategory.com. It is a harmless test page from Cloudflare. It must not load.
  4. If you like: Screen Time. In your account, turn on System Settings > Screen Time > “Content & Privacy” and choose “Lock Screen Time Settings”. Stricter: your anchor sets the Screen Time passcode.
  5. Optional, stricter: only your anchor can undo it. In System Settings > Users & Groups your anchor creates a new administrator account, logs in with it and turns off “Administrator” for your account. Only he knows the new account's password.

The profile is signed with the Apple “Developer ID” certificate of Michael Porwol (effata development). Its description lists what it sets. It contains no password.

To remove it

System Settings > General > Device Management, select the profile and remove it. The Mac asks for the administrator password.

Windows PC

One command in an administrator terminal. Done in two minutes, with your own password.

What it does

  • Sets up DNS over HTTPS to Cloudflare for Families, for IPv4 and IPv6, with no fallback to unencrypted DNS (Windows 11; Windows 10 filters unencrypted).
  • Puts these DNS servers on every active network adapter.
  • Edge, Chrome, Brave and Firefox: no InPrivate or Incognito windows, no guest mode, secure DNS fixed to Cloudflare for Families, SafeSearch in Edge and Chrome.
  • Checks at the end whether the filter works.

What it cannot do

  • Anyone with an administrator account can undo everything.
  • Other browsers (such as Opera or Vivaldi), a VPN, starting from a USB stick or a fresh Windows installation get around the protection.
  • A new network adapter, such as a USB network dongle, does not get the DNS servers by itself. Run the command again.

Who holds the key

You. With your administrator password you can also undo it. If you want only your anchor to be able to undo it, take the optional stricter step below.

How to

  1. Open the terminal. Right-click Start > “Terminal (Admin)”, on Windows 10 “Windows PowerShell (Admin)”. Windows asks for the administrator password.
  2. Paste the command. Click “Copy command” below, paste it in the terminal with a right-click or Ctrl+V, confirm pasting several lines, press Enter.
  3. Check. The last check line says “[4/4] OK”. Then restart your browsers.
  4. Optional, stricter: only your anchor can undo it. In Settings > Accounts > Other users your anchor creates an administrator account (a local account is fine) and changes your account to “Standard user”.
PowerShell
# Consurgam Schutz fuer Windows / Consurgam protection for Windows (version 1)
# Source: consurgam.com/schutz  -  Sends nothing to Consurgam, downloads nothing.
#
# What it does:
#   1. DNS over HTTPS with Cloudflare for Families (blocks adult and malware sites), IPv4 and IPv6,
#      no fallback to unencrypted DNS (Windows 11; on Windows 10 only plain DNS).
#   2. Sets these DNS servers on every active network adapter.
#   3. Browser policies (HKLM): no InPrivate/Incognito/private windows, no guest mode, secure DNS fixed
#      to Cloudflare for Families, SafeSearch. Edge, Chrome, Brave, Firefox.
#   4. Checks the result: a Cloudflare test domain must resolve to 0.0.0.0.
# Run it in "Terminal (Admin)". Safe to run again (idempotent). To undo: consurgam-windows-entfernen.ps1
# The key: whoever knows the administrator password can undo this. Your anchor keeps it.

& {
  $ErrorActionPreference = 'Stop'
  $doh  = 'https://family.cloudflare-dns.com/dns-query'
  $dns  = @('1.1.1.3', '1.0.0.3', '2606:4700:4700::1113', '2606:4700:4700::1003')
  $test = 'nudity.testcategory.com'   # Cloudflare test domain in the adult category, harmless

  # --- 0. Administrator? ---
  $ich = [Security.Principal.WindowsPrincipal][Security.Principal.WindowsIdentity]::GetCurrent()
  if (-not $ich.IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) {
    Write-Host 'Bitte als Administrator starten: Rechtsklick auf Start > Terminal (Administrator).' -ForegroundColor Yellow
    Write-Host 'Please run as administrator: right-click Start > Terminal (Admin).' -ForegroundColor Yellow
    return
  }

  # --- 1. Register DNS over HTTPS (Windows 11 / Server 2022+) ---
  $mitDoh = [bool](Get-Command Add-DnsClientDohServerAddress -ErrorAction SilentlyContinue)
  if ($mitDoh) {
    foreach ($a in $dns) {
      $da = Get-DnsClientDohServerAddress -ServerAddress $a -ErrorAction SilentlyContinue
      if ($da) {
        Set-DnsClientDohServerAddress -ServerAddress $a -DohTemplate $doh -AllowFallbackToUdp $false -AutoUpgrade $true | Out-Null
      } else {
        Add-DnsClientDohServerAddress -ServerAddress $a -DohTemplate $doh -AllowFallbackToUdp $false -AutoUpgrade $true | Out-Null
      }
    }
    Write-Host '[1/4] DNS ueber HTTPS eingerichtet / DNS over HTTPS registered'
  } else {
    Write-Host '[1/4] Dieses Windows kennt kein DNS ueber HTTPS (Windows 10). Es filtert trotzdem, aber unverschluesselt.' -ForegroundColor Yellow
    Write-Host '      This Windows has no DNS over HTTPS (Windows 10). It still filters, unencrypted.' -ForegroundColor Yellow
  }

  # --- 2. DNS servers on all active adapters ---
  $adapter = @(Get-NetAdapter | Where-Object { $_.Status -eq 'Up' })
  foreach ($n in $adapter) {
    Set-DnsClientServerAddress -InterfaceIndex $n.ifIndex -ServerAddresses $dns
  }
  Clear-DnsClientCache
  Write-Host ("[2/4] DNS gesetzt auf {0} Adapter(n) / DNS set on {0} adapter(s): {1}" -f $adapter.Count, (($adapter | ForEach-Object Name) -join ', '))

  # --- 3. Browser policies ---
  function Setze([string]$pfad, [hashtable]$werte) {
    if (-not (Test-Path $pfad)) { New-Item -Path $pfad -Force | Out-Null }
    foreach ($k in $werte.Keys) {
      $v = $werte[$k]
      $typ = if ($v -is [string]) { 'String' } else { 'DWord' }
      New-ItemProperty -Path $pfad -Name $k -Value $v -PropertyType $typ -Force | Out-Null
    }
  }
  Setze 'HKLM:\SOFTWARE\Policies\Microsoft\Edge' @{
    InPrivateModeAvailability = 1; BrowserGuestModeEnabled = 0; ForceGoogleSafeSearch = 1; ForceBingSafeSearch = 2
    DnsOverHttpsMode = 'secure'; DnsOverHttpsTemplates = $doh
  }
  Setze 'HKLM:\SOFTWARE\Policies\Google\Chrome' @{
    IncognitoModeAvailability = 1; BrowserGuestModeEnabled = 0; SafeSitesFilterBehavior = 1; ForceGoogleSafeSearch = 1
    DnsOverHttpsMode = 'secure'; DnsOverHttpsTemplates = $doh
  }
  Setze 'HKLM:\SOFTWARE\Policies\BraveSoftware\Brave' @{
    IncognitoModeAvailability = 1; BrowserGuestModeEnabled = 0; SafeSitesFilterBehavior = 1; ForceGoogleSafeSearch = 1
    DnsOverHttpsMode = 'secure'; DnsOverHttpsTemplates = $doh
  }
  Setze 'HKLM:\SOFTWARE\Policies\Mozilla\Firefox' @{ DisablePrivateBrowsing = 1; PrivateBrowsingModeAvailability = 1 }
  Setze 'HKLM:\SOFTWARE\Policies\Mozilla\Firefox\DNSOverHTTPS' @{ Enabled = 1; ProviderURL = $doh; Locked = 1; Fallback = 0 }
  Write-Host '[3/4] Richtlinien fuer Edge, Chrome, Brave, Firefox gesetzt (Browser neu starten) / Browser policies set (restart browsers)'

  # --- 4. Check ---
  try {
    $ip = @(Resolve-DnsName -Name $test -Type A -DnsOnly -QuickTimeout | Where-Object { $_.IPAddress } | ForEach-Object IPAddress)
  } catch { $ip = @() }
  if ($ip -contains '0.0.0.0') {
    Write-Host "[4/4] OK: $test -> 0.0.0.0. Der Filter wirkt. / The filter works." -ForegroundColor Green
  } else {
    Write-Host ("[4/4] Achtung: {0} -> {1}. Erwartet 0.0.0.0. VPN aktiv oder anderer DNS? / Check failed, expected 0.0.0.0." -f $test, ($ip -join ', ')) -ForegroundColor Yellow
  }
  Write-Host 'Jetzt: eigenes Konto auf Standardbenutzer stellen, Administrator-Passwort behaelt dein Anker.'
  Write-Host 'Next: make your own account a standard user; your anchor keeps the administrator password.'
}

Prefer a file: consurgam-windows.ps1. Start it in an administrator terminal with powershell -ExecutionPolicy Bypass -File .\consurgam-windows.ps1

To remove it

With consurgam-windows-entfernen.ps1, started the same way. It undoes exactly what the command set.

Linux

A script for the DNS filter and the browsers, started with your password.

What it does

  • Sends all DNS queries through systemd-resolved, encrypted (DNS over TLS), to Cloudflare for Families, with no fallback servers.
  • Chrome, Chromium, Edge, Brave and Firefox: no private windows, no guest mode, secure DNS fixed to Cloudflare for Families.
  • Checks at the end whether the filter works.

What it cannot do

  • Whoever is root or may use sudo can undo everything.
  • Browsers installed as Flatpak do not read the policies in /etc.
  • Without systemd-resolved the script sets up no DNS filter. The router helps then.
  • A VPN, a live USB stick or a fresh installation get around the protection.

Who holds the key

You. Whoever is root or may use sudo can undo it. If you want only your anchor to be able to undo it, take the optional stricter step below.

How to

  1. Download the script: consurgam-linux.sh
  2. Run it. In a terminal, in your Downloads folder: su -c 'sh consurgam-linux.sh', with the root password. If the system has no root password (Ubuntu, for example), start it with sudo sh and the path to the file.
  3. Check. The last check line says “[3/3] OK”. Then restart your browsers.
  4. Optional, stricter: only your anchor can undo it. Your anchor creates his own admin account and removes yours from the sudo group (Debian, Ubuntu) or wheel (Fedora, Arch).
View the script
#!/bin/sh
# Consurgam Schutz fuer Linux / Consurgam protection for Linux (version 1)
# Source: consurgam.com/schutz  -  Sends nothing to Consurgam, downloads nothing.
#
# What it does (run as root: sudo sh consurgam-linux.sh, or su -c 'sh consurgam-linux.sh'):
#   1. systemd-resolved: DNS over TLS with Cloudflare for Families (blocks adult and malware sites) for ALL
#      domains (Domains=~.), no fallback servers. Drop-in /etc/systemd/resolved.conf.d/consurgam.conf
#   2. Browser policies: no private windows/incognito/guest mode, secure DNS fixed to Cloudflare for Families,
#      SafeSearch. Chrome, Chromium, Edge, Brave: own file consurgam.json in .../policies/managed/.
#      Firefox: /etc/firefox/policies/policies.json (merged with existing policies if python3 is present).
#   3. Checks the result: a Cloudflare test domain must resolve to 0.0.0.0.
# Safe to run again. To undo: consurgam-linux-entfernen.sh
# The key: whoever has root (sudo) can undo this. Your own account should not be in the sudo/wheel group;
# your anchor keeps the root or admin password.
set -eu

DOH='https://family.cloudflare-dns.com/dns-query'
TEST='nudity.testcategory.com'   # Cloudflare test domain in the adult category, harmless

if [ "$(id -u)" -ne 0 ]; then
  echo "Bitte als root starten (sudo sh $0) / Please run as root (sudo sh $0)." >&2
  exit 1
fi

# --- 1. systemd-resolved ---
if ! command -v resolvectl >/dev/null 2>&1 || ! systemctl is-active --quiet systemd-resolved; then
  echo "systemd-resolved laeuft nicht. Ohne ihn richtet dieses Skript den DNS-Filter nicht ein." >&2
  echo "systemd-resolved is not running. This script needs it for the DNS filter." >&2
  echo "Alternative: DNS-Server 1.1.1.3 und 1.0.0.3 im Router oder im Netzwerk-Manager eintragen." >&2
  exit 2
fi
mkdir -p /etc/systemd/resolved.conf.d
cat > /etc/systemd/resolved.conf.d/consurgam.conf <<'EOF'
# Consurgam: Cloudflare for Families over DNS-over-TLS for all domains. Remove with consurgam-linux-entfernen.sh
[Resolve]
DNS=1.1.1.3#family.cloudflare-dns.com 1.0.0.3#family.cloudflare-dns.com 2606:4700:4700::1113#family.cloudflare-dns.com 2606:4700:4700::1003#family.cloudflare-dns.com
DNSOverTLS=yes
Domains=~.
FallbackDNS=
EOF
systemctl restart systemd-resolved
resolvectl flush-caches 2>/dev/null || true
echo "[1/3] systemd-resolved: DNS ueber TLS zu Cloudflare for Families / DNS over TLS to Cloudflare for Families"
case "$(readlink -f /etc/resolv.conf 2>/dev/null || true)" in
  */systemd/resolve/stub-resolv.conf|*/systemd/resolve/resolv.conf) ;;
  *) echo "      Achtung: /etc/resolv.conf zeigt nicht auf systemd-resolved. Netzwerk-Manager auf systemd-resolved umstellen." >&2
     echo "      Warning: /etc/resolv.conf does not point to systemd-resolved. Switch your network manager to systemd-resolved." >&2 ;;
esac

# --- 2. Browser policies ---
CHROMIUM_JSON='{
  "IncognitoModeAvailability": 1,
  "BrowserGuestModeEnabled": false,
  "SafeSitesFilterBehavior": 1,
  "ForceGoogleSafeSearch": true,
  "DnsOverHttpsMode": "secure",
  "DnsOverHttpsTemplates": "'"$DOH"'"
}'
EDGE_JSON='{
  "InPrivateModeAvailability": 1,
  "BrowserGuestModeEnabled": false,
  "ForceGoogleSafeSearch": true,
  "ForceBingSafeSearch": 2,
  "DnsOverHttpsMode": "secure",
  "DnsOverHttpsTemplates": "'"$DOH"'"
}'
for d in /etc/opt/chrome/policies/managed /etc/chromium/policies/managed /etc/chromium-browser/policies/managed /etc/brave/policies/managed; do
  mkdir -p "$d" && printf '%s\n' "$CHROMIUM_JSON" > "$d/consurgam.json"
done
mkdir -p /etc/opt/edge/policies/managed && printf '%s\n' "$EDGE_JSON" > /etc/opt/edge/policies/managed/consurgam.json

FF=/etc/firefox/policies/policies.json
mkdir -p /etc/firefox/policies
if [ -s "$FF" ] && [ ! -f /etc/firefox/policies/.consurgam ]; then
  if command -v python3 >/dev/null 2>&1; then
    python3 - "$FF" "$DOH" <<'EOF'
import json, sys
p, doh = sys.argv[1], sys.argv[2]
d = json.load(open(p))
pol = d.setdefault("policies", {})
pol.update({"DisablePrivateBrowsing": True, "PrivateBrowsingModeAvailability": 1,
            "DNSOverHTTPS": {"Enabled": True, "ProviderURL": doh, "Locked": True, "Fallback": False}})
json.dump(d, open(p, "w"), indent=2)
EOF
    echo "      Firefox: bestehende Richtlinien ergaenzt / existing policies extended"
  else
    echo "      Firefox: $FF existiert schon und python3 fehlt. Bitte von Hand ergaenzen. / exists, python3 missing: please merge by hand." >&2
  fi
else
  cat > "$FF" <<EOF
{
  "policies": {
    "DisablePrivateBrowsing": true,
    "PrivateBrowsingModeAvailability": 1,
    "DNSOverHTTPS": { "Enabled": true, "ProviderURL": "$DOH", "Locked": true, "Fallback": false }
  }
}
EOF
  : > /etc/firefox/policies/.consurgam   # marks the file as ours, so the removal script may delete it
fi
echo "[2/3] Richtlinien fuer Chrome, Chromium, Edge, Brave, Firefox gesetzt (Browser neu starten) / browser policies set (restart browsers)"

# --- 3. Check ---
ERG=$(resolvectl query --legend=no -t A "$TEST" 2>/dev/null | head -1 || true)
case "$ERG" in
  *0.0.0.0*) echo "[3/3] OK: $TEST -> 0.0.0.0. Der Filter wirkt. / The filter works." ;;
  *) echo "[3/3] Achtung: $TEST -> ${ERG:-keine Antwort}. Erwartet 0.0.0.0. VPN aktiv? / Check failed, expected 0.0.0.0." >&2 ;;
esac
echo "Jetzt: dein eigenes Konto ohne sudo, das Root- oder Admin-Passwort behaelt dein Anker."
echo "Next: your own account without sudo; your anchor keeps the root or admin password."

To remove it

With consurgam-linux-entfernen.sh, started the same way.

Home router

A DNS filter in the router protects every device on your Wi-Fi, including TV and console.

What it does

  • Every device on your Wi-Fi or cable asks Cloudflare for Families. Adult sites will not open there.
  • On a FRITZ!Box, encrypted (DNS over TLS).

What it cannot do

  • Works only at home, not on the road or on mobile data.
  • iCloud Private Relay, a VPN or a browser with its own “secure DNS” get around it. The Mac and Windows sections help against that.
  • Resetting the router to factory settings removes the filter.

Who holds the key

You, with the router's admin password. Stricter: your anchor changes that password and keeps it.

How to

  1. Open fritz.box in a browser and sign in.
  2. Internet > Account Information > DNS Server. Under DNSv4 “Use other DNSv4 servers”: 1.1.1.3 and 1.0.0.3. Under DNSv6 “Use other DNSv6 servers”: 2606:4700:4700::1113 and 2606:4700:4700::1003.
  3. Turn on “Encrypted name resolution on the internet (DNS over TLS)” and enter family.cloudflare-dns.com as the resolver name.
  4. Better leave “Fallback to unencrypted name resolution” off. That is stricter. If Cloudflare is ever unreachable, no site opens for a while; then your anchor can turn the fallback on.
  5. Apply. Then your anchor changes the password of the admin page under System > FRITZ!Box Users.
  6. Other routers: the menu is often called “DNS”, “Internet” or “WAN”. Enter the same addresses there. Menu names may differ between versions.

To remove it

Under DNS Server choose “Use DNS servers assigned by the internet service provider” again. This needs your anchor's password.

iPhone and iPad

That is what the Consurgam app is for. One purchase covers iPhone and iPad.

What it does

  • In the app under Companion > Protection: Safari protection with a breathing pause, Apple's adult filter, and a pause before apps you choose.

What it cannot do

  • You can undo these locks yourself. On iPhone and iPad, a real key exists only through Apple's Screen Time passcode.

Who holds the key

You, in the app. Stricter: your anchor sets the Screen Time passcode and enters his own Apple Account for recovery. The app walks you through it under Companion > Protect all devices.

Android

Set Private DNS to Cloudflare for Families.

What it does

  • Adult sites will not open in any app, also on mobile data.

What it cannot do

  • Android offers adults no key: you can change the setting back yourself.

Who holds the key

Nobody. If that is not enough for you: the router at home at least holds there.

How to

  1. Settings > Network & internet > Private DNS, “Private DNS provider hostname”: family.cloudflare-dns.com. Menu names may differ by manufacturer.

No filter is airtight. A lock buys you time; it does not replace a conversation.

What we learn: nothing

The profile and the scripts contain no identifier of yours and send nothing to us. They download nothing either. The names of the sites you open (DNS queries) go to Cloudflare for Families. By its own commitment, Cloudflare truncates the IP address there and deletes it within 25 hours (Cloudflare's privacy commitment). More in our privacy policy.

← Consurgam