Block trackers in every app
App-wide blocking filters the domain lookups your device makes, so tracker domains are refused in every app rather than in Safari alone. It arrives switched off, and you turn it on yourself.
Turn on app-wide blocking
- Open Blue Guard.
- Go to Settings.
- Turn on app-wide blocking.
- Allow the VPN configuration when iOS asks for it.
App-wide blocking runs through a packet tunnel, which is why iOS asks to add a VPN configuration. Nothing is routed to a systemBlue server.
What happens to a lookup
- A lookup for a blocked domain is answered on your device. Nothing is sent.
- Any other lookup is forwarded to Cloudflare (1.1.1.1) or Quad9 (9.9.9.9), alternating between them.
- Forwarded lookups use DNS over TLS on port 853. The resolver's certificate is verified before a lookup is sent. There is no unencrypted fallback: a lookup that cannot be sent encrypted is not sent at all.
A resolver receives the domain and the network address it came from. systemBlue does not receive, observe, log or retain any lookup or answer. Each resolver is an independent controller under its own privacy policy.
Limits
Filtering works on domain names, which is what lets it cover every app:
- An ad served from an app's own domain cannot be blocked without blocking the app.
- Page elements cannot be hidden outside Safari, because hiding requires a CSS selector applied to a page.
Custom rules apply here too, but only where they can be read as whole domains. Custom rules sets out which forms carry across and which do not.
Your category settings and allowed sites apply here too. Switching app-wide blocking off ends all of this and does not affect Safari blocking.
What is stored
The counts on the Home screen come from this mechanism, since it is the part that sees a decision being made. What those totals contain, and how long they are kept, is in Privacy and data.