A family filter can appear to work on one device and fail on another because the devices are not taking the same route to the internet. VPNs, encrypted DNS and Apple’s iCloud Private Relay are three possible reasons—but they are different technologies and should not be treated as a single problem.
Start by understanding the route
A router-level DNS policy works when a device uses the protected home network and its intended resolver. If the device sends its DNS requests or wider traffic through another encrypted service, the household resolver may no longer be making the decision.
- A VPN usually creates an encrypted connection between a device and a VPN provider. DNS and other traffic may travel through that connection.
- Encrypted DNS protects DNS questions in transit and can let an app or operating system choose a resolver other than the router’s.
- iCloud Private Relay is an iCloud+ privacy feature focused on Safari browsing and certain unencrypted traffic. It is not the same as a general-purpose VPN.
What Apple says about Private Relay
Apple explains that Private Relay separates identity and destination information across two internet relays. Apple also acknowledges that networks using filtering may be incompatible with it and allows the feature to be disabled for a specific Wi-Fi network through Limit IP Address Tracking.
Private Relay is not available in every country or region. Menus can also change between iOS, iPadOS and macOS releases, so follow Apple’s current instructions rather than an old screenshot.
Diagnose before changing settings
- Confirm the device is on the protected Wi-Fi. Turn off mobile data temporarily during the test.
- Check Fitra Guard’s connection status. A router replacement, factory reset or changing public IP can interrupt the home link.
- Look for a VPN profile or app. Work, school and security apps may install one for a legitimate reason.
- Review browser and operating-system DNS settings. A “secure DNS” option may be using another provider.
- On Apple devices, review Private Relay for that Wi-Fi network. Do not disable an account-wide privacy feature when a network-specific change is enough.
- Test with a safe diagnostic page. Do not deliberately open harmful content to prove a block.
Fixes by cause
When a VPN is responsible
Decide whether the VPN is necessary. A school or employer may require it, while an unknown consumer VPN on a child’s device may not belong there. Remove unauthorised VPN profiles where the parent owns and administers the device. If the VPN is required, ask the organisation whether its policy can coexist with the family setup.
When encrypted DNS is responsible
Set the browser or operating system to use the network’s designated resolver, then restrict changes through the device’s parental or administrator controls where appropriate. Exact options differ by platform. Treat “designed to restrict common bypass attempts” as the realistic goal; no network rule is invulnerable to someone who retains full administrative control.
When Private Relay is responsible
Apple’s current guidance lets a user turn off Limit IP Address Tracking for a particular Wi-Fi network. On an iPhone or iPad, this is usually found under Settings, Wi-Fi and the information button for that network. On a Mac, review the network’s Details. Confirm the current path in Apple Support before making the change.
What not to do
- Do not block every privacy tool without understanding why it is installed.
- Do not assume private browsing alone changes DNS or defeats filtering; it mainly limits local browser history and cookies.
- Do not install untrusted certificates or “fix” profiles from unknown websites.
- Do not promise that one router rule can control a device on mobile data or another network.
- Do not turn troubleshooting into a secret contest with a child. Explain the boundary and its reason.
Build a more stable setup
Keep router firmware current, protect administrator access and use child accounts so network and device settings reinforce one another. Review the setup after an operating-system update, new router, new phone or ISP change. For older children, agree in advance which privacy tools are allowed and when a parent should be consulted.
A filter is most reliable when the technical route, device permissions and family expectations all point in the same direction.
Sources & further reading · 4 references
- About iCloud Private Relay — Apple Support
- Manage Private Relay for websites, networks or system settings — Apple Support
- RFC 8484: DNS Queries over HTTPS — IETF
- Filter content for Apple devices — Apple Platform Deployment
Last reviewed: 4 August 2026. Interface labels and compatibility can change; check current vendor guidance for the device you administer.