Quick Cheat Sheet

Here is the short version.

The beginner formula

  • Start with one profile
  • Start with one device
  • Enable malware and phishing protection
  • Add one moderate ad/tracker filter
  • Keep custom rules narrow and documented
  • Avoid stacking multiple aggressive lists at once

Good default mindset

  • Conservative first
  • Balanced second
  • Hardened only after testing
  • Exceptions only when you know why

If something breaks

  1. Check the query log
  2. Find the exact blocked domain
  3. Confirm it is necessary
  4. Add a narrow allowlist entry
  5. Re-test the site or app
  6. Keep notes so you remember why the exception exists

If you want to use Hagezi

  • Pick one list level
  • Use it on one profile first
  • Test for a few days
  • Add targeted exceptions only when required
  • Do not enable everything at once

If the config feels messy

  • Remove the least useful rule
  • Simplify the profile
  • Reduce the number of exceptions
  • Keep the setup boring and stable

A DNS config should help you browse, not turn every website into a debugging session.