---
title: Policy configuration
slug: policy-configuration
docTags: 
createdAt: 2026-01-14T08:22:25.784Z
---

## Overview

This section serves as a **logical map** to help you navigate the available protection modules. When you edit a policy, you are not presented with a single static dashboard. Instead, the system unlocks a specific set of **tabs in the top navigation bar**. The number and type of these tabs depend entirely on whether the policy is **Standard** (fully customizable) or **Restricted** (locked profile).

## If the Policy is "Standard"

Policies allow you to fully customize every aspect of the protection, including Malware, Content Filtering, and GeoBlocking.

When you open a Standard policy, you will access the **Advanced Configuration Dashboard**. The available protection modules are listed in the **Top Navigation Bar**.

### Understanding the Modules

| ### Modules                                   | ### Focus & Description                                                                                                |
| --------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- |
| [Malware](docId\:lZ2K1KsAg--lFSJI98pDL)       | Block ransomware, phishing, botnets, and other cyber threats at the DNS level.                                         |
| [Content](docId\:vfLPxujhSJVWrDCKiAYx0)       | Block websites based on categories such as Adult, Gambling, Social Media, or Games.                                    |
| [Applications](docId\:fKLjEG0UHZeYc26MkXmfH)  |  Block specific applications and services (e.g., TikTok, WhatsApp, Discord) completely.                                |
| [GeoBlocking](docId\:doJYyuB-hodGffRWAZ9sD)   | Block incoming and outgoing traffic to specific countries to reduce your attack surface.                               |
| [Exceptions](docId\:qOIz3D3hjLLYPQcWHto8O)    | Create granular rules to Allow (Whitelist) or Block (Blacklist) specific domains, overriding the general policy rules. |
| [SafeSearch](docId\:Tbx-coOecG3tkRyFIh9wg)    | Enforce "Strict Mode" on search engines (Google, Bing, YouTube) to hide explicit results.                              |
| [TLD Blocking](docId\:jK2FSGe8JNQsDHS3uI5Uq)  | Block entire Top-Level Domains (e.g., .xyz, .top, .ru) that are often associated with spam.                            |
| [Advanced](docId\:jKfplf7m9bg1Bu81bf4pZ)      | Configure system-level overrides and specific behavior settings.                                                       |
| [EDNS](docId:6gqQCCL7f3AfmtlGjvrof)           | Manage extension mechanisms for DNS to support advanced parameters.                                                    |

## If the Policy is "Restricted"

Policies are pre-configured profiles where the core security rules are locked to ensure consistent protection.

When you open a Restricted policy, the interface is significantly simplified. You will not see the full list of protection modules. Instead, the **Top Navigation Bar** only displays the specific settings you are allowed to modify locally.

### Understanding the Modules

| ### Modules                                 | ### Focus & Description                                                                                      |
| ------------------------------------------- | ------------------------------------------------------------------------------------------------------------ |
| [Exceptions](docId\:qOIz3D3hjLLYPQcWHto8O)  | Assign previously created exception groups (Allow Lists or Block Lists) to override specific blocking rules. |
| [SafeSearch](docId\:Tbx-coOecG3tkRyFIh9wg)  | Enable or disable strict search filtering for search engines.                                                |

