๐Ÿ“– Guide
๐ŸŽ› Control
โš™๏ธ Profiles
โฐ Schedule
๐Ÿ› ๏ธ Advanced
๐Ÿ›ก๏ธ Safety

๐Ÿ  OpenDNS Home Remote Control

Control what websites are accessible on your home Wi-Fi โ€” from any phone or computer. Block social media, games, adult content, or everything, and switch back with one tap.

How it works: This tool uses your free OpenDNS account to filter websites at the DNS level. Every device on your home network is affected automatically โ€” no app needed on individual devices.

What you need (all free)

Step 1
Create a free OpenDNS account
Go to opendns.com โ†’ Get Started Free โ†’ OpenDNS Home. Sign up with your email. No credit card required.
Step 2
Change your router's DNS servers

Log in to your router (usually 192.168.1.1) and find DNS Settings. Replace existing DNS numbers with:

Primary DNS208.67.222.222 Secondary DNS208.67.220.220

Where to find DNS settings

RouterWhere to look
Most routers192.168.1.1 โ†’ WAN / Internet / DNS
BT / Virgin192.168.1.254 โ†’ Advanced โ†’ DNS
Sky192.168.0.1 โ†’ Security โ†’ Advanced โ†’ DNS
ASUS192.168.1.1 โ†’ WAN โ†’ Internet Connection โ†’ DNS
TP-Link192.168.0.1 โ†’ Advanced โ†’ Network โ†’ Internet
Netgearrouterlogin.net โ†’ Advanced โ†’ Setup โ†’ Internet
Swisscom / SunriseSome ISP boxes block DNS changes โ€” connect a second router between the box and your devices
Step 3
Register your home network with OpenDNS

Log in at dashboard.opendns.com. It will detect your IP and ask you to register it. Click Add This Network.

Dynamic IP note: Download the free OpenDNS Updater app on one always-on computer to keep your IP registered automatically.
Step 4
Control your network from here
Click the Control tab, log in with your OpenDNS credentials, and tap any profile to switch your network instantly.

Filtering profiles

๐Ÿ›ก๏ธ Block Ads & Adware
Blocks 2 categories: Adware, Advertisements
๐ŸŒ Everything Open
No category filtering
๐Ÿ‘ถ Kids Mode
Blocks 12 categories: Adware, Advertisements, Adult Themes, Pornography, Sexuality, Nudity, Lingerie/Bikini, Drugs, Weapons, Hate/Discrimination, Tasteless, Gambling
๐Ÿ“š Study Mode
Blocks 12 categories: Adware, Advertisements, Social Networking, Games, Video Sharing, Movies, Television, Music, Radio, Photo Sharing, Instant Messaging, Chat
๐Ÿ“ต No Social Media
Blocks 3 categories: Adware, Advertisements, Social Networking
๐ŸŒ™ Evening Mode
Blocks 10 categories: Adware, Advertisements, Video Sharing, Social Networking, Games, Movies, Television, Music, Radio, Photo Sharing
๐Ÿ›Œ Bedtime Mode
No category filtering ยท Also blocks: roblox.com, youtube.com
๐Ÿ“ต No Media
Blocks 5 categories: Adware, Advertisements, Social Networking, Video Sharing, Games
๐Ÿ”’ Full Lockdown
Blocks all 59 categories
๐Ÿ‘ฉ Wife Mode
Blocks 2 categories: Adware, Advertisements ยท Also blocks: facebook.com
๐Ÿ‘จ Husband Mode
Blocks 7 categories: Adware, Advertisements, Pornography, Adult Themes, Sexuality, Nudity, Lingerie/Bikini
๐Ÿซ Education Only
Blocks all categories except: Educational Institutions, Research/Reference
๐Ÿง’ KinderGPT Only
Blocks all 59 categories ยท Always allows: kindergpt.com
Privacy: Your credentials are used only to contact OpenDNS. They are held in your browser session and discarded when you close the tab โ€” never permanently stored on this server unless you set up a schedule (see the Schedule tab for details).
โš ๏ธ Important: OpenDNS is a useful first layer of protection but it is not foolproof โ€” a motivated teenager can bypass it. Read the ๐Ÿ›ก๏ธ Safety & Limitations tab to understand what it does and does not protect against, and what additional measures to put in place.

๐Ÿ›ก๏ธ Safety & Limitations

Honest assessment: OpenDNS filtering is a useful first layer of protection โ€” but it is not a complete solution on its own. A motivated teenager can bypass it in under a minute. Understanding how it can be defeated helps you decide what additional measures to put in place.

How it can be bypassed

Easiest bypass โ€” no technical knowledge needed
Switch to mobile data
OpenDNS only filters your home Wi-Fi. Any smartphone on 4G or 5G goes through the phone network instead, bypassing your router entirely. This is the most common workaround and works instantly on any phone with a SIM.
Easy bypass โ€” 30 seconds
Change DNS on the device
In the Wi-Fi settings on any phone or laptop, you can type in a different DNS address (such as Google's 8.8.8.8 or Cloudflare's 1.1.1.1). This takes about 30 seconds, leaves no trace, and completely bypasses OpenDNS.
Easy bypass โ€” free app
Use a VPN
Dozens of free VPN apps are available in the App Store and Google Play. A VPN encrypts all traffic and routes it through its own servers, bypassing DNS filtering completely. Many work with a single tap.
Easy bypass โ€” browser setting
DNS over HTTPS (DoH)
Firefox uses Cloudflare's encrypted DNS by default, bypassing your router's DNS entirely. Chrome can be configured the same way. This means filtering can be bypassed without any app or VPN โ€” just by using a different browser or changing one setting.
Easy bypass
Connect to a friend's hotspot
Any device can connect to another phone's mobile hotspot instead of your home Wi-Fi. OpenDNS has no involvement in that connection.

What actually works

OpenDNS is most effective for younger children who do not yet know about these workarounds. For older children and teenagers, it works best as one layer among several.
Strong countermeasure
Screen Time (iPhone) / Digital Wellbeing (Android)
Built into the phone's operating system and protected by a separate passcode. Controls which apps can be installed (blocking VPN apps), limits screen time, and filters content at the device level โ€” works on both Wi-Fi and mobile data. This is the most effective single measure for smartphone use.
Strong countermeasure
Parental controls on the mobile network account
EE, O2, Vodafone, Three, and most other carriers offer free parental controls that apply at the network level โ€” filtering mobile data as well as Wi-Fi, and blocking adult content even on 4G/5G. Set up through your online account or by calling the carrier.
Router-level countermeasure
Force all DNS through your router
Some routers can be configured to intercept all DNS traffic on port 53 and redirect it to your chosen DNS โ€” meaning even if a device manually sets a different DNS address, the router overrides it. This blocks the "change DNS on device" bypass. Check your router's firewall or DNS interception settings.
Router-level countermeasure
Block VPN protocols at the router
Most home routers can block common VPN protocols (OpenVPN, WireGuard, L2TP). Combined with app installation controls through Screen Time, this makes VPN bypass significantly harder.
The bottom line: Use OpenDNS for home Wi-Fi filtering, Screen Time or Digital Wellbeing on the phone itself, and your carrier's parental controls for mobile data. All three together provide meaningful protection. Any single layer alone can be bypassed.

No account? Read the guide โ†’

All Profiles

Always Authorised Domains
These domains are never blocked, regardless of which profile is active. Use this for sites that should always be accessible on your network.
Sign in on the Control tab to manage always-authorised domains
Browser Schedules tab must be open
No server needed. These rules are stored on this device only โ€” nothing is sent to any server. The tab must be open and you must be signed in for them to fire. When a scheduled window ends, the network automatically switches back to Everything Open.
Add Browser Rule
Server Schedules requires own server & cron job
โš ๏ธ Own server required. Server schedules run 24/7 even when no browser is open โ€” but they require you to download this tool and host it on your own web server with a cron job. They are not available on clivethompson.com to other users. See the Advanced tab for setup instructions.
No server schedules set
Add Server Rule

๐Ÿ› ๏ธ Advanced Users Only

This section is for people who have their own web server or web hosting account.

If you are just visiting this tool on clivethompson.com to control your home filter, you do not need any of this โ€” everything on the Control, Profiles, and Schedule tabs already works for you as-is.

Who this is for: You have a web hosting account (like SiteGround, Namecheap, Bluehost, etc.) or a VPS, and you want to run your own private copy of this tool โ€” with full 24/7 automatic scheduling that works even when no browser tab is open.

Part 1 โ€” Download & Install Your Own Copy

What you get
A single PHP file โ€” the entire tool in one download
No database, no config files, no installation wizard. Just one file you upload to your server and it works.
Requirements
What your server needs
Any web host running PHP 7.4 or newer with cURL enabled. This is standard on virtually all shared hosting plans โ€” if your host runs WordPress sites, it can run this too.
How to install
Three steps

1. Download the file using the button below.

2. Upload it to your web server using FTP (or your host's file manager).

3. Visit it in your browser โ€” for example yoursite.com/opendns-remote.php โ€” and it will work immediately.

๐Ÿ“„ opendns-remote.php

Single file ยท PHP 7.4+ ยท No database

โฌ‡๏ธ Download Free

Created by Clive Thompson ยท Free to use and modify

Part 2 โ€” Setting Up 24/7 Automatic Scheduling

This is the part that makes your schedules fire on their own โ€” even when you are asleep and no browser tab is open.

The problem it solves
Why schedules need a cron job
A normal webpage can only do things while you are looking at it. The moment you close the tab, it goes completely quiet and cannot do anything on its own. So if you set a schedule to switch on Kids Mode at 8pm, something else needs to check the clock and act on it for you.
What a cron job is
An alarm clock on your web server
Your web server runs 24 hours a day, 7 days a week, even while you sleep. A cron job is simply an alarm you set on that server. You tell it: "every minute, run this small task." That task visits a special address on your site, which wakes the PHP file up to check whether any schedule should be active right now โ€” and if so, logs into OpenDNS and switches the filter automatically.
How to set it up
Add one line in your hosting control panel

1. Log in to your web hosting control panel (most hosts call it cPanel).

2. Find the section called Cron Jobs.

3. Set the frequency to Every Minute (usually shown as five asterisks: * * * * *).

4. Paste this as the command, replacing the URL with your own server address:

* * * * * curl -s "https://yoursite.com/opendns-remote.php?cron=1&key=ODNS2026CRON"

The five asterisks mean every minute, every hour, every day. The ?cron=1 tells the PHP file this is the automatic check. The key=ODNS2026CRON is a secret password so random people on the internet cannot trigger it.

5. Save the cron job. That is it โ€” the server handles everything from this point on.

Without the cron job
Schedules do nothing on their own
Your rules will be saved, but nothing will ever check them. They will sit there doing nothing until you open the page yourself and manually switch profiles. The cron job is what makes them truly automatic.

Part 3 โ€” Security

Protect the schedule file
Stop others from downloading your credentials

When you save a schedule, this tool stores your OpenDNS password in a file called opendns-schedules.json so the cron job can log in automatically. By default, anyone who knows the filename could download it. Prevent that by creating a file called .htaccess in the same folder as the PHP file, containing:

<Files "opendns-schedules.json">
  Order allow,deny
  Deny from all
</Files>

This tells your web server: never serve that file to any browser โ€” ever. Most hosting control panels let you create files directly; alternatively upload the .htaccess file via FTP.

Part 4 โ€” Customising Profiles & the Cron Key

Built-in profiles
Edit them in the PHP file
Open the downloaded file in any text editor (Notepad, TextEdit, VS Code). Near the top you will find an array called $profiles. Each profile lists the categories it blocks (cats) and any specific websites (domains). The full list of available category names is in the $catIds array just below it.
Cron key
Change it to something private
The default key is ODNS2026CRON. Find the line near the top of the file that reads define('CRON_KEY', 'ODNS2026CRON'); and change it to anything you like. Then update the URL in your cron job to match your new key.