A tamper-resistant, system-wide DNS content filter for Linux.
Brought to you by Shell Ninja — who didn't trust themselves with sudo rights.
Blocker is a single C++ binary that filters adult content at the DNS level, system-wide. No browser extension, no per-app config — it intercepts DNS and redirects blocked sites before the browser even connects. Rebooting doesn't help the user bypass it either; the unlock timer resets on every restart.
- Runs a local DNS proxy on
127.0.0.1:53— blocked names resolve to loopback, everything else is forwarded to Cloudflare Families (1.1.1.3) - Blocked sites get a
302redirect to a YouTube video instead of an error page - Rules are stored scrambled in a root-only vault — no readable file to delete
- A systemd watchdog restarts the daemon within 1 second if it's killed;
systemctl stop blockeris refused - Any change that loosens protection (removing rules, stopping the service, uninstalling) requires a password and a 72-hour waiting period. The timer resets on every reboot.
- Linux with systemd (Debian, Ubuntu, Fedora, Arch, etc.)
g++≥ 9 (or clang ≥ 10) and GNUmake- No third-party libraries
Clone the repo and run the setup script. That's it — it builds, installs, and verifies everything in one step.
git clone https://github.com/shell-ninja/blocker.git
cd blocker
chmod +x setup.sh
./setup.shFor the full accountability setup (let someone else hold the password):
./setup.sh --random-password --delay-hours 72The script will:
- Check that your system meets the requirements
- Build the binary (
build/blocker) - Ask for confirmation
- Enable and start the systemd service
- Verify that blocking works
| Option | What it does |
|---|---|
--random-password |
Generate a 24-character password (print once, hand to someone else) |
--delay-hours N |
Hours to wait after unlock-request before changes are allowed (default 24) |
--mode password|delay|both |
How changes are gated. both = password + waiting period |
--no-firewall |
Skip the nftables DNS-bypass rules |
--build-only |
Just compile, install nothing |
--upgrade |
Replace an existing install |
--dry-run |
Show what would happen without doing anything |
Tightening (blocking more) needs no password:
sudo blocker add badsite.com '*.ads' kw:gambling
sudo blocker add --file ~/extra-list.txtLoosening (allowing something) needs the password and the unlock window:
sudo blocker unlock-request # starts the countdown
# wait the configured delay...
sudo blocker allow example.com # allowed once the window opensCheck if a site is blocked and why:
sudo blocker check somethingfishy.net
sudo blocker list # show all current rules (needs unlock)./setup.sh --upgradeThis stops the running daemon (needs the unlock password/window), installs the new binary, and keeps your password, config, and rules.
sudo blocker uninstallNeeds the unlock password and the delay window, same as any other loosening.
