Relution Decon (content filter)
Starting with version 26.5, Relution enables the setup of a DNS-based content filter for macOS devices. This feature ensures a secure and focused internet experience by restricting access to selected websites and apps. With AI-powered content categorization, Relution Decon also provides a comprehensive parental control filter with advanced configuration options.
What is Relution Decon?
Relution Decon is an AI-powered add-on for macOS that filters content in real-time, creating a safe digital environment. Using DNS-based content control, Decon blocks unwanted websites and apps, allowing users to work and learn in a protected, distraction-free space.
Relution Decon uses a DNS proxy to forward all requests to the Decon server. Websites are classified and either allowed or blocked according to policy rules. All data transfers are SSL-encrypted, ensuring user activities remain secure.
Decon App
The Decon app is automatically deployed on macOS devices when the policy is installed. It monitors device DNS requests and ensures that only approved content is accessible.
App features:
- Activates a system-wide DNS proxy, which cannot be disabled by the user
- Displays the current status of Relution Decon
- Provides insight into blocked websites and applied filter categories
VPP setup in Relution →
Relution Decon in the Apple App Store →
Decon Policy
In the device policy, click Add → Relution Decon.
This policy automatically installs the Decon app on the devices, where it acts as a proxy for all DNS requests.
Unlike on iOS, macOS additionally requires a Managed App Configuration → and the approval of the system extension — Relution sets up both automatically.
Policy configuration is completed upon publishing.
On macOS, Relution Decon is only available for devices with the enrollment type Device enrollment. With User Enrollment →, the configuration cannot be added.
Policy configuration hierarchy (highest to lowest priority)
- Allow Apps
- Block Apps
- Allow Websites
- Block Websites
- Blocked Categories
Decon in Relution Teacher
Decon can be selected and managed in class profiles with Relution Server 5.32.0 and Relution Agent 5.19.0. Student devices must have a Decon policy assigned.
Note: For the duration of the lesson, the otherwise valid Decon configuration is overwritten.
Category Classification
Relution Decon automatically assigns each website to a category. Administrators can define which categories are blocked:
| Category | Description | Examples |
|---|---|---|
| Not suitable for minors | Sites inappropriate for youth | Pornography, Violence, Weapons, Drugs, Gambling, Adult Entertainment, Adult Shopping, Dating, Google Safe Search |
| Advertising | Advertising websites | Ad providers |
| Communication | Communication services | Email, Messenger, (Video) Calling |
| Social Media | Social media content | Facebook, Instagram, TikTok, etc. |
| Entertainment | Entertainment websites like streaming or games | Movies, Games, Videos |
| Music | Music streaming services | Spotify, Tidal, etc. |
| News | News and magazines | News, Weather |
| Shopping | Online shops (excluding adult content) | Amazon, eBay, etc. |
| Work | Work-related websites | Office, File Sharing, Intranet |
| Education | Learning websites | Wikipedia, Google Scholar |
| Generative AI | AI-specific websites | ChatGPT, Perplexity.ai, etc. |
| Phishing | Potential phishing websites | Potential scams, Data theft |
| Other | Everything else | Remaining sites |
Allow and Block Lists
- Allow / Block Websites: Specific domains can be allowed or blocked independently of categories. Only the domain should be specified, not the path.
- Allow / Block Apps: Internet access for apps can be controlled specifically, while basic functions remain available.
Advanced DNS Configuration
Device DNS Servers: Alternative DNS servers can be configured if the Relution Decon DNS is unavailable. Fallback: Cloudflare Families DNS (1.1.1.3).
Relution Decon Server DNS: An alternative DNS server can replace the standard DNS on the Decon server. IP addresses (UDP) or DNS-over-HTTPS (DoH) such as Zero or Quad9 can be used.
Limitations
- Caching: Blocks and policy changes can take up to 1 minute to take effect.
- Path independence: DNS operates at domain level, subpages are not distinguished.
- App blocking: Only internet access is blocked, basic functions and cached content remain available.