Custom allow / deny
Your own list, on top of the categories and threat feeds. Rules belong to one policy — the header tells you which one ("Rules for: Guest Wi-Fi"); switch policy on the Policy tab.
Add one rule
- Go to Secure Access → DNS Filtering → Custom rules.
- Type the domain.
example.commatches the domain and all its subdomains.*.example.commatches only the subdomains, not the bare domain.
- Choose Block or Allow.
- Click Add.
Each rule appears in the list below with an ALLOW or BLOCK badge and a Remove link.
Import a list
Click + Bulk import (paste a list):
- Paste your domains into the textarea — one per line, or comma-separated.
- The action is whatever is set in the Block / Allow select above the box — the helper text reminds you which one is active.
- Click Add all.
You get a summary like "Added 184, skipped 12 duplicate(s)". Up to 2,000 domains per import; duplicates are skipped silently.
Which rule wins
An Allow rule beats a category block — that is how you unblock a single business tool inside a category you otherwise want closed. It does not override malware and phishing feeds: if a domain is a known threat, it stays blocked.
Worth doing
- Allow the SaaS tools your team actually uses before you switch a broad category on.
- Block the specific domains that show up repeatedly in Most blocked with reason Category if you want them stopped even outside the schedule window.
- Keep an allow rule list per policy — guests rarely need the same exceptions as staff.
Use Check a domain on the Overview tab to see exactly which of your rules matched before you add another one. Two overlapping rules are the most common reason a "block" appears not to work.