VerifyFiltering — home VerifyFiltering — home
Learn / Compliance

How the VerifyFiltering Scanner Works

"We have a content filter" and "our content filter actually blocks what it's supposed to" are two different claims — and the gap between them is exactly what gets schools, libraries, and public WiFi providers into trouble during a compliance audit. A filter can be installed, configured, and still fail silently: a misapplied policy, a bypassed device, a rule that quietly stopped working after an update. You don't find that out from your filtering vendor's dashboard. You find it by testing from the outside, the way an auditor would.

That's what the VerifyFiltering scanner does. Here's what it actually checks, how to read your results, and what to do with them.

What the scan checks

When you run a scan, we test how your network resolves a set of domains that are known to fall into specific content categories — the kind of categories regulators actually care about, like adult content, gambling, and known-malicious or command-and-control infrastructure. If your filter is doing its job, those lookups should be blocked or redirected before they ever resolve. If they resolve cleanly, that's a gap.

Nothing is installed on your network to run a one-time scan, and no traffic is intercepted — you run it from a device already sitting behind your filter, the same way a real visitor would.

Choosing a standard

Different regulations care about different things, so before you scan, you pick the standard you need to demonstrate compliance with:

StandardWho it's for
CIPAUS K-12 schools and libraries, typically tied to E-rate funding
UK Safer InternetUK schools, under Department for Education filtering guidance
Friendly WiFiPublic venues — retail, hospitality, transport — offering guest WiFi
CustomAnyone testing against their own internal acceptable use policy

Each standard maps to a specific set of content categories. You don't need to know the exact list — pick the standard that applies to you, and the right categories are tested automatically.

Reading your results

Results come back on two levels. Each category gets its own result, not just one combined score — that matters, because "mostly compliant" isn't a useful answer to give an auditor. A school that blocks adult content perfectly but has a wide-open gap on malicious domains has a real, specific problem, and needs to know which one it is.

  1. Blocked — every domain we tested in that category was blocked.
  2. Partially blocked — some of the tested domains in that category were blocked, some weren't.
  3. Not blocked — none of the tested domains in that category were blocked.

On top of the per-category breakdown, the scan as a whole gets a single Pass or Fail. It's a Fail if even one category isn't fully blocked — so the overall badge tells you whether you're compliant right now, and the per-category table tells you exactly where to go fix it if you're not.

A category that isn't fully blocked doesn't necessarily mean your filter is broken outright — it often means that category's rules weren't part of your original configuration, or drifted after a policy change. Either way, the per-category result tells you exactly where to go look.

If something fails

Check that category's rules in your filtering solution's own admin console first — most fails trace back to a category that was simply never enabled, not a deeper problem. Re-run the scan after you make a change to confirm it took effect.

The PDF report

Every scan can generate a PDF report — a dated, per-category breakdown you can hand to an auditor, attach to an E-rate application, or just keep on file as evidence you checked. It's built to be the kind of document someone outside your organization can read without needing you in the room to explain it.

One scan vs. ongoing monitoring

A free scan tells you the truth right now. It doesn't tell you if something changes next month — a filtering rule that gets edited, a device that falls out of policy, a new gap that opens after a vendor update. For that, the paid plans add scheduled, ongoing checks across every device you monitor, so a new gap shows up on your dashboard instead of during your next audit.

Curious what a scan actually finds on your network? Run a free scan — it takes a few minutes, and you'll walk away with a real answer instead of an assumption.

Compliance & Filtering

Guides on network content filtering, the standards that regulate it, and how to verify your own network actually meets them.

Standards We Test

  • CIPA
  • UK Safer Internet
  • Friendly WiFi
  • Custom Profiles

VerifyFiltering Monitoring

Move past a one-time scan — scheduled, ongoing checks across every device you manage, with alerts when something changes.

See plans →

CleanBrowsing

VerifyFiltering is a CleanBrowsing service. CleanBrowsing itself offers fast, privacy-first DNS filtering you can deploy directly.

Explore CleanBrowsing →

Contact Us

Have an idea for an article, or see something missing? Email support@noc.org.