Android Private DNS outside the family resolver
How common it is: not established as a child bypass. Android’s Private DNS capability is documented first-party.
Detection
Router DNS logs lose queries from the device even though Internet activity continues.
Fix (technical)
Android documents the EN path as (siehe ui_strings_ref). A corresponding DE path was not accepted into this report because no successfully opened German first-party page was available for verification…
Fix (relational)
Explain that DNS filtering is being used to reduce accidental exposure, not as invisible surveillance. Invite the child to report incorrectly blocked domains.
Residual risk
Application-specific encrypted DNS and VPN tunnels can remain separate from the system resolver.
Sources
-
android-private-dns
-
rfc9490-mten