HTTPS web proxy or relay outside a domain-only block
How common it is: not established for minors in the reviewed primary sources. General blocking research recognizes that blocking efficacy depends on how easily the blocked resource can be reached through alternate path…
Detection
The expected blocked destination is absent from logs while an allowed intermediary service carries substantial browsing activity. This is only a clue; many relay-like services have legitimate uses.
Fix (technical)
Prefer device-side allow/deny policy or an allowlist for high-assurance cases rather than attempting to enumerate every possible relay. If an intermediary has no legitimate use in the household, it ca…
Fix (relational)
Ask whether the block is preventing a legitimate research, translation or accessibility task. Do not broadly prohibit useful intermediary services merely because the architecture could relay content.
Residual risk
New intermediaries appear continuously; encrypted tunnels and external networks remain.
Sources
- rfc7754-filtering