Home › Gap checks
I check for gaps
After a local rule exists, I assume it is incomplete until I can say which family of addresses and which apps it never sees. This is maintenance thinking, not a claim that I tested your network. If a check would require bypass instructions, I describe the gap and stop.
I separate name blocks from address blocks
DNS is the phone book. A filter that sinks a name still fails if software already knows the numeric address, or if a new name points at the same service. IPv4 and IPv6 are two address families. A hosts line or a firewall rule written only for IPv4 can leave the IPv6 path open on a network that has both. I do not know whether your ISP assigns IPv6; many do, and many home routers show it in a status page you can read without changing anything.
| Layer | Typical miss | Honest check |
|---|---|---|
| DNS | A second resolver, a VPN, or DNS-over-HTTPS inside one browser. | See which resolver the device claims to use, on home Wi-Fi and on cellular data. Do not “test” by hunting new gambling names. |
| IPv4 | A hard-coded address that never asks DNS. | Note that name-only rules cannot see it. Closing it needs an address rule you are willing to maintain. |
| IPv6 | A block written only as an IPv4 hosts line. | Look for an IPv6 address on the same interface. If one exists, a v4-only rule is unfinished. |
| Page script | JavaScript that hides links but still allows navigation. | Treat it as decoration. Prefer a request block, as in the local build notes. |
I borrow a caution from OWASP
OWASP, the Open Worldwide Application Security Project, publishes long-standing guidance that client-side checks are not a security boundary. That guidance was written for people building websites, not for people limiting their own gambling. I still find the sentence useful: a control that runs where the person can edit it, disable it, or switch clients is a convenience, not an enforcement point. If you need a boundary you cannot casually remove, a browser add-on is the wrong tool, and a clinician or a support service is a more honest conversation than a stricter manifest.
I schedule a dull review
- After a system update, confirm the add-on is still loaded and the hosts file, if you use one, still contains your lines.
- After adding a browser, repeat the local load. New browsers arrive without your rules.
- After a router replacement, assume DNS filtering was not copied across.
- If a needed site breaks, remove the narrow rule that caused it. Do not disable the entire idea and then forget why.
- If you feel pulled to “just check” a blocked name, stop the technical review and use the support path named on the boundary page, including the National Council on Problem Gambling.
I will not describe how to slip past a block
People ask for mirror sites, new domains, and app clones. I do not list them, and I do not explain how to find them. A gap check that becomes a scavenger hunt has changed sides. The useful question is which of your own devices still has an unconfigured browser, not which operator renamed a host.
I accept that some gaps stay
A determined person with another device will get online. I would rather admit that than sell a false seal. The value of the check is fewer accidental openings on the machines you actually configured, plus a written record of what you chose not to trust. Pair this with the local build and the boundary definition.