A decision may use the full Uniform Resource Locator (URL), domain, hostname, path, category, reputation, age, ownership, or observed campaign links, depending on what the enforcement point can see.
Filtering can run in a browser, endpoint agent, proxy, secure web gateway, or domain-name control. With encrypted web traffic, an intermediary may see only the domain unless it terminates Transport Layer Security (TLS), while Domain Name System (DNS) filtering generally acts on domains rather than full URLs.
Key points
Policy designUse categories and reputation as inputs to documented, risk-based rules, with narrower exceptions for legitimate sites that are misclassified or newly established.
Context and actionConsider user, device, destination, request method, and business purpose; warning, isolation, or restricted access may be more suitable than a universal block.
OperationsRecord decision reasons, review overrides, refresh threat and category data, and protect browsing records because they can reveal sensitive interests and activity.
Important limitationClassifications become stale, shared hosting mixes unrelated services, redirects obscure final destinations, and newly created sites lack history. An allowed URL is not a safety verdict, and a blocked URL is not proof of maliciousness.