Protection → Services and safe search (GET|PUT /api/v1/blocked-services, PUT /api/v1/safe-search, administrators).
A service is blocked by its name, without knowing its domains: Warda keeps
its own list of about 45 services (social networks, video, games,
messaging, music, AI, shopping, dating; internal/services), each with its
domains and their subdomains. A block is given for the whole network
(all), a profile (profile: child, teen, adult, none), a group, a person
or a device; a device gets the blocks of the network, of its profile, and
of its person or its group. A blocked name is answered like a list block
(0.0.0.0, reason service in the query log and the reports), before the
rules and the pauses: a personal allow does not open it. The box itself is
never blocked. The blocks are in the backups and follow the people, groups
and devices (removed with them).
Safe search answers the search engines with their safe version: Google
(forcesafesearch.google.com, every country domain of the search), Bing
(strict.bing.com), DuckDuckGo (safe.duckduckgo.com), Yandex
(familysearch.yandex.ru) and Pixabay; and YouTube with its restricted mode
(restrict.youtube.com). The name asked gets the addresses of the safe
name (no CNAME), and an empty answer for the other types (HTTPS, SVCB), so
that the browsers use them. Two settings by profile, search and
youtube, on for every profile by default; not during a pause of the
filtering, never for the box itself.