A lookup is a device asking for a name. It is not a minute and not a byte, and it is not proof anyone looked at anything: apps ask for names in the background all day. Blocked means the name was not answered (or was answered with the portal's address). Nothing here can see inside HTTPS, and a device on a VPN or DNS-over-HTTPS is invisible to all of it.
Counts of lookups, not of people or of visits. One page can ask for an adult domain many times through an embedded advert; one child can ask once. Open the log before drawing a conclusion, and treat what you find as the start of a conversation.
"Adult" and "gambling" are the names of the blocklists that matched (OISD NSFW and HaGeZi Gambling, as AdGuard is set up). A blocklist can be wrong about a site. Rows from before 2026-09-02 have no recorded reason, so they can only ever show as "blocked".
DNS lookups per hour today, stacked by the person whose device asked. Hours follow the gateway's clock; the current hour is part-finished.
Unattributed lookups come from devices not yet assigned to anyone. Name them on the Devices tab and they start counting for that person.
| When | Nova | Rangi | Piper | Ari | Marama | Unattributed, and Callum, Dorothy | Blocked | Total |
|---|---|---|---|---|---|---|---|---|
| 00:00 | 0 | 10 | 0 | 0 | 0 | 0 | 10 | 10 |
| 01:00 | 0 | 41 | 0 | 0 | 0 | 0 | 41 | 41 |
| 02:00 | 0 | 60 | 0 | 0 | 0 | 0 | 59 | 60 |
| 03:00 | 0 | 30 | 0 | 0 | 0 | 0 | 30 | 30 |
| 04:00 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| 05:00 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| 06:00 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| 07:00 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| 08:00 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| 09:00 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| 10:00 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| 11:00 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| 12:00 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| 13:00 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| 14:00 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| 15:00 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| 16:00 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| 17:00 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| 18:00 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| 19:00 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| 20:00 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| 21:00 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| 22:00 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
| 23:00 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
Blocked lookups per hour, by the reason AdGuard gave. Adverts and trackers are usually most of it and mean nothing about the person; the rest is what the filter is for.
| When | Portal | Total |
|---|---|---|
| 00:00 | 10 | 10 |
| 01:00 | 41 | 41 |
| 02:00 | 59 | 59 |
| 03:00 | 30 | 30 |
| 04:00 | 0 | 0 |
| 05:00 | 0 | 0 |
| 06:00 | 0 | 0 |
| 07:00 | 0 | 0 |
| 08:00 | 0 | 0 |
| 09:00 | 0 | 0 |
| 10:00 | 0 | 0 |
| 11:00 | 0 | 0 |
| 12:00 | 0 | 0 |
| 13:00 | 0 | 0 |
| 14:00 | 0 | 0 |
| 15:00 | 0 | 0 |
| 16:00 | 0 | 0 |
| 17:00 | 0 | 0 |
| 18:00 | 0 | 0 |
| 19:00 | 0 | 0 |
| 20:00 | 0 | 0 |
| 21:00 | 0 | 0 |
| 22:00 | 0 | 0 |
| 23:00 | 0 | 0 |
"Sent to the portal" is a child whose internet was off (time up, bedtime, or a block): every name their device asked for was answered with the portal's address, so a hundred of those is one open browser, not a hundred attempts.
The names each person's devices asked for most. Coloured where the site is in a metered category (gaming, video, social); grey is everything else, including the CDNs and app back-ends that make up most of any device's lookups. Click a name to see every lookup of it.
Open the log for a site: youtube.com rbxcdn.com googlevideo.com roblox.com snapchat.com wikipedia.org spotify.com bbc.co.uk cdninstagram.com netflix.com
| Site | Category | Lookups | Blocked |
|---|---|---|---|
| youtube.com | video | 18 | 18 |
| rbxcdn.com | gaming | 12 | 12 |
| googlevideo.com | video | 10 | 10 |
| roblox.com | gaming | 10 | 10 |
| snapchat.com | social | 9 | 8 |
| wikipedia.org | schoolwork | 9 | 9 |
| spotify.com | audio | 7 | 7 |
| bbc.co.uk | video | 5 | 5 |
| cdninstagram.com | social | 5 | 5 |
| netflix.com | video | 4 | 4 |
Metered minutes per day for each child, from the firewall counters (METERING.md). A minute counts when the device moved real traffic to that category in that minute, so a backgrounded app does not rack up time. Music, schoolwork and messaging are never metered. The meter works by day, so today is one column.
Nova
gaming 19 min · video 28 min · social 0 min
| Day | Gaming | Video | Social |
|---|---|---|---|
| Thu 3 Sep | 19 | 28 | 0 |
Rangi
gaming 41 min · video 41 min · social 10 min
| Day | Gaming | Video | Social |
|---|---|---|---|
| Thu 3 Sep | 41 | 41 | 10 |
Piper
gaming 25 min · video 44 min · social 39 min
| Day | Gaming | Video | Social |
|---|---|---|---|
| Thu 3 Sep | 25 | 44 | 39 |
These are the same figures as the Trends tab. They are measured, not derived from the lookup counts above, and the two must not be added together. A child with no metered minutes in the window (a visiting child is never metered) is not listed.
Every lookup in the window, newest first. Pick a person, then a site, and read every time a device asked for it. Genkan keeps domains only, never what was on a page, and keeps them for thirty days.
Showing: person: Dorothy · site: scorecardresearch.com, today.
| When | Person | Device | Name asked for | Category | What happened |
|---|
A row is one question from one device: "what is the address of this name?" It is not a page view, not a minute, and not proof a person did anything. Blocked means the name got no real answer. Times follow the gateway's clock. What this cannot see: anything inside HTTPS, anything a device sends through a VPN, Cloudflare WARP or its own DNS-over-HTTPS, and anything on mobile data.
Genkan is a family conversation aid, not a surveillance console. Domains only, thirty days, all of it in the house.