Domain Blocking

Configure which domains are blocked by the Browser Guard.


Overview

The Browser Guard blocks access to domains known for data exfiltration. Domains are managed via the policy's browser guard configuration.

Default Blocked Domains

BlueSentinel ships with 35+ pre-configured blocked domains:

Cloud Storage:

  • drive.google.com
  • dropbox.com
  • onedrive.live.com
  • mega.nz
  • wetransfer.com
  • box.com

Code Sharing:

  • pastebin.com
  • hastebin.com
  • gist.github.com (file uploads)

AI Tools:

  • chat.openai.com (ChatGPT)
  • claude.ai
  • bard.google.com

Messaging:

  • web.whatsapp.com
  • web.telegram.org
  • discord.com
  • slack.com (file uploads)

Social Media:

  • facebook.com (file sharing)
  • twitter.com
  • linkedin.com

Adding Custom Domains

  1. Navigate to Policies → select your policy
  2. Edit the Browser Guard section
  3. Add domains to the Blocked Domains list
  4. Save — changes push to agents on next heartbeat

Domain Matching

Domains are matched by suffix. Blocking dropbox.com also blocks:

  • www.dropbox.com
  • dl.dropbox.com
  • content.dropbox.com

Per-User Exceptions

If specific users need access to a blocked domain:

  1. Navigate to Exceptions
  2. Create a whitelist exception for the Browser Guard
  3. Add the allowed domains
  4. Set an optional time window (e.g., allow for 24 hours)