Four layers, in the order worth doing them — from a setting you can change in thirty seconds to blocking pages nobody has reported yet.
“Blocking fake websites” sounds like one setting. It is really four different mechanisms, each catching a different kind of site, and they are worth applying in order of effort.
Chrome checks the sites you visit against Google’s list of known dangerous pages. Standard protection does this using a locally cached list; Enhanced protection checks in real time and assesses pages Google has not classified yet.
Open Chrome settings, go to Privacy and security, then Safe Browsing, and select Enhanced protection. It takes half a minute and it meaningfully raises your floor.
The trade-off is stated in the setting itself: Enhanced protection shares more browsing data with Google. That is a genuine decision, not a formality, and it is worth reading the description before choosing.
DNS filtering blocks a site before your browser ever connects, by refusing to resolve the address. Because it works below the browser, it protects every application on the device and every browser you use.
Free options include Cloudflare’s 1.1.1.2 and Quad9’s 9.9.9.9, both of which block known malicious domains. You can set these on a single device or on your home router, which covers everything on the network including phones and smart devices.
The limitation is the same as any list-based approach: it blocks domains already identified as malicious. A domain registered an hour ago resolves normally.
Both layers so far depend on a site having been reported. That is not a criticism — it is how lists work — but it is why the next layer exists.
This is the layer that addresses pages nobody has reported. Instead of checking an address against a list, a live-analysis extension assesses the page itself as it loads: what it looks like, whether it is impersonating a brand, whether it is asking for credentials it should not be asking for.
It is the only approach that can flag a phishing page on the day it is created, which matters because most phishing sites are gone within twenty-four hours. Look for one that explains its verdicts rather than silently blocking, so you learn the signals rather than simply obeying a warning.
Everything above is per-device and reversible by the person using it. For a business, the equivalent controls exist as policy.
URL blocklists by policy. Chrome Enterprise supports URLBlocklist and URLAllowlist policies, set through Microsoft Intune, Group Policy or Google Workspace admin. Useful for categories you want closed off entirely, and for specific domains after an incident.
Force-installed extensions. The same management tools can install a security extension across every device so it cannot be removed by the user. This is how most organisations deploy protection that needs to actually stay deployed.
Enhanced Safe Browsing by policy. You can enforce the setting from step one rather than hoping people enable it themselves.
Two honest limitations, worth knowing.
First, none of this stops a convincing message from arriving. It reduces the chance that clicking ends badly, which is different from removing the decision.
Second, blocking is device-bound. A link opened on a personal phone rather than the laptop you configured has none of these layers. If protection matters, it needs to exist wherever the person actually opens things — which increasingly means the phone.
Enhanced Safe Browsing first, because it is free and immediate. DNS filtering second, because it covers the whole device. Live analysis third, because it covers what the first two structurally cannot. Policy last, and only if you are responsible for other people’s devices.
SafeToOpen checks links in your browser and inbox in real time — free to start.
See plans →