Force SafeSearch and turn OFF Google SSL queries

Google, Yahoo and other search engines offer a SafeSearch™ feature which blocks most adult images.
This option enforce the safesearch policies of the search engines.
The safesearch feature enforces safe searches for the following search engines:
AOL search, Bing, Excite, Foxnews, Google, Infospace, Live, Lycos, MSN,Yahoo and other less popular search engine.

By default, this option is enabled but your must pay attention about the HTTPS.

The web filtering is in charge to add tokens in each search request in order to enforce Safe Search.
When browsing to an SSL search engine (such as google) , the web filtering cannot see requests and is not able to add Safe search policy.
There is a tip when using Google search engine in order to disable the automatic Google SSL switch.


  • Click on Your Proxy on the top button
  • Select “Service Status” on the URL filtering section

24-04-2015 19-56-40


Ensure that the Safe Search option is enabled.

05-09-2014 01-41-09


  • Click on the “Turn OFF Google SSL searchs” link
  • Turn to green the “Turn OFF Google SSL searchs” option and click on apply.
  • This feature will work only if your using the proxy in connected mode.
    Using “transparent mode” workstations are able to resolve the DNS entry for to be a CNAME for

05-09-2014 01-49-34


This feature will add to the proxy host file the ip address of for all google websites.
In most cases it should be working.

Especially when using Artica in transparent mode, it is better to mody your local DNS server in order to enforce the resolution.

More informations on Google Web site.

Adding in Windows DNS server

  • Create a new Primary DNS Zone on your DNS server for
  • Add a single CNAME record with a blank alias name and “” for the FQDN for target host.
    The trailing dot after “com” is important.

googlenosslClear your DNS server cache by right-clicking on your server in DNS manager and selecting Clear Cache.
When your clients request, your DNS server will direct the client to instead of
Sample output from NSLOOKUP after configuring this DNS zone:

Server: dns.domain.local


Leave a comment