Surfshark adds web content blocker to its post-quantum Dausos protocol
Surfshark integrates its web content blocker into the Dausos VPN protocol, enabling macOS users on One and One+ plans to filter unsafe sites without losing speed or security.
Previously, the content blocker only worked alongside WireGuard, another VPN protocol. Bringing it to Dausos closes a gap, so households no longer need to trade the protocol's performance for safer browsing. Dausos uses a hybrid post-quantum secure key exchange and delivers up to 30% faster speeds than other industry-standard protocols, according to Surfshark. The integration allows users to combine speed, privacy, and content protection in a single connection.
The web content blocker is designed to protect an entire household without monitoring individual activity. Unlike traditional parental-control apps, it controls access rather than logs every click, and Surfshark says it does not record browsing history. Users can choose from predefined categories such as adult websites, gambling, profanity, phishing, and malware, and any site falling under those categories is blocked. Surfshark's Karolis Kaciulis said the aim is to protect people from threats "caused by curiosity or carelessness" and to reduce exposure to online scams.
To enable the feature, users connect through Dausos, open the Surfshark app settings, and toggle on the web content blocker. They can then select which categories to restrict, and two-factor authentication can lock the configuration so only an approved admin can change it. The rollout is currently limited to Surfshark One and One+ subscribers running the latest app version on macOS; Starter plan users and other platforms will need to wait or upgrade.
Dausos, which means "paradise" in Lithuanian, is Surfshark's first homegrown protocol. Unlike many rivals that pool traffic through a single tunnel, Dausos assigns each user session its own dedicated, private data tunnel, which contributes to its speed advantage. On security, it uses a hybrid ML-KEM and X25519 key exchange plus an ML-DSA self-signed root certificate system to guard against future quantum threats, along with post-compromise security, port randomization, and AEGIS-256X2 encryption. The protocol has been independently audited by Cure53, and a recent update improved its behavior on locked-down networks often found on school and office firewalls.