← All guides

Domain Rules

Match exact hosts or groups of subdomains to protection settings and presets.

What a Domain Rule does

A Domain Rule matches an exact host or domain pattern. It stores protection settings and can select a Regional Preset.

A rule without its own preset can still apply its protection settings.

Privacy Thing Domain Rules screen with host rules and a hostname inspector

Host matching

Use app.example.com to match that exact host.

Use *example.com to match example.com and its subdomains. Use *.example.com to match subdomains only.

When several rules match, the most specific enabled pattern wins. The hostname inspector shows the result before you save.

Add a rule

  1. Open Domain Rules.
  2. Select Add rule.
  3. Enter a host or domain pattern.
  4. Optionally select a Regional Preset.
  5. Set the protection options you need.
  6. Check the hostname inspector.
  7. Save the rule.
  8. Reload the site.

Preset inheritance

A rule without its own preset first uses the preset from the active Firefox Container, when available. Otherwise, it can use the preset from the Default Rule.

Preset inheritance does not replace protection settings saved directly in the Domain Rule.

Which source wins

Privacy Thing resolves the current host in this order:

  1. a matching Trusted Site,
  2. the most specific enabled Domain Rule,
  3. the active Firefox Container assignment,
  4. the Default Rule.

A Trusted Site turns Privacy Thing off. The remaining sources provide the configuration in control.

Check the result

Open the extension popup on the site. Check the source in control, then open X-Ray.

If the result is unexpected, check the exact host, Trusted Sites, and more specific Domain Rules. In Firefox, also check the active container.