Domain Rules
Match exact hosts or groups of subdomains to protection settings and presets.
What a Domain Rule does
A Domain Rule matches an exact host or domain pattern. It stores protection settings and can select a Regional Preset.
A rule without its own preset can still apply its protection settings.

Host matching
Use app.example.com to match that exact host.
Use *example.com to match example.com and its subdomains. Use *.example.com to match subdomains only.
When several rules match, the most specific enabled pattern wins. The hostname inspector shows the result before you save.
Add a rule
- Open Domain Rules.
- Select Add rule.
- Enter a host or domain pattern.
- Optionally select a Regional Preset.
- Set the protection options you need.
- Check the hostname inspector.
- Save the rule.
- Reload the site.
Preset inheritance
A rule without its own preset first uses the preset from the active Firefox Container, when available. Otherwise, it can use the preset from the Default Rule.
Preset inheritance does not replace protection settings saved directly in the Domain Rule.
Which source wins
Privacy Thing resolves the current host in this order:
- a matching Trusted Site,
- the most specific enabled Domain Rule,
- the active Firefox Container assignment,
- the Default Rule.
A Trusted Site turns Privacy Thing off. The remaining sources provide the configuration in control.
Check the result
Open the extension popup on the site. Check the source in control, then open X-Ray.
If the result is unexpected, check the exact host, Trusted Sites, and more specific Domain Rules. In Firefox, also check the active container.