My ClearDNS

Analytics and Live Observability

Last reviewed: 2026-09-08 20:32 UTC / 1.1.1

Most of the Transparency Center explains what data exists and how it is protected. This page explains the other half: what the product can actually do with the observability a policy owner chooses to enable. ClearDNS treats historical analytics and live visibility as separate data rails, and a policy can run with one, both, or neither. Understanding that separation is the key to reading everything below.

The privacy architecture that governs which identifiers exist, why, and for how long is documented in Privacy and Observability. This page describes capability, not the retention model, and it points back to the privacy page wherever the two meet.

Observability is not one product#

ClearDNS sells three distinct observability capabilities, and they do not travel together:

  • Historical Analyze is the retained, queryable analytics capability. It answers questions about the last 7, 30, or 90 days of policy-linked activity.
  • Instant Logs is a live rail. It streams DNS events to an authorized dashboard in real time and does not depend on a retained query history.
  • Live Traffic Map is a live geographic visualization of current DNS activity for the whole policy.

Because these are separate rails, a policy can have live visibility while historical query retention stays disabled, and it can have historical analytics without a live stream. The product state a policy is in determines which rails are active:

Product stateHistorical AnalyzeInstant LogsLive Traffic Map
EssentialNoNoNo
AnalyzeYesNoNo
StreamNoYesYes
FullYesYesYes
TrialYesYesYes

The matrix reflects current source. Historical Analyze is enabled for the Analyze and Full states; the live rail that powers Instant Logs and the Live Traffic Map is enabled for the Stream and Full states. During the trial window a policy exposes the full product regardless of the tier it later settles on, so a trial sees all three.

The important consequence is the Stream row. Stream provides Instant Logs and the Live Traffic Map without enabling the 90-day historical query database. Live visibility and retained history are decoupled by design.

A policy can run without a query history#

A ClearDNS policy can operate without retaining any policy-linked history of the DNS names it looked up. The Essential state keeps no historical query analytics and no live rail. The Stream state adds live visibility but still keeps no retained query-history database. Only the Analyze and Full states enable the retained, queryable history described next.

Historical Analyze#

Analyze is the retained analytics capability, with up to 90 days of policy-linked history. It presents a fixed set of views, and each view answers a specific question rather than dumping a raw log:

  • Top Domains shows which queried hostnames account for the most activity.
  • Root Domains consolidates activity at the registrable-domain level, so a service that spreads across many subdomains reads as one entry instead of subdomain noise.
  • GAFAM Footprint shows how much traffic is attributed to the large Big Tech ecosystem, according to the ClearDNS classification of those domains.
  • User Insights breaks activity down by member.
  • Device Insights breaks activity down by individual device.
  • Blocked Categories shows which of the enabled policy categories account for blocking activity.

These are the views current source exposes. ClearDNS does not present a metric here that the product does not actually compute.

Drilldown dimensions#

Each Analyze view is read through a small set of orthogonal filters. In the current dashboard, a view is composed with:

view
  × time range   (last 7 / 30 / 90 days)
  × traffic type  (all / allowed / blocked)
  × user scope    (all members, or a selected member)
  × device scope  (all devices, or a selected device)

So a question like "which root domains did one member's phone reach, blocked only, over the last 30 days" is a normal combination of these dimensions, not a special report. The Reports export is a separate owner and admin capability that builds a downloadable workbook; it is not the same surface as the interactive Analyze views, and the dimensions above describe the interactive dashboard.

Instant Logs#

Instant Logs use a demand-activated, fire-and-forget live-delivery rail separate from historical analytics. Opening an authorized live view activates the per-policy live rail; the resolver populates its temporary query-bearing buffer only while that policy is actively using live visibility or within the brief continuation window that supports reconnect continuity. When the live rail is inactive, Instant Logs does not continuously accumulate DNS queries in the background.

For real-time delivery and brief replay continuity, query-bearing events use a transient per-policy server-side buffer with a hard maximum TTL of one minute from server receipt. The maximum may be shortened but not extended. Expired events are excluded from server-side live reads and replay, and the live rail does not write them into a persistent Instant Logs history database.

This is deliberately different from implementing "live logs" as an ordinary event database with a shorter retention setting. The temporary live buffer exists only to deliver what is happening now and to survive brief interruptions in the live connection. Historical Analyze is a different data rail and, where enabled by the product state, can independently retain policy-linked query analytics for up to 90 days.

This demand-activated, per-policy, hard-expiring delivery model is one of ClearDNS's privacy-oriented architectural innovations: ClearDNS creates query-bearing live state when live visibility is actually in use instead of requiring a continuously accumulating query archive merely to offer real-time monitoring.

This separation allows ClearDNS to provide Instant Logs and the Live Traffic Map in a no-history product state without enabling historical query retention.

Live Traffic Map#

The Live Traffic Map visualizes current DNS activity for the whole policy as animated arcs on a world map. It is part of the same live rail as Instant Logs, so it is available in the Stream and Full states and during the trial, and it does not create a retained map-history database.

The map draws on two independent geographic facts, and the authority behind each is described in ClearDNS IP Intelligence:

  • Source is the geographic country of the connecting IP.
  • Destination is the geographic country of the actual DNS answer IP.

Source and destination are separate authority rails. Neither overwrites the other, and the network-associated country of an address is a third, distinct fact that is never substituted for either geographic country. City-level detail is not required to render the map or to indicate a cross-country tunnel.

The scope of the map is the policy, not the browser. For an authorized owner or admin, the map shows current activity across the whole policy and all of its devices, not merely the activity of the device that happens to be viewing the dashboard. A member's scope is limited to what their role authorizes; the map does not let one member inspect another member where the role model does not permit it.

ClearDNS can expose live DNS events and a policy-wide geographic view while historical query retention stays disabled, because historical analytics and live delivery are separate data rails.

Why was this blocked?#

Live and historical views both answer the accountability question directly, because the resolver records its own decision. Each event carries the decision it received, the reason for that decision, and the category that acted, and the ClearDNS Guard block page presents the same reason to the person who hit it: a category block, an unpaid or expired policy, or a destroyed policy. The reason a name was blocked is the ClearDNS policy or category decision that acted, which is the subject of The DNS Policy Engine and Domain and Network Intelligence.

Ready to try ClearDNS?

Private DNS protection without a conventional account.

Try Now for Free