Overview
Atmosphere is Neptune's protective DNS service. It blocks ads, trackers, malware, phishing and other unwanted content across your whole network using sinkhole DNS technology, and it doubles as a flexible parental control tool.
Atmosphere is now managed through profiles. A profile holds your filtering policy: the categories you block, your always-allowed and always-blocked domains, and your activity logging preferences. You then assign that profile to any of your internet services and VPN tunnels, so one policy can protect everything without having to configure each service separately.
Before you start
Atmosphere requires at least one active Neptune internet service. If you cancel your last service, your profiles and their settings are removed.
You can create up to 2 profiles per account. If you need more, contact support.
On your home network, Atmosphere relies on the DNS servers we assign automatically via DHCP. If you have manually configured different DNS servers on your router or devices, filtering will not apply.
Server | Address |
DNS1 | 138.252.23.23 (UDP, TCP, DOT and DOH) |
DNS2 | 138.252.23.138 (UDP, TCP, DOT and DOH) |
DNS1 IPV6 | 2401:dc20:cafe::53 (UDP and TCP) |
DNS2 IPV6 | 2402:3120:cafe::53 (UDP and TCP) |
DOH | |
TLS | atmosphere.neptune.net.au:853 |
What is sinkhole DNS?
Sinkhole DNS works by intercepting requests to known ad, tracking and malicious domains and preventing your device from connecting to them. When you try to access a site blocked by Atmosphere, the page won't load and your browser will show a connection error. By redirecting these unwanted requests, sinkhole DNS effectively "sinks" them, keeping ads, tracking scripts and harmful content from loading.
Important considerations
While Atmosphere can greatly improve your browsing experience, blocking can occasionally prevent legitimate websites from loading correctly. If a site appears broken, you can use the Domain tester (see below) to check whether Atmosphere is blocking it, add it to your allowed domains, or pause filtering for a service entirely.
Please note: a profile applies to every user and device on the services it is assigned to. If you want different rules for different services (for example, stricter filtering on the kids' connection than on your VPN tunnel), create a second profile and assign each service to the profile that suits it.
Creating a profile
1. Log in to your Neptune account.
2. Select Atmosphere from the menu.
3. Click New profile and give it a recognisable name, like "Home" or "Kids' devices".
Once created, open the profile to configure it. The profile page has tabs for Overview, Allowed domains, Blocked domains, Domain tester, Private DNS and Logs.
Choosing what to block
On the profile's Overview tab you'll find the content filtering categories, grouped for convenience:
- Recommended is a curated set covering ads, trackers, malware, phishing and threat intelligence feeds. This is the right starting point for most households.
- Protective DNS contains the full security selection: malware, phishing, ransomware and emerging threat feeds.
- Further categories let you block adult content, social media platforms, gambling, and more.
Toggle a category on and it applies to every service using the profile, withing 5-10 minutes.
Using Atmosphere as a parental control tool
With category filtering you can:
- Block adult content and prevent access to explicit or inappropriate material.
- Restrict social media platforms to limit distractions or set boundaries around apps like Facebook, Instagram and TikTok.
- Block gambling websites including online betting and casinos.
Because profiles are assigned per service, you can keep a strict profile on the family internet service and a lighter one on your own VPN tunnel.
Assigning services
In the Assigned services section of the profile, toggle on the internet services and VPN tunnels the profile should protect. Each service can belong to only one profile at a time; turning a service on here moves it from any other profile it was assigned to.
VPN tunnels can be filtered when they are in an Atmosphere-enabled (Australian Neptune) region.
You can also pause filtering for a single service without removing it from the profile, which is handy for troubleshooting.
If you cancel a service, it is removed from its profile automatically.
Allowed and blocked domains
Each profile carries two domain lists, each holding up to 100 entries:
- Allowed domains are never blocked, even when a category matches them. Use this to fix a site that a blocklist catches by mistake.
- Blocked domains are always blocked for every service using the profile.
Wildcards are supported: *.example.com matches the domain and all of its subdomains.
Domain tester
Not sure why a site isn't loading? Open the Domain tester tab, type the domain, and Atmosphere will tell you whether this profile blocks it and which category list is responsible. If it is blocked and you want it back, the Allow button adds it to your allowed domains in one click.
Private DNS: take your profile with you
Your profile protects your home network automatically. To use the same filtering away from home, on mobile data or other networks, each profile can have up to 5 private DNS endpoints. We recommend one per device.
Each endpoint gets a random, unguessable address. **Treat the hostname like a password**: anyone who knows it can use your endpoint.
On the profile's Private DNS tab, enter a device name (for example "My iPhone") and click Add endpoint. Each endpoint shows its Android Private DNS hostname and its DNS-over-HTTPS URL, along with setup instructions:
- iPhone, iPad and Mac: download the configuration profile with the download button and install it. On iPhone/iPad, open Settings, tap Profile Downloaded, then Install. On a Mac, open the downloaded file and install it under System Settings, General, Device Management.
- Android: open Settings, Network & internet, Private DNS, choose "Private DNS provider hostname" and paste the endpoint's hostname.
- Browsers: enable custom secure DNS in your browser's privacy settings and paste the endpoint's DNS-over-HTTPS URL.
Deleting an endpoint stops it working immediately, and the address cannot be recreated. The device using it will lose DNS until you remove its Private DNS setting or installed profile.
Activity logs
Each profile has a Logs tab where you can optionally enable DNS query logging to see top domains, recently blocked queries and activity over time for every service using the profile.
Before enabling logging, please read the consent notice carefully: logging records queries from all devices on the assigned services, so you must have the informed consent of everyone in your household aged 18 or over. Log entries are encrypted at rest and automatically deleted after 24 hours; there is no long-term retention. A privacy masking option is available if you want aggregate statistics without full query detail.
Review our privacy policy regarding Atmosphere to understand what data is stored.
DNS over HTTPS on your home network
Atmosphere also supports DNS over HTTPS (DoH), a protocol that encrypts DNS queries so third parties cannot monitor or tamper with them. On your home connection, our public resolvers apply your profile's policy automatically:
https://138.252.23.23 (Anycast)
https://138.252.23.138 (Anycast)
Note: the public resolvers recognise you by your Neptune connection, so they only apply your policy while you are at home. Away from home, use a private DNS endpoint from your profile instead.
Firefox
1. Type about:settings in the address bar, then open Privacy & Security and find DNS over HTTPS.
2. Choose Increased Protection.
3. Select Custom provider and enter https://atmosphere.neptune.net.au/dns-query (at home) or your private endpoint URL (anywhere).
4. Make sure the server shows as Active.
Chrome
1. Open the three-dot menu, then Settings.
2. Go to Privacy and security then Security.
3. Scroll down and enable Use secure DNS.
4. Choose Add custom DNS provider and enter https://atmosphere.neptune.net.au/dns-query (at home) or your private endpoint URL (anywhere).
A final note
Atmosphere gives you real control over your browsing experience, but DNS blocking is a blunt instrument by nature and may occasionally affect a site you want. If something isn't working, check the Domain tester first, allow the domain if needed, or pause filtering for the affected service. If you're unsure whether Atmosphere is right for you, it's perfectly fine to leave it off.









