This is the complete web-filtering taxonomy behind the Website Categorization API. Query any URL in real time and receive one or more of the 59 labels below — or skip live lookups entirely with the offline database, where the same categories come pre-computed across 102 million domains.
The labels most deployments enforce first — mandatory blocks in schools, configurable age gates everywhere else.
Pornography and explicit sexual content. A default-deny rule in virtually every school, family and workplace policy, and a CIPA compliance requirement.
Sites promoting or selling beer, wine and spirits. Blocked for minors and in restrictive jurisdictions; usually allowed on adult corporate networks.
Matchmaking apps and romance platforms. Schools block them outright; employers often restrict them to curb personal use and romance-scam exposure.
Betting, casino and lottery operators. Treated as high-risk by filter vendors: blocked for compliance in finance and education, geo-restricted almost everywhere.
Intimate-apparel retail that is legal but suggestive. Separated from Adult so K-12 policies can block it while retail-friendly networks keep it open.
Cigarette, cigar and vaping content. Commonly denied on youth-facing networks and monitored where health or advertising regulations apply.
Work-relevant commercial categories — generally allowed, but monitored for fraud and data-loss risk.
Ad networks, trackers and martech domains. Many gateways block these at scale to cut tracking, bandwidth waste and malvertising, not for content reasons.
General corporate and B2B services. One of the safest allow-listed categories in enterprise policy and a useful baseline when scoring unknown domains.
Exchanges, wallets and DeFi services. Frequently blocked by banks and public-sector networks over fraud, sanctions and cryptojacking concerns.
Insurers, brokers, lenders and fintech. Typically allowed but watched closely, since lookalike financial domains are a favorite phishing lure.
Job boards and recruiting portals. Some employers restrict them during work hours; schools, libraries and public networks almost always leave them open.
Peer-to-peer selling, classifieds and auction platforms. Allowed by default in most policies, monitored for counterfeit-goods and payment-scam activity.
Transactional banking portals. Filters usually whitelist these explicitly and pair the label with anti-phishing checks to protect user credentials.
Property listings, agencies and rental platforms. A low-risk label admins rarely block; handy for tuning personal-browsing rules on work devices.
Online retail of every kind. Enterprises often time-window or monitor it for productivity, while consumer filters leave it fully open.
Channels where information leaves the network — policies here balance collaboration against data-loss risk.
Independent blogs and personal homepages. Usually allowed, but flagged for review in strict environments because content safety varies site by site.
User-generated community hubs and interest groups. Admins tend to monitor rather than block, since moderation standards differ widely across platforms.
Webmail and chat services. A classic DLP control point: many enterprises block personal webmail to keep data inside sanctioned channels.
Discussion boards and Q&A sites. Valuable for research and support, so most policies allow them while logging visits to unmoderated boards.
Journalism outlets and media publications. Rarely blocked; the label mainly drives bandwidth reporting and helps schools separate news from opinion content.
Party, campaign and advocacy sites. Government and workplace policies sometimes restrict these for neutrality; most filters simply tag them for reporting.
Civic and fallback labels that keep policy engines deterministic — every domain resolves to something.
Official government portals, courts and legal resources. Effectively allow-listed everywhere; the label mostly exempts these sites from stricter rules.
Armed-forces, defense-industry and veterans' sites. Generally permitted, though some organizations tag this traffic for export-control awareness.
The catch-all 59th label for legitimate sites that fit no other category. Policies typically allow-and-monitor it so unclassified traffic never goes unlogged.
Benign everyday-interest categories — almost always allowed, but essential for granular reporting and parental controls.
Film, music and culture sites. Allowed in nearly all policies; some workplaces schedule-limit it as part of broader leisure-browsing rules.
Vehicle brands, dealers and transit services. A low-risk label kept so fleet, logistics and dealership networks can whitelist their own vertical.
Encyclopedias, dictionaries and study resources. Universally allowed — many school filters anchor their allow-first policy on this label.
Recipes, food blogs and beverage content. Harmless by default; keeping it distinct from Alcohol lets strict filters avoid blocking cooking sites.
Medical reference and healthcare services. Kept open even under strict policies, though some deployments log visits for duty-of-care programs.
DIY, decor and gardening content. Among the lowest-risk labels in the taxonomy; useful mostly for audience analytics and ad-safety scoring.
Pet care, adoption and wildlife sites. No meaningful policy risk — the label exists so reporting dashboards classify this traffic accurately.
Faith organizations and worship resources. Most filters allow it; some public institutions tag it separately to keep policies viewpoint-neutral.
Restaurant guides, reservations and delivery apps. Routinely allowed; hospitality networks often pin this label to their own allow lists.
Research institutions, journals and popular-science sites. Treated as trusted educational traffic and exempted from most restriction tiers.
Leagues, scores, fitness and outdoor recreation. Allowed by default; enterprises sometimes rate-limit it during major live sporting events.
Airlines, booking engines and destination guides. Open in nearly every policy, with monitoring reserved for travel-themed phishing lookalikes.
Online courses and live training platforms. Explicitly allowed in corporate and campus policies, often with QoS priority for video sessions.
The categories admins throttle by schedule — blocked during class or work hours, opened up after.
Personal cloud drives and file lockers. A top DLP concern: enterprises commonly block unsanctioned storage to keep files on approved platforms.
Torrent trackers and peer-to-peer networks. Blocked almost universally over piracy liability, bandwidth abuse and malware riding on shared files.
Game stores, browser games and esports. Schools and workplaces schedule-block it; home filters use the label to enforce screen-time budgets.
Podcast hosts and audio directories. A lighter distraction label — most policies allow it but count it against streaming-bandwidth quotas.
Profile-and-feed platforms. The most schedule-controlled category in workplace filtering, with exemptions carved out for marketing and HR teams.
Video and music streaming services. Throttled or time-boxed on shared networks, since a handful of streams can saturate an office uplink.
The web's plumbing — mostly allow-listed, with a few edge cases every security team keeps an eye on.
Chatbots, LLM front-ends and AI copilots. Today's fastest-moving policy area: enterprises allow approved tools and block the long tail over data-leak risk.
CDNs, cloud platforms and edge providers. Blocking these breaks the web, so filters allow them and inspect hosted paths, where abuse actually lives.
Tech news, reviews and IT resources. Trusted professional content that stays open in every standard policy tier.
Repositories, CI/CD and developer documentation. Allowed for engineering teams; some organizations gate public-repo uploads as a source-code DLP control.
Download portals and software catalogs. Frequently restricted on managed endpoints so users install software only through vetted channels.
Placeholder and domain-sale pages. Many gateways block them preemptively, because parked domains can flip to malicious hosting with no warning.
General search and discovery portals. Always allowed, with schools layering SafeSearch enforcement on top of the category rather than blocking it.
Browser-delivered SaaS and online utilities. Allowed broadly, but the label helps shadow-IT programs inventory which web apps employees actually use.
The default-block tier — categories denied out of the box on nearly every firewall, DNS filter and secure gateway.
Content promoting hatred or discrimination against groups of people. Denied by default under acceptable-use, brand-safety and duty-of-care policies alike.
Sites selling or promoting controlled substances. A mandatory block in schools and a legal-liability block on most corporate and ISP networks.
Remote-desktop and remote-admin services. Security teams block unapproved providers because attackers and scammers use them to take over endpoints.
Domains our classifiers flag as malicious, deceptive or otherwise untrustworthy. Treat as block-first: this is the taxonomy's active-threat signal.
Redirect services that hide a link's true destination. Filters block or unwrap them, since shorteners are a standard phishing delivery layer.
Gore, terrorism and glorified violent content. Blocked across consumer, education and enterprise policy tiers with essentially no exceptions.
Filter-evasion services: proxies, anonymizers and consumer VPNs. Blocking this category is what keeps every other rule on this page enforceable.
Firearms sales, weapon modification and related instructional content. Blocked in education and most workplaces; regulated-retail networks may allow it.
Classify URLs in real time with the Website Categorization API, or license the offline URL database with the same 59-category taxonomy pre-computed across 102 million domains.
Explore the URL Database View API Plans