How to set up parental controls on Sky Q Hub
Sky Broadband Shield provides network-level filtering, but older Sky Q Hubs need special care: Sky ended security updates for Q Hub models on 31 December 2025. This guide starts with that support check, then covers Shield and the supported route to Canopy-managed filtering.
Before you start
- Sky Broadband Shield is tied to your Sky account. Ensure your Sky account password and email are secure — a child who accesses your account can turn the Shield off.
- The Sky Q Hub admin panel at http://192.168.0.1 is only accessible from within your home network.
- Changing your Wi-Fi password will disconnect all devices. Reconnect smart TVs and consoles using the new password before your children notice.
- Sky Q Hub models stopped receiving security updates on 31 December 2025. Ask Sky about a supported replacement before relying on an older Q Hub.
Step 1 — Log into the Sky Q Hub admin panel
- Connect a device to your Sky Wi-Fi (not mobile data).
- Open a browser and go to http://192.168.0.1.
- Enter the admin password. The default is on the label on the back of the hub — look for "Wireless Key" or "Admin Password".
- Click Log in.
If the page does not load, try http://192.168.0.254. Some Sky Q Hub models use a different default gateway. Check your router's IP in your device's network settings.
Step 2 — Change the default admin password
The default admin passwords on Sky hubs are predictable. Changing it is the single most important security step.
- Once logged in, find Settings or Admin Settings.
- Select Change Admin Password.
- Enter the current password, then set a new strong password.
- Save the change and log back in.
Step 3 — Enable WPA2 or WPA3 Wi-Fi encryption
- Go to Wireless Settings.
- Under Security, select WPA2-PSK (AES) or WPA3-Personal if your hub supports it.
- Change the Wi-Fi password to a strong passphrase — 16+ characters, mixed case and numbers.
- Apply and reconnect all devices with the new password.
Step 4 — Replace an unsupported Sky Q Hub
- Check the model on the hub label and compare it with Sky’s current router-update notice.
- If it is a Sky Q Hub, contact Sky and request a currently supported hub.
- Do not assume a generic Guest Network, WPA3, or custom-DNS menu exists on every Sky model.
Sky Max Hub and Gigafast+ Hub settings are managed through current Sky instructions; their menus differ from the older Q Hub.
Step 5 — Connect Canopy-managed NextDNS
Do not hunt for similarly named fields or enter DNS values into DHCP, gateway, or IP-address fields.
- Start a Canopy Families full-access subscription or 14-day trial; a managed NextDNS profile is included.
- Open Home Safety → Router Setup and select your exact Sky model.
- Sky does not document a universal custom-DNS route across Q, Max, and Gigafast+ hubs. Use Canopy Device Setup, or a compatible third-party router, when Router Setup identifies no supported DNS menu.
- Run Test connection in Home Safety before treating the setup as active.
Step 6 — Enable Sky Broadband Shield
- Go to sky.com and sign in to My Sky.
- Navigate to My Account → Products & Services → Broadband.
- Find Broadband Shield and click Manage.
- Switch Shield On.
- Select the filtering level: "Child Safe" (under 13) or "Adult Content" (13+).
- Save. The change takes effect within a few minutes for all devices on your connection.
Sky Broadband Shield works at the Sky network level, upstream of your router. It applies even if a device changes its DNS settings — making it the most robust layer for ISP-level filtering.
Sources and model checks
Router menus vary by model and firmware. These instructions were checked against the manufacturers' current support material; use the route shown for your exact model.
Want Canopy to manage this for you?
Canopy Families full access includes a managed NextDNS profile, guided router setup, content controls, connection checks, and a safety dashboard for your family.
Start your 14-day full-access trial