I had the same problem, browser extensions weren't enough, and I wanted something system-wide.
So I built Sinkzone [1], a DNS tool that blocks everything unless allowlisted.
It’s open-source and works across OSs. Thought it might be helpful if you're looking beyond NextDNS.
I'm not familiar with this project, just checked their GitHub Readme and if I understand correctly they block what you want them to block. Sinkzone does the opposite, it allows what you want to allow, and blocks everything else.
You can configure your upstream resolvers in the config, so I think Sinkzone can be placed in front of your VPN's resolver. I never tested this to be honest.
Hey Eszpee, Thanks for checking Sinkzone out. I'm thinking about building custom schedules in the next iteration, that would support some basic pomodoro style scheduling for sure.
Let's reverse this notion: if your company is a remote(-friendly) company the place your employees are living is their decision. Since your company allows them to work wherever they want, they don't necessarily have to live in the Bay Area. This becomes a personal preference and I don't see why a personal preference is your business, moreover why you need to reward it with extra money.
Also it's worth considering that in this business your employees are hired to think. It is nice companies starting to realize that it's not needed to be present 100% in the time in an office to be able to deliver the thinking, but they also need to realize that my brain produces the same output no matter where I live.
Kudos, I've started the same project a few months ago, but I had no time to finish. The only question is what are you going to do if amazon integrates the bounce handling into the ses api?
[1] https://github.com/berbyte/sinkzone