They need to be using deep packet inspection to get reliable and useful blocks.
If you cannot install their self-signed cert on your device (i.e non-managed device) then you likely aren't being MitM and thus, restrictions are hard.