Encrypted client transport
DNS questions sent through the configured endpoint travel inside HTTPS rather than plaintext DNS between the compatible client and QueryWarden.
DNS-over-HTTPS carries DNS questions inside HTTPS. QueryWarden gives each configured device a private, rotatable DoH URL so the service can authorize the endpoint, apply its profile, and reject an unknown credential.
DoH protects DNS questions in transit between a compatible client and QueryWarden. The complete endpoint URL also acts like a bearer secret, so it must be installed only in the intended client and kept out of screenshots, logs, and public configuration.
Each capability below reflects the current public product, with beta and compatibility limits called out separately.
DNS questions sent through the configured endpoint travel inside HTTPS rather than plaintext DNS between the compatible client and QueryWarden.
The endpoint authorizes the configured device and connects its requests to the intended policy without exposing a shared public resolver credential.
A stable device or network can require an approved public IP or CIDR in addition to presenting the correct private endpoint.
The setup check waits for activity from the selected endpoint after the check begins instead of relying on an older last-seen value.
QueryWarden currently publishes DNS-over-HTTPS, not a generic DNS server address. Compatibility depends on whether the operating system, application, router, or local forwarder accepts a complete custom HTTPS resolver URL.
Open full-size screenshot | Client or deployment | Current method | Status and boundary |
|---|---|---|
| macOS 11 or later | Unsigned Apple DNS profile or a compatible custom-DoH client | Available; explicit user or administrator approval is required. |
| iPhone and iPad (iOS or iPadOS 14 or later) | Unsigned Apple DNS profile | Available; the profile must be reviewed and installed in Settings. |
| Windows, Linux, or browser | Compatible software that accepts the complete custom DoH URL | Available when the chosen client supports a full URL; QueryWarden does not provide a native client today. |
| Android | Compatible custom-DoH application | Android Private DNS expects a provider hostname and cannot use the current private DoH URL. |
| Router or local forwarder | Firmware or software that accepts the complete custom DoH URL | Device-specific; a plain DNS IP or DoT hostname field is not compatible. |
| QueryWarden Relay | Maintained Linux host forwarding local DNS to QueryWarden | Beta and unsigned; intended for technically managed networks. |
QueryWarden applies policy at the recursive DNS layer, before a supported client connects to the requested domain.
Choose its platform and profile so the new private endpoint has a clear owner and policy before it leaves the dashboard.
A generic DNS server field, IP-address field, or DNS-over-TLS hostname field is not compatible with the private HTTPS URL.
Preserve the scheme, hostname, path, and private identifier, and avoid shell history, screenshots, tickets, or version-controlled files.
Start QueryWarden verification, generate a new lookup, and inspect whether the client silently returns to another resolver when custom DoH fails.
DoH changes the transport for DNS questions. It does not turn QueryWarden into a VPN or hide every part of an internet connection.
Published and reviewed by QueryWarden Engineering, Digiport OÜ. First-party review against the current public QueryWarden product, its documented deployment constraints, and the primary sources listed on this page. This is not an independent audit, certification, approval, or endorsement.
Product screenshots are deterministic captures of the current interface using synthetic accounts, devices, and reserved .test domains. External sources explain protocols and industry guidance; they do not verify QueryWarden implementation claims.
Last reviewed . Product availability can change; dashboard capability labels remain the source of truth. Review our Security & Trust disclosure.These primary sources support the general technical context. Citing them does not mean their publishers evaluated, approved, or endorsed QueryWarden.
DNS-over-HTTPS carries DNS questions and answers inside HTTPS between a compatible client and its configured resolver. It protects that DNS transport from ordinary plaintext observation in transit, but it is not a VPN and does not encrypt all device traffic.
No. Android system Private DNS expects a DNS-over-TLS provider hostname, while the current QueryWarden endpoint is a complete private DoH URL. Use a compatible custom-DoH app instead.
It authorizes requests as the selected QueryWarden endpoint. Someone with the complete URL could consume its allowance, create misleading activity, or receive its policy until the endpoint is rotated or otherwise restricted.
Begin with one endpoint, keep its complete URL private, and confirm fresh activity before relying on it.