DNS-OVER-HTTPS

Encrypted DNS transport through a private device endpoint.

DNS-over-HTTPS carries DNS questions inside HTTPS. QueryWarden gives each configured device a private, rotatable DoH URL so the service can authorize the endpoint, apply its profile, and reject an unknown credential.

DNS-over-HTTPS is the only public QueryWarden device protocol today Every direct endpoint is private and rotatable Optional source-IP restrictions add another authorization condition
DNS decision pathIllustrative request
Device
Private DoH
QueryWarden policy
Allowed destination
Policy checked before connectionDecision evidence is reviewable when the profile retains it.
TRANSPORT AND IDENTITY

Encryption protects the path; the private URL identifies the endpoint.

DoH protects DNS questions in transit between a compatible client and QueryWarden. The complete endpoint URL also acts like a bearer secret, so it must be installed only in the intended client and kept out of screenshots, logs, and public configuration.

BUILT INTO THE PRODUCT

Controls you can use and verify.

Each capability below reflects the current public product, with beta and compatibility limits called out separately.

Encrypted client transport

DNS questions sent through the configured endpoint travel inside HTTPS rather than plaintext DNS between the compatible client and QueryWarden.

A private endpoint per device

The endpoint authorizes the configured device and connects its requests to the intended policy without exposing a shared public resolver credential.

Optional source conditions

A stable device or network can require an approved public IP or CIDR in addition to presenting the correct private endpoint.

Fresh-traffic verification

The setup check waits for activity from the selected endpoint after the check begins instead of relying on an older last-seen value.

COMPATIBILITY EVIDENCE

A complete private DoH URL needs the right kind of client.

QueryWarden currently publishes DNS-over-HTTPS, not a generic DNS server address. Compatibility depends on whether the operating system, application, router, or local forwarder accepts a complete custom HTTPS resolver URL.

QueryWarden macOS connection setup showing an example private DNS-over-HTTPS endpoint, Apple profile download, and traffic verification controls.Open full-size screenshot
Current macOS setup interface captured with a reserved example endpoint. Private production credentials are never used in this image.

Current QueryWarden setup compatibility

Current setup paths for QueryWarden private DNS-over-HTTPS endpoints.
Client or deploymentCurrent methodStatus and boundary
macOS 11 or laterUnsigned Apple DNS profile or a compatible custom-DoH clientAvailable; explicit user or administrator approval is required.
iPhone and iPad (iOS or iPadOS 14 or later)Unsigned Apple DNS profileAvailable; the profile must be reviewed and installed in Settings.
Windows, Linux, or browserCompatible software that accepts the complete custom DoH URLAvailable when the chosen client supports a full URL; QueryWarden does not provide a native client today.
AndroidCompatible custom-DoH applicationAndroid Private DNS expects a provider hostname and cannot use the current private DoH URL.
Router or local forwarderFirmware or software that accepts the complete custom DoH URLDevice-specific; a plain DNS IP or DoT hostname field is not compatible.
QueryWarden RelayMaintained Linux host forwarding local DNS to QueryWardenBeta and unsigned; intended for technically managed networks.
HOW IT WORKS

From setup to an explainable DNS decision.

QueryWarden applies policy at the recursive DNS layer, before a supported client connects to the requested domain.

  1. 01

    Create the intended QueryWarden device

    Choose its platform and profile so the new private endpoint has a clear owner and policy before it leaves the dashboard.

  2. 02

    Confirm that the client accepts a full custom DoH URL

    A generic DNS server field, IP-address field, or DNS-over-TLS hostname field is not compatible with the private HTTPS URL.

  3. 03

    Install the complete URL privately

    Preserve the scheme, hostname, path, and private identifier, and avoid shell history, screenshots, tickets, or version-controlled files.

  4. 04

    Check fresh traffic and fallback

    Start QueryWarden verification, generate a new lookup, and inspect whether the client silently returns to another resolver when custom DoH fails.

CLEAR BOUNDARIES

Encrypted DNS is not anonymous or complete traffic encryption

DoH changes the transport for DNS questions. It does not turn QueryWarden into a VPN or hide every part of an internet connection.

  • Web destinations and network intermediaries can still receive connection information outside the DNS exchange; DoH does not encrypt all device traffic.
  • The QueryWarden service must process the DNS question to resolve and filter it, subject to the profile logging choice and Privacy Policy.
  • Public QueryWarden DNS-over-TLS and DNS-over-QUIC remain launch-gated and must not be presented as available alternatives.
  • QueryWarden does not currently provide a signed native roaming client; Windows, Android, and Linux use compatible custom-DoH software, while Apple profiles are unsigned.
WHO AND HOW

Technical basis and product evidence

Published and reviewed by QueryWarden Engineering, Digiport OÜ. First-party review against the current public QueryWarden product, its documented deployment constraints, and the primary sources listed on this page. This is not an independent audit, certification, approval, or endorsement.

Product screenshots are deterministic captures of the current interface using synthetic accounts, devices, and reserved .test domains. External sources explain protocols and industry guidance; they do not verify QueryWarden implementation claims.

Last reviewed . Product availability can change; dashboard capability labels remain the source of truth. Review our Security & Trust disclosure.
QUESTIONS, ANSWERED

What to know before you change DNS.

What is DNS-over-HTTPS (DoH)?

DNS-over-HTTPS carries DNS questions and answers inside HTTPS between a compatible client and its configured resolver. It protects that DNS transport from ordinary plaintext observation in transit, but it is not a VPN and does not encrypt all device traffic.

Can I paste the QueryWarden URL into Android Private DNS?

No. Android system Private DNS expects a DNS-over-TLS provider hostname, while the current QueryWarden endpoint is a complete private DoH URL. Use a compatible custom-DoH app instead.

Why must the private DoH URL stay secret?

It authorizes requests as the selected QueryWarden endpoint. Someone with the complete URL could consume its allowance, create misleading activity, or receive its policy until the endpoint is rotated or otherwise restricted.

START WITH THE AVAILABLE FREE PLAN

Create a private DoH endpoint for a compatible client.

Begin with one endpoint, keep its complete URL private, and confirm fresh activity before relying on it.