DNS PRIVACY

A DNS privacy setting should change what is stored.

QueryWarden profiles can retain full domain history, keep anonymized aggregate activity, or turn new domain-level logging off. Retention is bounded by the account plan and can be shortened by the profile; it is not described with a blanket “zero-log” promise.

Full, Anonymized, and Off domain-level logging modes are available A profile can shorten but never extend its plan retention boundary The Privacy Receipt reports the effective profile state
DNS decision pathIllustrative request
Device
Private DoH
QueryWarden policy
Allowed destination
Policy checked before connectionDecision evidence is reviewable when the profile retains it.
STORAGE CHOICES

Separate live protection from durable domain history.

QueryWarden still has to process a live DNS question to resolve and filter it. The profile logging mode controls the durable event detail created afterward, while limited operational metadata can be processed separately to authorize endpoints, prevent abuse, and operate the service.

BUILT INTO THE PRODUCT

Controls you can use and verify.

Each capability below reflects the current public product, with beta and compatibility limits called out separately.

Privacy per protection profile

The logging choice travels with the profile so protection and durable evidence can be balanced for its intended audience.

Anonymized aggregate activity

Anonymized mode can preserve account-level counts while omitting hostname, endpoint attribution, and matched-rule detail from durable DNS events.

Retention that can be shortened

A profile may choose a supported period no longer than its account plan window, and a later reduction updates existing eligible event expiry.

A visible effective state

The Privacy Receipt summarizes account and profile choices so a dashboard preference is not the only evidence of the active boundary.

DATA-FLOW EVIDENCE

See where live DNS processing ends and durable history begins.

The resolver must process a live question to authorize, filter, validate, and answer it. The profile privacy mode determines what eligible DNS-event detail is stored afterward; it does not make the live resolution step disappear.

QueryWarden privacy controls showing Full, Anonymized, and Logging off modes together with retention and Privacy Receipt information.Open full-size screenshot
Current QueryWarden privacy interface captured with deterministic demo data. The effective setting still depends on each account and profile.

QueryWarden DNS data flow

  1. 01
    Compatible client

    Sends a DNS question through its private HTTPS endpoint.

  2. 02
    Authorization and policy

    QueryWarden validates the endpoint and applies the assigned profile and resolver controls.

  3. 03
    DNS result

    The live request is blocked or recursively resolved and answered.

  4. 04
    Profile-controlled history

    Full, Anonymized, or Off determines the eligible durable DNS event created after the decision.

What the three logging modes change

Durable DNS-event detail by QueryWarden profile logging mode.
ModeDurable DNS-event detailImportant consequence
FullEligible hostname, endpoint attribution, result, timing, and decision detail within the selected retention window.Supports per-event investigation while creating the most detailed history.
AnonymizedEligible aggregate activity without hostname, endpoint attribution, or matched-rule detail.Account totals can remain while named endpoint rows no longer add up to that total.
OffNo new durable DNS-event history for the profile.Live protection continues, but the Query Log cannot reconstruct activity that was not retained.
HOW IT WORKS

From setup to an explainable DNS decision.

QueryWarden applies policy at the recursive DNS layer, before a supported client connects to the requested domain.

  1. 01

    Decide what evidence is actually needed

    Choose whether troubleshooting requires full domains, aggregate activity is enough, or no new durable DNS-event history should be created.

  2. 02

    Set Full, Anonymized, or Off on the profile

    The new choice applies to subsequent DNS activity from endpoints assigned to that profile.

  3. 03

    Choose the shortest useful retention window

    Select a supported duration at or below the plan boundary; Free retains no more than 48 hours when history is enabled.

  4. 04

    Read the resulting Privacy Receipt

    Confirm that the receipt describes the effective logging and retention state for every relevant profile before relying on it.

CLEAR BOUNDARIES

Why QueryWarden does not make a blanket zero-log claim

Domain-event privacy is one part of operating a secure, accountable service and should not be confused with the absence of all processing or records.

  • Live DNS questions are processed to authorize, filter, validate, and resolve requests even when durable domain-level logging is Off.
  • Limited source-IP and request metadata can be processed for endpoint restrictions, rate limits, abuse prevention, and service operations as described in the Privacy Policy.
  • Support, account, security, billing, and backup records have separate purposes and retention rules; they are not DNS query history.
  • The available Free plan keeps no more than 48 hours of DNS history. Paid plans with 7–90 days of durable analytics remain planned rather than generally purchasable.
WHO AND HOW

Technical basis and product evidence

Published and reviewed by QueryWarden Engineering, Digiport OÜ. First-party review against the current public QueryWarden product, its documented deployment constraints, and the primary sources listed on this page. This is not an independent audit, certification, approval, or endorsement.

Product screenshots are deterministic captures of the current interface using synthetic accounts, devices, and reserved .test domains. External sources explain protocols and industry guidance; they do not verify QueryWarden implementation claims.

Last reviewed . Product availability can change; dashboard capability labels remain the source of truth. Review our Security & Trust disclosure.
QUESTIONS, ANSWERED

What to know before you change DNS.

Does Off logging stop QueryWarden protection?

No. QueryWarden still processes the live request to authorize the endpoint, apply policy, and resolve or block it. Off prevents new durable DNS-event history for that profile.

What does Anonymized logging retain?

It retains eligible aggregate activity without the hostname, endpoint attribution, or matched-rule detail used for a full event. This means named endpoint lines may not add up to the account total.

Is QueryWarden a zero-log DNS provider?

We do not use that blanket claim. Profiles offer Full, Anonymized, or Off domain-event logging, while limited operational, account, security, support, and backup records remain subject to their stated purposes and retention.

START WITH THE AVAILABLE FREE PLAN

Choose the minimum useful DNS history.

Connect one Free endpoint, set its profile to Full, Anonymized, or Off, and verify the effective choice in the Privacy Receipt.