Privacy per protection profile
The logging choice travels with the profile so protection and durable evidence can be balanced for its intended audience.
QueryWarden profiles can retain full domain history, keep anonymized aggregate activity, or turn new domain-level logging off. Retention is bounded by the account plan and can be shortened by the profile; it is not described with a blanket “zero-log” promise.
QueryWarden still has to process a live DNS question to resolve and filter it. The profile logging mode controls the durable event detail created afterward, while limited operational metadata can be processed separately to authorize endpoints, prevent abuse, and operate the service.
Each capability below reflects the current public product, with beta and compatibility limits called out separately.
The logging choice travels with the profile so protection and durable evidence can be balanced for its intended audience.
Anonymized mode can preserve account-level counts while omitting hostname, endpoint attribution, and matched-rule detail from durable DNS events.
A profile may choose a supported period no longer than its account plan window, and a later reduction updates existing eligible event expiry.
The Privacy Receipt summarizes account and profile choices so a dashboard preference is not the only evidence of the active boundary.
The resolver must process a live question to authorize, filter, validate, and answer it. The profile privacy mode determines what eligible DNS-event detail is stored afterward; it does not make the live resolution step disappear.
Open full-size screenshot Sends a DNS question through its private HTTPS endpoint.
QueryWarden validates the endpoint and applies the assigned profile and resolver controls.
The live request is blocked or recursively resolved and answered.
Full, Anonymized, or Off determines the eligible durable DNS event created after the decision.
| Mode | Durable DNS-event detail | Important consequence |
|---|---|---|
| Full | Eligible hostname, endpoint attribution, result, timing, and decision detail within the selected retention window. | Supports per-event investigation while creating the most detailed history. |
| Anonymized | Eligible aggregate activity without hostname, endpoint attribution, or matched-rule detail. | Account totals can remain while named endpoint rows no longer add up to that total. |
| Off | No new durable DNS-event history for the profile. | Live protection continues, but the Query Log cannot reconstruct activity that was not retained. |
QueryWarden applies policy at the recursive DNS layer, before a supported client connects to the requested domain.
Choose whether troubleshooting requires full domains, aggregate activity is enough, or no new durable DNS-event history should be created.
The new choice applies to subsequent DNS activity from endpoints assigned to that profile.
Select a supported duration at or below the plan boundary; Free retains no more than 48 hours when history is enabled.
Confirm that the receipt describes the effective logging and retention state for every relevant profile before relying on it.
Domain-event privacy is one part of operating a secure, accountable service and should not be confused with the absence of all processing or records.
Published and reviewed by QueryWarden Engineering, Digiport OÜ. First-party review against the current public QueryWarden product, its documented deployment constraints, and the primary sources listed on this page. This is not an independent audit, certification, approval, or endorsement.
Product screenshots are deterministic captures of the current interface using synthetic accounts, devices, and reserved .test domains. External sources explain protocols and industry guidance; they do not verify QueryWarden implementation claims.
Last reviewed . Product availability can change; dashboard capability labels remain the source of truth. Review our Security & Trust disclosure.These primary sources support the general technical context. Citing them does not mean their publishers evaluated, approved, or endorsed QueryWarden.
No. QueryWarden still processes the live request to authorize the endpoint, apply policy, and resolve or block it. Off prevents new durable DNS-event history for that profile.
It retains eligible aggregate activity without the hostname, endpoint attribution, or matched-rule detail used for a full event. This means named endpoint lines may not add up to the account total.
We do not use that blanket claim. Profiles offer Full, Anonymized, or Off domain-event logging, while limited operational, account, security, support, and backup records remain subject to their stated purposes and retention.
Connect one Free endpoint, set its profile to Full, Anonymized, or Off, and verify the effective choice in the Privacy Receipt.