DNS VISIBILITY

DNS query evidence that stays inside the privacy boundary.

QueryWarden turns eligible retained DNS activity into a searchable Query log, account and endpoint analytics, decision explanations, and measured incident records. What appears depends on the profile’s Full, Anonymized, or Off logging mode and the account retention window.

Real-time Query log and DNS analytics are available Full, Anonymized, and Off logging change visible evidence Free history is bounded to no more than 48 hours
DNS decision pathIllustrative request
Device
Private DoH
QueryWarden policy
Allowed destination
Policy checked before connectionDecision evidence is reviewable when the profile retains it.
ONE DATASET, DIFFERENT QUESTIONS

Move from an account trend to the evidence for one DNS decision.

The analytics workspace summarizes retained query and block activity. The Query log then narrows to eligible event rows, while Explain and Incidents add decision-source and detector context without inventing detail removed by privacy settings.

BUILT INTO THE PRODUCT

Controls you can use and verify.

Each capability below reflects the current public product, with beta and compatibility limits called out separately.

Account and endpoint trends

Switch the report scope and chart view to compare retained query volume, blocked activity, categories, domains, and resolver processing for eligible endpoints.

Searchable Query log

Full retained events can expose domain, result, category, endpoint, query type, and time for operational review inside the active retention window.

Decision and incident context

Explain shows recorded decision evidence, while measured incident records add detector window, threshold, occurrence, limitation, and privacy coverage.

Privacy-aware aggregation

Anonymized events remain account-level aggregate activity and are not reassigned to a named endpoint; Off logging creates no new durable DNS-event history.

FIRST-PARTY PRODUCT EVIDENCE

Move from a trend to the retained event that supports it.

Analytics summarizes eligible DNS activity; the Query Log provides the event-level view when Full history exists. Both remain bounded by profile privacy and retention, so an absent row is not evidence that a request never happened.

QueryWarden Overview dashboard with DNS query totals, blocked activity, resolver processing time, and a retained activity chart using synthetic demo data.Open full-size screenshot
Current QueryWarden Overview interface captured with deterministic demo data. No customer DNS activity is shown.

A practical investigation sequence

  1. 01
    Find a measured change

    Choose the correct date range and account or endpoint scope before comparing activity.

  2. 02
    Filter the Query Log

    Narrow retained Full events by endpoint, result, or hostname instead of treating a chart as the event record.

  3. 03
    Explain the decision

    Review the recorded result and decision source separately from policy that matches the hostname now.

  4. 04
    Corroborate before responding

    Use endpoint, identity, application, or other security evidence before declaring an incident or broadening a rule.

QueryWarden evidence field guide

Meaning and privacy boundary of common QueryWarden analytics and Query Log fields.
FieldWhat it representsBoundary
TimeThe recorded event time for retained DNS activity.Time ranges and expiry can remove older events from view.
ResultWhether the recorded DNS decision was allowed or blocked.A result alone does not establish user intent or device compromise.
DomainThe hostname attached to an eligible Full event.Unavailable in Anonymized and Off durable DNS history.
EndpointThe attributable direct device or Relay backing the eligible event.Anonymized events deliberately omit endpoint attribution.
ExplainRecorded decision evidence plus clearly separated current-policy context.Later policy changes do not rewrite the retained historical result.
HOW IT WORKS

From setup to an explainable DNS decision.

QueryWarden applies policy at the recursive DNS layer, before a supported client connects to the requested domain.

  1. 01

    Choose a time range within the plan boundary

    QueryWarden enables only the ranges supported by current retained data; Free supports no more than 48 hours rather than the planned paid windows.

  2. 02

    Set account or endpoint report scope

    Start with all eligible activity, then select one direct endpoint or Relay when attribution exists and a narrower report is needed.

  3. 03

    Move from trends to retained event evidence

    Use the Query log to search eligible domain rows and open Explain for the recorded decision source and clearly separated current-policy context.

  4. 04

    Record a deliberate incident response

    Review detector evidence and limitations, then acknowledge or resolve the operational item without deleting its retained evidence or automatically changing policy.

CLEAR BOUNDARIES

DNS analytics is not complete network surveillance

Charts and incidents summarize only the DNS events eligible for durable storage under the current profile settings and plan window.

  • Anonymized activity lacks hostname and endpoint attribution, so named endpoint totals can be lower than the account total.
  • Off logging creates no new durable DNS-event rows, which intentionally limits later troubleshooting, explanations, domain lists, and detector evidence.
  • QueryWarden does not capture packet payloads, full URLs, page content, application processes, or all connections made without its DNS path.
  • Paid plans with 7–90 days of durable analytics remain planned; those windows are not available to the current Free plan.
WHO AND HOW

Technical basis and product evidence

Published and reviewed by QueryWarden Engineering, Digiport OÜ. First-party review against the current public QueryWarden product, its documented deployment constraints, and the primary sources listed on this page. This is not an independent audit, certification, approval, or endorsement.

Product screenshots are deterministic captures of the current interface using synthetic accounts, devices, and reserved .test domains. External sources explain protocols and industry guidance; they do not verify QueryWarden implementation claims.

Last reviewed . Product availability can change; dashboard capability labels remain the source of truth. Review our Security & Trust disclosure.
QUESTIONS, ANSWERED

What to know before you change DNS.

How long does QueryWarden keep DNS query logs?

The available Free plan keeps eligible DNS event history for no more than 48 hours. A profile can choose a shorter supported duration, Anonymized activity, or Off. Longer paid windows remain planned.

Why do endpoint lines not add up to the account total?

Anonymized events are preserved only as Privacy-protected account activity and are never reassigned to a named endpoint. Removed or currently unavailable endpoints can also affect comparisons within a retained window.

Does a security incident prove a device was compromised?

No. It records that a documented detector threshold was met in the eligible retained DNS evidence. The detector limitation, privacy coverage, and surrounding endpoint evidence must be reviewed before deciding what happened.

START WITH THE AVAILABLE FREE PLAN

Measure only the DNS evidence you choose to retain.

Connect one endpoint, select its privacy setting, and inspect fresh Query log and analytics results inside the available 48-hour Free boundary.