Account and endpoint trends
Switch the report scope and chart view to compare retained query volume, blocked activity, categories, domains, and resolver processing for eligible endpoints.
QueryWarden turns eligible retained DNS activity into a searchable Query log, account and endpoint analytics, decision explanations, and measured incident records. What appears depends on the profile’s Full, Anonymized, or Off logging mode and the account retention window.
The analytics workspace summarizes retained query and block activity. The Query log then narrows to eligible event rows, while Explain and Incidents add decision-source and detector context without inventing detail removed by privacy settings.
Each capability below reflects the current public product, with beta and compatibility limits called out separately.
Switch the report scope and chart view to compare retained query volume, blocked activity, categories, domains, and resolver processing for eligible endpoints.
Full retained events can expose domain, result, category, endpoint, query type, and time for operational review inside the active retention window.
Explain shows recorded decision evidence, while measured incident records add detector window, threshold, occurrence, limitation, and privacy coverage.
Anonymized events remain account-level aggregate activity and are not reassigned to a named endpoint; Off logging creates no new durable DNS-event history.
Analytics summarizes eligible DNS activity; the Query Log provides the event-level view when Full history exists. Both remain bounded by profile privacy and retention, so an absent row is not evidence that a request never happened.
Open full-size screenshot Choose the correct date range and account or endpoint scope before comparing activity.
Narrow retained Full events by endpoint, result, or hostname instead of treating a chart as the event record.
Review the recorded result and decision source separately from policy that matches the hostname now.
Use endpoint, identity, application, or other security evidence before declaring an incident or broadening a rule.
| Field | What it represents | Boundary |
|---|---|---|
| Time | The recorded event time for retained DNS activity. | Time ranges and expiry can remove older events from view. |
| Result | Whether the recorded DNS decision was allowed or blocked. | A result alone does not establish user intent or device compromise. |
| Domain | The hostname attached to an eligible Full event. | Unavailable in Anonymized and Off durable DNS history. |
| Endpoint | The attributable direct device or Relay backing the eligible event. | Anonymized events deliberately omit endpoint attribution. |
| Explain | Recorded decision evidence plus clearly separated current-policy context. | Later policy changes do not rewrite the retained historical result. |
QueryWarden applies policy at the recursive DNS layer, before a supported client connects to the requested domain.
QueryWarden enables only the ranges supported by current retained data; Free supports no more than 48 hours rather than the planned paid windows.
Start with all eligible activity, then select one direct endpoint or Relay when attribution exists and a narrower report is needed.
Use the Query log to search eligible domain rows and open Explain for the recorded decision source and clearly separated current-policy context.
Review detector evidence and limitations, then acknowledge or resolve the operational item without deleting its retained evidence or automatically changing policy.
Charts and incidents summarize only the DNS events eligible for durable storage under the current profile settings and plan window.
Published and reviewed by QueryWarden Engineering, Digiport OÜ. First-party review against the current public QueryWarden product, its documented deployment constraints, and the primary sources listed on this page. This is not an independent audit, certification, approval, or endorsement.
Product screenshots are deterministic captures of the current interface using synthetic accounts, devices, and reserved .test domains. External sources explain protocols and industry guidance; they do not verify QueryWarden implementation claims.
Last reviewed . Product availability can change; dashboard capability labels remain the source of truth. Review our Security & Trust disclosure.These primary sources support the general technical context. Citing them does not mean their publishers evaluated, approved, or endorsed QueryWarden.
The available Free plan keeps eligible DNS event history for no more than 48 hours. A profile can choose a shorter supported duration, Anonymized activity, or Off. Longer paid windows remain planned.
Anonymized events are preserved only as Privacy-protected account activity and are never reassigned to a named endpoint. Removed or currently unavailable endpoints can also affect comparisons within a retained window.
No. It records that a documented detector threshold was met in the eligible retained DNS evidence. The detector limitation, privacy coverage, and surrounding endpoint evidence must be reviewed before deciding what happened.
Connect one endpoint, select its privacy setting, and inspect fresh Query log and analytics results inside the available 48-hour Free boundary.