Choose a compatible setup method, connect the device or network to QueryWarden’s private DNS firewall through its private DNS-over-HTTPS endpoint, then check for fresh endpoint activity.
Private encrypted endpoint Fresh endpoint activity check Treat the endpoint as a secret
CHOOSE YOUR PLATFORM
Follow the guide for the device in front of you.
Every guide names the working method, its limits, an endpoint-activity check, and a safe rollback.
Available · unsigned Apple profile
macOS
Unsigned Apple DNS configuration profile
QueryWarden can generate an Apple DNS configuration profile tied to one private device endpoint. Downloading the file only stages it for review: “Profile downloaded” means approval is pending and DNS is not active. The current profile is not digitally signed; signing would improve its identity and trust presentation, but would not automate installation or remove Apple’s approval step.
The current Apple configuration profile is not digitally signed.
Whether signed or unsigned, downloading a profile does not install it automatically; macOS requires explicit approval unless an organization deploys it through device management.
The authenticated dashboard can generate an Apple DNS profile for one iPhone or iPad endpoint. Apple will show that the current profile is unsigned; review its QueryWarden name and DNS payload before installation.
The current Apple configuration profile is not digitally signed.
Device-management restrictions can prevent a user-installed DNS profile.
QueryWarden currently supplies a private DNS-over-HTTPS URL rather than a signed native Windows application. Use it only in Windows software that explicitly accepts a complete custom DoH provider URL.
Windows and client versions differ; use only a setting documented to accept a full custom DoH URL.
A field that accepts only an IP address or provider hostname is not the required custom-DoH field.
Android system Private DNS is not compatible with the current QueryWarden endpoint because that system field requires a DNS-over-TLS hostname. Today’s supported path is a compatible Android app that accepts a complete custom DNS-over-HTTPS URL.
Android system Private DNS requires a DNS-over-TLS hostname and cannot accept the current QueryWarden private DoH URL.
A compatible third-party DNS app is required until QueryWarden publishes a supported native method.
Compatible Linux browser, DNS client, or local forwarder
Linux does not have one universal DNS configuration path. Use a browser, DNS client, or local forwarder that explicitly accepts a complete custom DNS-over-HTTPS URL, and keep the private endpoint out of command history and public configuration.
Linux resolver stacks vary; QueryWarden has not certified every distribution or DNS client.
Do not place the private endpoint directly in a shell command that will be retained in history.
Router or local forwarder with full custom-DoH URL support
Direct router setup works only when the router or its local DNS forwarder accepts a complete custom DNS-over-HTTPS URL. Plain DNS server fields and DNS-over-TLS hostname fields cannot use the private QueryWarden endpoint.
Many routers accept only DNS server IP addresses or DNS-over-TLS hostnames; those fields cannot use this private DoH URL.
A router endpoint can represent many LAN clients as one QueryWarden device.
QueryWarden Relay is a beta, unsigned Linux technical preview for networks that cannot send a custom DoH URL directly from the router. It is a local DNS forwarder, not a VPN, DHCP server, remote-management agent, or signed native client.
QueryWarden Relay is an unsigned Linux technical preview, not a signed native client or managed updater.
It requires a maintained Linux host and deliberate router or DHCP configuration for LAN clients.
The platform changes the controls—not the need to protect the endpoint and confirm that fresh activity arrived.
1
Create the protected endpoint
Sign in, create a device with the closest platform, and assign the protection profile that should govern its new DNS requests.
2
Choose a compatible installation method
Use the platform guide below. Install the complete private DoH URL only in a supported client or use the generated Apple profile or Relay workflow.
3
Check endpoint activity after setup
Select Start traffic check in QueryWarden, generate a new DNS request from the configured device or network, and wait for activity newer than the check start time.
4
Keep a tested rollback path
Record the previous DNS setting, know how to remove the profile or client configuration, and rotate the private endpoint if it may have been exposed.
PRIVATE ENDPOINT
Treat the connection URL like a password.
Do not publish it, add it to a screenshot, paste it into a public issue, or reuse it as a public resolver. Rotate the endpoint immediately if it may have been exposed.