QUERYWARDEN INSTALLATION

Install QueryWarden on a device or network.

Choose a compatible setup method, connect the device or network to QueryWarden’s private DNS firewall through its private DNS-over-HTTPS endpoint, then check for fresh endpoint activity.

Private encrypted endpoint Fresh endpoint activity check Treat the endpoint as a secret
CHOOSE YOUR PLATFORM

Follow the guide for the device in front of you.

Every guide names the working method, its limits, an endpoint-activity check, and a safe rollback.

Available · unsigned Apple profile

macOS

Unsigned Apple DNS configuration profile

QueryWarden can generate an Apple DNS configuration profile tied to one private device endpoint. Downloading the file only stages it for review: “Profile downloaded” means approval is pending and DNS is not active. The current profile is not digitally signed; signing would improve its identity and trust presentation, but would not automate installation or remove Apple’s approval step.

  • The current Apple configuration profile is not digitally signed.
  • Whether signed or unsigned, downloading a profile does not install it automatically; macOS requires explicit approval unless an organization deploys it through device management.
Open macOS guide
Available · unsigned Apple profile

iPhone and iPad

Unsigned Apple DNS configuration profile

The authenticated dashboard can generate an Apple DNS profile for one iPhone or iPad endpoint. Apple will show that the current profile is unsigned; review its QueryWarden name and DNS payload before installation.

  • The current Apple configuration profile is not digitally signed.
  • Device-management restrictions can prevent a user-installed DNS profile.
Open iPhone and iPad guide
Available with a compatible custom-DoH client

Windows

Compatible Windows browser or custom-DoH client

QueryWarden currently supplies a private DNS-over-HTTPS URL rather than a signed native Windows application. Use it only in Windows software that explicitly accepts a complete custom DoH provider URL.

  • Windows and client versions differ; use only a setting documented to accept a full custom DoH URL.
  • A field that accepts only an IP address or provider hostname is not the required custom-DoH field.
Open Windows guide
Available through a compatible custom-DoH app

Android

Compatible Android app with a custom DoH URL

Android system Private DNS is not compatible with the current QueryWarden endpoint because that system field requires a DNS-over-TLS hostname. Today’s supported path is a compatible Android app that accepts a complete custom DNS-over-HTTPS URL.

  • Android system Private DNS requires a DNS-over-TLS hostname and cannot accept the current QueryWarden private DoH URL.
  • A compatible third-party DNS app is required until QueryWarden publishes a supported native method.
Open Android guide
Available with a compatible custom-DoH client

Linux

Compatible Linux browser, DNS client, or local forwarder

Linux does not have one universal DNS configuration path. Use a browser, DNS client, or local forwarder that explicitly accepts a complete custom DNS-over-HTTPS URL, and keep the private endpoint out of command history and public configuration.

  • Linux resolver stacks vary; QueryWarden has not certified every distribution or DNS client.
  • Do not place the private endpoint directly in a shell command that will be retained in history.
Open Linux guide
Conditional · custom DoH support required

Router

Router or local forwarder with full custom-DoH URL support

Direct router setup works only when the router or its local DNS forwarder accepts a complete custom DNS-over-HTTPS URL. Plain DNS server fields and DNS-over-TLS hostname fields cannot use the private QueryWarden endpoint.

  • Many routers accept only DNS server IP addresses or DNS-over-TLS hostnames; those fields cannot use this private DoH URL.
  • A router endpoint can represent many LAN clients as one QueryWarden device.
Open Router guide
Beta · unsigned Linux technical preview

QueryWarden Relay

QueryWarden Relay on a supported Linux host

QueryWarden Relay is a beta, unsigned Linux technical preview for networks that cannot send a custom DoH URL directly from the router. It is a local DNS forwarder, not a VPN, DHCP server, remote-management agent, or signed native client.

  • QueryWarden Relay is an unsigned Linux technical preview, not a signed native client or managed updater.
  • It requires a maintained Linux host and deliberate router or DHCP configuration for LAN clients.
Open QueryWarden Relay guide
THE SAFE PATH

Four steps every installation shares.

The platform changes the controls—not the need to protect the endpoint and confirm that fresh activity arrived.

  1. 1

    Create the protected endpoint

    Sign in, create a device with the closest platform, and assign the protection profile that should govern its new DNS requests.

  2. 2

    Choose a compatible installation method

    Use the platform guide below. Install the complete private DoH URL only in a supported client or use the generated Apple profile or Relay workflow.

  3. 3

    Check endpoint activity after setup

    Select Start traffic check in QueryWarden, generate a new DNS request from the configured device or network, and wait for activity newer than the check start time.

  4. 4

    Keep a tested rollback path

    Record the previous DNS setting, know how to remove the profile or client configuration, and rotate the private endpoint if it may have been exposed.

PRIVATE ENDPOINT

Treat the connection URL like a password.

Do not publish it, add it to a screenshot, paste it into a public issue, or reuse it as a public resolver. Rotate the endpoint immediately if it may have been exposed.

Secure troubleshooting