Know the safe path before changing DNS.
Create a QueryWarden device with Android selected.
Choose an Android DNS app whose documentation explicitly supports a full custom DNS-over-HTTPS URL.
Check for an existing VPN, work profile, or device-management policy that could conflict with the DNS app.
Configure Android.
- Use a custom-DoH app, not system Private DNS
Open the chosen compatible DNS app. Do not paste the QueryWarden URL into Android Settings → Private DNS; that field expects a DNS-over-TLS hostname and cannot accept the current endpoint.
- Add the complete endpoint privately
Copy the endpoint from the selected QueryWarden device and paste it into the app’s custom DoH URL field. Keep every part of the URL unchanged and do not share it between unrelated users.
- Resolve app and VPN conflicts
Enable the DNS app and review any local-VPN permission it requests. Android often permits only one active VPN-style service, so confirm that the choice does not disable another required connection.
- Check Android endpoint activity
Select Start traffic check in QueryWarden and then open a new destination on the Android device through the configured app.
Confirm that fresh endpoint activity reaches QueryWarden.
Select Start traffic check on the matching QueryWarden device before opening the test destination.
Generate a new lookup from an app covered by the chosen Android DNS client.
Confirm that QueryWarden records fresh activity and that pausing the DNS app removes that configured path during a controlled check.
Return to a known working resolver safely.
Disable or remove the custom provider from the Android DNS app, then stop the app’s local VPN connection when it uses one.
Restore the previous DNS or VPN configuration and confirm that other required network software still works.
Rotate the QueryWarden endpoint if it was pasted into the wrong app, shared, or captured in a screenshot.
Resolve the most likely setup problems.
- Android asks for a provider hostname.
You are in system Private DNS, which requires DNS-over-TLS and is not compatible with the current QueryWarden private DoH URL. Use a compatible custom-DoH app.
- The DNS app will not start while a VPN is active.
Review whether both products use Android’s local VPN slot. Choose one path deliberately; do not disable an organization VPN without authorization.
- The traffic check remains pending.
Confirm the DNS app is active, select Start traffic check again, request a new domain, and inspect whether the app reports fallback or connection failure.
Choose another deployment path.
Ready to protect this device?
Create the private endpoint in QueryWarden, follow this guide, and check for fresh endpoint activity before considering setup complete.