IPHONE AND IPAD INSTALLATION

Set up QueryWarden on iPhone or iPad

The authenticated dashboard can generate an Apple DNS profile for one iPhone or iPad endpoint. Apple will show that the current profile is unsigned; review its QueryWarden name and DNS payload before installation.

Available · unsigned Apple profile Available now activity check
PREPARE

Know the safe path before changing DNS.

  1. Create a QueryWarden device with iPhone / iPad selected and open its Connection setup panel.

  2. Use a device you administer and check whether Screen Time or mobile-device management restricts profile installation.

  3. Treat the downloaded profile as sensitive because it contains the private endpoint for this device.

INSTALL

Configure iPhone and iPad.

  1. Use the Apple profile—not an endpoint QR

    On the intended iPhone or iPad, open Devices in QueryWarden, select this device, expand Connection setup, and choose Download Apple profile (unsigned). A QR containing a DoH URL is not an Apple installer and cannot configure iOS or iPadOS by itself.

  2. Open the downloaded profile in Settings

    After the download prompt, open Settings and choose Profile Downloaded. If that entry is not visible, open General → VPN & Device Management and select the downloaded QueryWarden profile.

  3. Review and approve installation

    Confirm that the display name refers to QueryWarden and the payload configures encrypted DNS, then choose Install. The device passcode may be required and Apple will mark the current distribution as unsigned. Do not approve it on a shared or organization-managed device without authority.

  4. Begin a live traffic check

    Return to the selected device in QueryWarden, select Start traffic check, and then create new browsing activity on the iPhone or iPad.

CHECK ACTIVITY

Confirm that fresh endpoint activity reaches QueryWarden.

  1. Select Start traffic check from the matching QueryWarden device panel.

  2. Open a destination that the iPhone or iPad has not recently requested, or restart the relevant app before testing.

  3. Wait for QueryWarden to report a request newer than the check start time; earlier or cached requests do not count.

ROLL BACK

Return to a known working resolver safely.

  1. Open the device’s profile or VPN & Device Management settings and remove the QueryWarden DNS profile.

  2. Confirm that the device returns to its previous DNS behavior after removal.

  3. Rotate the QueryWarden endpoint if the profile was forwarded, published, installed on the wrong device, or otherwise exposed.

TROUBLESHOOT

Resolve the most likely setup problems.

  1. Settings does not offer profile installation.

    Open the downloaded file again and check profile-management restrictions. A managed device can prevent user-installed DNS profiles.

  2. Scanning the QR did not install anything.

    That is expected for a raw DNS-over-HTTPS endpoint QR. iPhone and iPad installation uses the Apple profile download and still requires deliberate review in Settings.

  3. Apple reports that the profile is unsigned.

    This is the truthful status of the current QueryWarden profile. Verify its source and contents before choosing whether to install it.

  4. A second QueryWarden profile appears after re-downloading.

    Profiles downloaded before stable device identifiers were introduced can remain as a separate legacy entry. Remove the older QueryWarden profile before installing the current download, and do not leave both active.

  5. QueryWarden sees no new request.

    Select Start traffic check first, open a new destination, confirm the profile remains installed, and check whether the current network is allowed by source-IP restrictions.

RELATED INSTALLATION GUIDES

Choose another deployment path.

Ready to protect this device?

Create the private endpoint in QueryWarden, follow this guide, and check for fresh endpoint activity before considering setup complete.