Know the safe path before changing DNS.
Create a QueryWarden device with Linux selected and choose whether one browser, the host, or a local forwarder will use it.
Confirm that the chosen software accepts a full custom DNS-over-HTTPS URL and document its current resolver setting.
Plan secret-safe storage so the private endpoint does not enter shell history, public dotfiles, logs, or a shared repository.
Configure Linux.
- Choose the protection scope
Decide whether the endpoint belongs in one browser, a host-level DNS client, or a local forwarder. A direct device endpoint should not be copied broadly across an unmanaged LAN.
- Confirm complete custom-DoH support
Review the selected software documentation and locate the setting for a full HTTPS resolver URL. A nameserver IP field or DNS-over-TLS hostname field is not equivalent.
- Store the endpoint without leaking it
Copy the endpoint from QueryWarden into a permission-restricted configuration path or protected application field. Avoid command-line arguments, terminal recordings, and version-controlled files.
- Start the client and check activity
Apply the change, inspect the client for errors or fallback, select Start traffic check in QueryWarden, and generate a fresh lookup through the configured scope.
Confirm that fresh endpoint activity reaches QueryWarden.
Select Start traffic check in QueryWarden before issuing the test lookup.
Generate the request through the exact browser, client, or forwarder configured with the endpoint.
Confirm a fresh event on the correct device and inspect the local client status for silent fallback.
Return to a known working resolver safely.
Restore the client or resolver configuration saved before the change and restart only the relevant user service or application.
Confirm that the host resolves through the intended previous path and that no stale local forwarding process remains active.
Remove exposed copies and rotate the QueryWarden endpoint if it entered shell history, logs, a repository, or a shared configuration system.
Resolve the most likely setup problems.
- The resolver accepts only nameserver IP addresses.
Choose a separate client or forwarder with explicit custom-DoH URL support. Do not paste the private URL into an IP field.
- Only one browser appears in QueryWarden.
The endpoint may be configured at browser scope rather than host scope. That is valid, but other applications will continue using their existing resolver.
- The client works only with fallback enabled.
Inspect its DoH connection error, certificate trust, proxy, and source-IP access before deciding whether fallback is acceptable.
Choose another deployment path.
Ready to protect this device?
Create the private endpoint in QueryWarden, follow this guide, and check for fresh endpoint activity before considering setup complete.