MACOS INSTALLATION

Set up QueryWarden on macOS

QueryWarden can generate an Apple DNS configuration profile tied to one private device endpoint. Downloading the file only stages it for review: “Profile downloaded” means approval is pending and DNS is not active. The current profile is not digitally signed; signing would improve its identity and trust presentation, but would not automate installation or remove Apple’s approval step.

Available · unsigned Apple profile Available now activity check
PREPARE

Know the safe path before changing DNS.

  1. Create a QueryWarden device with macOS selected and keep its Connection setup panel open in a trusted browser session.

  2. Confirm that you administer the Mac and can review or remove configuration profiles in System Settings.

  3. Close or redact any screen that displays the private endpoint before taking a screenshot or asking for help.

INSTALL

Configure macOS.

  1. Download the profile from the selected device

    In QueryWarden, open Devices, select this Mac, expand Connection setup, and choose Apple profile. Download it only on the intended Mac or through a trusted transfer path. The download itself does not change the Mac’s DNS settings.

  2. Open the pending profile on current macOS

    If macOS reports “Profile downloaded,” approval is still pending and QueryWarden DNS is not active. Open Apple menu → System Settings → General → Device Management → Downloaded, then select the QueryWarden profile.

  3. Use the downloaded file or legacy settings when needed

    If Downloaded is not shown, open Finder → Downloads and double-click the QueryWarden `.mobileconfig` file, then return to Device Management. On macOS 12 or earlier, open Apple menu → System Preferences → Profiles and select the downloaded profile there.

  4. Inspect the profile before approval

    Confirm that the profile names QueryWarden, contains a managed DNS-over-HTTPS payload, and refers to the device endpoint you just created. macOS will identify the current profile as unsigned.

  5. Approve it on the intended Mac

    Choose Install and provide administrator confirmation when required. A future signature could improve publisher verification, but it would not make the downloaded profile install itself. A managed Mac may block user-installed profiles; do not bypass organization policy, and ask the device administrator to approve or deploy the configuration.

  6. Start a fresh traffic check

    Return to the selected device in QueryWarden and choose Start traffic check before opening a new destination on the Mac.

CHECK ACTIVITY

Confirm that fresh endpoint activity reaches QueryWarden.

  1. Select Start traffic check in QueryWarden before generating the test request.

  2. Open a new website or perform a fresh lookup on the Mac so cached activity does not mask the test.

  3. Confirm that QueryWarden records activity after the check start time and that the selected device becomes active.

ROLL BACK

Return to a known working resolver safely.

  1. On macOS 13 or later, open Apple menu → System Settings → General → Device Management → QueryWarden DNS profile → Remove, then confirm removal.

  2. On macOS 12 or earlier, open Apple menu → System Preferences → Profiles → QueryWarden DNS profile, choose the remove (−) control, and confirm.

  3. Restore the prior DNS setting only if you intentionally changed a separate browser or network resolver.

  4. If the profile or endpoint may have been copied elsewhere, rotate the endpoint from QueryWarden rather than relying on local removal alone.

TROUBLESHOOT

Resolve the most likely setup problems.

  1. macOS says “Profile downloaded,” but DNS did not change.

    The message confirms only that macOS staged the file. Open Apple menu → System Settings → General → Device Management → Downloaded, select QueryWarden, review it, and explicitly approve installation before testing DNS.

  2. Downloaded does not appear in Device Management.

    Open Finder → Downloads and double-click the QueryWarden `.mobileconfig` file, then check Device Management again. On macOS 12 or earlier, use Apple menu → System Preferences → Profiles instead.

  3. macOS says the profile is unsigned.

    That warning is expected for the current release. Confirm the file came from your authenticated QueryWarden device panel and review its DNS payload before deciding to continue. A signed profile would still require installation approval.

  4. A second QueryWarden profile appears after re-downloading.

    Profiles downloaded before stable device identifiers were introduced can remain as a separate legacy entry. Remove the older QueryWarden profile before installing the current download, and do not leave both active.

  5. The profile cannot be installed.

    Check whether the Mac is managed or user-installed profiles are restricted. Do not bypass an organization policy; ask the device administrator to review or deploy the profile.

  6. The traffic check stays pending.

    Confirm the profile is enabled, select Start traffic check again, request a destination that is not cached, and review source-IP restrictions for the device.

RELATED INSTALLATION GUIDES

Choose another deployment path.

Ready to protect this device?

Create the private endpoint in QueryWarden, follow this guide, and check for fresh endpoint activity before considering setup complete.