Know the safe path before changing DNS.
Use a supported Linux host that you administer and that can remain available to the intended LAN.
Review the technical-preview status, package checksum, local listener, firewall boundary, and rollback plan before installation.
Provision a dedicated Relay in QueryWarden; do not substitute a direct-device endpoint or share the one-time enrollment token.
Configure QueryWarden Relay.
- Provision a dedicated Relay
Open the Relay workspace in QueryWarden and create a Relay for this network. The one-time enrollment token is a secret and should be pasted only into the enrollment prompt.
- Download and verify the unsigned package
Download the versioned Relay archive and its SHA-256 file from QueryWarden. Compare the checksum on the Linux host before installing the technical preview as root.
- Enroll without exposing the token
Run the Relay enrollment command as the locked service user and paste the token through standard input when prompted. Do not place it in a command-line argument, shell history, ticket, or configuration file.
- Start locally and expand deliberately
Keep the safe local-only listener while validating service status and QueryWarden check-in. Change LAN routing or listener exposure only after reviewing firewall and network boundaries.
Confirm that fresh endpoint activity reaches QueryWarden.
Confirm the Relay service is running and reports a current control-plane check-in without exposing credentials.
Start with one controlled LAN client and generate a fresh DNS request through the Relay listener.
Verify QueryWarden activity, then test UDP and TCP resolution, restart behavior, and the documented failure mode before wider use.
Return to a known working resolver safely.
Restore the router or DHCP DNS settings so clients no longer depend on the Relay listener.
Stop and disable the QueryWarden Relay service, then verify that LAN clients resolve through the restored path.
Revoke the Relay in the QueryWarden dashboard before uninstalling it. Preserve local state only when deliberate recovery or audit needs require it.
Resolve the most likely setup problems.
- The checksum does not match.
Do not install or run the package. Download both files again from QueryWarden and investigate any persistent mismatch.
- Enrollment is rejected or expired.
Create a new one-time enrollment transaction in the dashboard and paste it only when prompted. Do not reuse a consumed or exposed token.
- Relay checks in but LAN clients do not resolve.
Keep the rollout bounded and inspect the listener address, local firewall, router or DHCP DNS settings, service status, and configured upstream path.
Choose another deployment path.
Ready to deploy this Relay?
Provision the Relay in QueryWarden, follow this beta guide, and confirm check-in plus fresh endpoint activity before directing LAN clients to it.