ROUTER INSTALLATION

Set up QueryWarden on a compatible router

Direct router setup works only when the router or its local DNS forwarder accepts a complete custom DNS-over-HTTPS URL. Plain DNS server fields and DNS-over-TLS hostname fields cannot use the private QueryWarden endpoint.

Conditional · custom DoH support required Available now activity check
PREPARE

Know the safe path before changing DNS.

  1. Confirm in the router or forwarder documentation that it accepts a complete custom DNS-over-HTTPS URL.

  2. Record the current LAN DNS, DHCP, IPv6, caching, and fallback settings so they can be restored.

  3. Create a dedicated QueryWarden router device and understand that its activity can represent multiple LAN clients together.

INSTALL

Configure Router.

  1. Verify router compatibility first

    Locate a documented custom DoH or HTTPS resolver URL field. Stop if the firmware accepts only IP addresses, a provider hostname, or a fixed provider list.

  2. Create a dedicated network endpoint

    Use a QueryWarden device intended for this router or forwarder. Do not reuse a personal-device endpoint or publish the URL as a public resolver.

  3. Apply the full URL and review failover

    Paste the complete private endpoint, save the configuration, and decide whether any alternate resolver would bypass QueryWarden during failure.

  4. Test one LAN client before broad rollout

    Select Start traffic check in QueryWarden, renew DNS settings on one controlled client when necessary, and generate a new request before relying on router-wide protection.

CHECK ACTIVITY

Confirm that fresh endpoint activity reaches QueryWarden.

  1. Select Start traffic check for the dedicated router device before testing a LAN client.

  2. Generate a new lookup from a client that receives DNS settings from this router or forwarder.

  3. Confirm fresh QueryWarden activity, then test IPv4, IPv6, restart behavior, and any configured fallback before expanding the rollout.

ROLL BACK

Return to a known working resolver safely.

  1. Restore the recorded upstream DNS, DHCP, IPv6 advertisement, and fallback settings on the router or forwarder.

  2. Restart or renew one test client and confirm that it resolves through the restored path before changing the rest of the LAN.

  3. Rotate the QueryWarden endpoint if it was exposed in a router export, screenshot, cloud backup, or support bundle.

TROUBLESHOOT

Resolve the most likely setup problems.

  1. The router rejects the URL.

    Its firmware may not support a custom DoH endpoint. Do not put the URL in a plain DNS or DNS-over-TLS field; consider a compatible forwarder or QueryWarden Relay.

  2. Some clients bypass the router.

    Check DHCP and IPv6 DNS advertisements, client-level secure DNS, VPNs, cached leases, and any hard-coded resolver behavior.

  3. QueryWarden shows one device for the whole network.

    That is expected for a direct router endpoint. It represents the router or forwarder rather than identifying every LAN client.

RELATED INSTALLATION GUIDES

Choose another deployment path.

Ready to protect this device?

Create the private endpoint in QueryWarden, follow this guide, and check for fresh endpoint activity before considering setup complete.