Know the safe path before changing DNS.
Confirm in the router or forwarder documentation that it accepts a complete custom DNS-over-HTTPS URL.
Record the current LAN DNS, DHCP, IPv6, caching, and fallback settings so they can be restored.
Create a dedicated QueryWarden router device and understand that its activity can represent multiple LAN clients together.
Configure Router.
- Verify router compatibility first
Locate a documented custom DoH or HTTPS resolver URL field. Stop if the firmware accepts only IP addresses, a provider hostname, or a fixed provider list.
- Create a dedicated network endpoint
Use a QueryWarden device intended for this router or forwarder. Do not reuse a personal-device endpoint or publish the URL as a public resolver.
- Apply the full URL and review failover
Paste the complete private endpoint, save the configuration, and decide whether any alternate resolver would bypass QueryWarden during failure.
- Test one LAN client before broad rollout
Select Start traffic check in QueryWarden, renew DNS settings on one controlled client when necessary, and generate a new request before relying on router-wide protection.
Confirm that fresh endpoint activity reaches QueryWarden.
Select Start traffic check for the dedicated router device before testing a LAN client.
Generate a new lookup from a client that receives DNS settings from this router or forwarder.
Confirm fresh QueryWarden activity, then test IPv4, IPv6, restart behavior, and any configured fallback before expanding the rollout.
Return to a known working resolver safely.
Restore the recorded upstream DNS, DHCP, IPv6 advertisement, and fallback settings on the router or forwarder.
Restart or renew one test client and confirm that it resolves through the restored path before changing the rest of the LAN.
Rotate the QueryWarden endpoint if it was exposed in a router export, screenshot, cloud backup, or support bundle.
Resolve the most likely setup problems.
- The router rejects the URL.
Its firmware may not support a custom DoH endpoint. Do not put the URL in a plain DNS or DNS-over-TLS field; consider a compatible forwarder or QueryWarden Relay.
- Some clients bypass the router.
Check DHCP and IPv6 DNS advertisements, client-level secure DNS, VPNs, cached leases, and any hard-coded resolver behavior.
- QueryWarden shows one device for the whole network.
That is expected for a direct router endpoint. It represents the router or forwarder rather than identifying every LAN client.
Choose another deployment path.
Ready to protect this device?
Create the private endpoint in QueryWarden, follow this guide, and check for fresh endpoint activity before considering setup complete.