Know the safe path before changing DNS.
Create a QueryWarden device with Windows selected and identify the exact browser or DNS client you plan to configure.
Check that the chosen client documents support for a complete custom DNS-over-HTTPS URL, not only an IP address or preset provider.
Know how to restore the client’s previous DNS setting before changing it.
Configure Windows.
- Choose a documented custom-DoH field
Open the secure DNS settings of the selected Windows browser or client. Continue only when its documentation says the field accepts a full HTTPS resolver URL.
- Copy the complete private endpoint
From the matching QueryWarden device, copy the endpoint exactly. Preserve the protocol, hostname, path, and private identifier; do not shorten it or substitute only the hostname.
- Save and inspect fallback behavior
Apply the client setting and review whether it silently returns to the system resolver when custom DoH fails. Choose fallback behavior deliberately according to your availability needs.
- Check new Windows endpoint activity
Select Start traffic check in QueryWarden, then generate a new request from the same configured browser or client.
Confirm that fresh endpoint activity reaches QueryWarden.
Select Start traffic check in QueryWarden before using the configured Windows client.
Request a new domain from that client and avoid relying on a tab or lookup already held in cache.
Confirm fresh activity on the correct QueryWarden device and check that disabling the custom provider stops that test path as expected.
Return to a known working resolver safely.
Restore the browser or DNS client setting recorded before installation, or disable its custom provider option.
Close and reopen the affected application, then confirm normal resolution through the intended previous resolver.
Rotate the QueryWarden endpoint if it was written into a public configuration, log, screenshot, or support ticket.
Resolve the most likely setup problems.
- The Windows setting accepts only an IP address.
That is not a compatible custom-DoH URL field. Use a browser or DNS client that accepts the complete HTTPS endpoint.
- Browsing works but QueryWarden records nothing.
The client may be using the Windows system resolver or falling back. Check its active provider status and generate traffic from the exact client you configured.
- The endpoint is rejected after a network change.
Review the selected device’s source-IP restrictions and compare them with the current public egress address before changing the client.
Choose another deployment path.
Ready to protect this device?
Create the private endpoint in QueryWarden, follow this guide, and check for fresh endpoint activity before considering setup complete.