WINDOWS INSTALLATION

Set up QueryWarden on Windows

QueryWarden currently supplies a private DNS-over-HTTPS URL rather than a signed native Windows application. Use it only in Windows software that explicitly accepts a complete custom DoH provider URL.

Available with a compatible custom-DoH client Available now activity check
PREPARE

Know the safe path before changing DNS.

  1. Create a QueryWarden device with Windows selected and identify the exact browser or DNS client you plan to configure.

  2. Check that the chosen client documents support for a complete custom DNS-over-HTTPS URL, not only an IP address or preset provider.

  3. Know how to restore the client’s previous DNS setting before changing it.

INSTALL

Configure Windows.

  1. Choose a documented custom-DoH field

    Open the secure DNS settings of the selected Windows browser or client. Continue only when its documentation says the field accepts a full HTTPS resolver URL.

  2. Copy the complete private endpoint

    From the matching QueryWarden device, copy the endpoint exactly. Preserve the protocol, hostname, path, and private identifier; do not shorten it or substitute only the hostname.

  3. Save and inspect fallback behavior

    Apply the client setting and review whether it silently returns to the system resolver when custom DoH fails. Choose fallback behavior deliberately according to your availability needs.

  4. Check new Windows endpoint activity

    Select Start traffic check in QueryWarden, then generate a new request from the same configured browser or client.

CHECK ACTIVITY

Confirm that fresh endpoint activity reaches QueryWarden.

  1. Select Start traffic check in QueryWarden before using the configured Windows client.

  2. Request a new domain from that client and avoid relying on a tab or lookup already held in cache.

  3. Confirm fresh activity on the correct QueryWarden device and check that disabling the custom provider stops that test path as expected.

ROLL BACK

Return to a known working resolver safely.

  1. Restore the browser or DNS client setting recorded before installation, or disable its custom provider option.

  2. Close and reopen the affected application, then confirm normal resolution through the intended previous resolver.

  3. Rotate the QueryWarden endpoint if it was written into a public configuration, log, screenshot, or support ticket.

TROUBLESHOOT

Resolve the most likely setup problems.

  1. The Windows setting accepts only an IP address.

    That is not a compatible custom-DoH URL field. Use a browser or DNS client that accepts the complete HTTPS endpoint.

  2. Browsing works but QueryWarden records nothing.

    The client may be using the Windows system resolver or falling back. Check its active provider status and generate traffic from the exact client you configured.

  3. The endpoint is rejected after a network change.

    Review the selected device’s source-IP restrictions and compare them with the current public egress address before changing the client.

RELATED INSTALLATION GUIDES

Choose another deployment path.

Ready to protect this device?

Create the private endpoint in QueryWarden, follow this guide, and check for fresh endpoint activity before considering setup complete.