AD AND TRACKER BLOCKING DNS

Block matching ad and tracker domains before they load.

QueryWarden applies managed ad and tracker domain sources in the DNS resolution path used by a configured endpoint. This can prevent a matching third-party hostname from resolving, while profiles, schedules, and scoped rules keep the policy visible and adjustable.

Managed ad and tracker domain controls are available now Every direct device uses a private DNS-over-HTTPS endpoint Scoped allow and block rules support deliberate exceptions
DNS decision pathIllustrative request
Configured device
Private DoH
Ad and tracker policy
Allowed destination
Policy checked before connectionDecision evidence is reviewable when the profile retains it.
WHAT DNS-LEVEL BLOCKING DOES

Stop a matching hostname request before the connection begins.

Many advertisements and trackers load from hostnames that are separate from the page or application a person wants to use. When one of those hostnames matches active policy, QueryWarden can return a DNS block instead of an address for the destination.

BUILT INTO THE PRODUCT

Controls you can use and verify.

Each capability below reflects the current public product, with beta and compatibility limits called out separately.

Managed domain decisions

Active ad and tracker sources can block a matching third-party hostname before the browser, app, television, or other configured client connects to it.

Policy by profile

Protection, schedules, service controls, custom rules, and privacy choices stay attached to the profile assigned to each available endpoint.

A decision you can review

When Full history is active and the event is still retained, the Query Log can show the recorded DNS result and its decision source.

Narrow exceptions

An account owner can preview a hostname and create an exact or deliberate subdomain allow rule for the selected audience and duration.

FIRST-PARTY PRODUCT EVIDENCE

See the profile that decides which domain controls apply.

The current protection-profile workspace keeps managed ad and tracker controls beside schedules, privacy, other DNS protections, and endpoint assignment. The synthetic example shows the available policy surface without claiming that one setting can remove every ad.

QueryWarden protection profile controls showing DNS security, content controls, schedules, privacy, and device assignment settings.Open full-size screenshot
Current QueryWarden protection-profile interface captured with a synthetic profile and no customer policy data.
MANAGED CONTROL

Match known ad and tracker domains

The profile can enable managed domain sources. A block occurs only when the requested hostname matches policy active for that endpoint.

PROFILE SCOPE

Assign the policy to its intended endpoint

The device-to-profile relationship determines which protection, schedule, custom-rule, and privacy choices apply to a direct endpoint.

EXCEPTION PATH

Preview before allowing a hostname

When a block disrupts wanted functionality, Domain Rules can preview the current decision before an exact or subdomain exception is considered.

HOW IT WORKS

From setup to an explainable DNS decision.

QueryWarden applies policy at the recursive DNS layer, before a supported client connects to the requested domain.

  1. 01

    Connect a compatible client privately

    Create a device, assign its intended profile, and install the complete private QueryWarden DNS-over-HTTPS URL in a compatible client.

  2. 02

    Enable the ad and tracker controls

    Choose the managed protection settings for that profile and add a timezone-aware schedule only when the policy should vary by time.

  3. 03

    A matching hostname is blocked at DNS

    When the configured device requests a domain covered by active policy, the resolver returns the blocking response before that destination connection begins.

  4. 04

    Investigate breakage before allowing broadly

    Use fresh test traffic and eligible retained evidence to identify the hostname, preview its effective policy, and prefer the narrowest useful exception.

CLEAR BOUNDARIES

DNS ad blocking cannot see or remove every ad.

The control works at hostname resolution. It does not inspect the page, application interface, media stream, browser DOM, or complete URL behind an allowed domain.

  • An advertisement or tracker served from the same hostname as wanted content cannot be separated reliably by a DNS-only decision.
  • Blocking a third-party hostname can leave an empty space or affect a feature; DNS does not rewrite the page layout after the request is blocked.
  • Applications can use cached addresses, another resolver, a VPN, or their own encrypted DNS path, so coverage depends on the client actually using QueryWarden.
  • QueryWarden publishes private per-device DNS-over-HTTPS URLs, not shared public plain-DNS server IP addresses.
WHO AND HOW

Technical basis and product evidence

Published and reviewed by QueryWarden Engineering, Digiport OÜ. First-party review against the current public QueryWarden product, its documented deployment constraints, and the primary sources listed on this page. This is not an independent audit, certification, approval, or endorsement.

Product screenshots are deterministic captures of the current interface using synthetic accounts, devices, and reserved .test domains. External sources explain protocols and industry guidance; they do not verify QueryWarden implementation claims.

Last reviewed . Product availability can change; dashboard capability labels remain the source of truth. Review our Security & Trust disclosure.
QUESTIONS, ANSWERED

What to know before you change DNS.

Is QueryWarden a public ad blocking DNS server?

No. QueryWarden currently provides a private, rotatable DNS-over-HTTPS URL for each direct endpoint rather than public plain-DNS IP addresses. The configured endpoint receives the ad, tracker, threat, service, custom-rule, and privacy policy assigned to its profile.

Will DNS ad blocking remove every advertisement and tracker?

No. It can prevent requests to hostnames that match active policy. It cannot reliably separate an ad, tracker, or unwanted path served from the same allowed hostname as wanted content, and it does not modify page layout.

What should I do if a site or app stops working?

Generate fresh traffic through the intended endpoint, review eligible Query Log evidence, and preview the hostname decision. If an exception is justified, use the narrowest hostname match, audience, and duration that restores the required feature.

START WITH THE AVAILABLE FREE PLAN

Test ad and tracker policy on one compatible device.

The available Free plan protects one device with one profile and up to 48 hours of history when Full logging is selected.