Prepare the safe path
- Use a trusted signed-in dashboard session.
- Do not paste the rejected endpoint into public diagnostic tools.
1 Confirm the endpoint was copied completely
Compare the client configuration with the selected device setup value without sending either value elsewhere. Missing path characters, an older rotated value, or the wrong device endpoint will be rejected.
2 Review Source access
Open the device Source access control. If restricted, confirm the current public IPv4 or IPv6 source is represented by an approved entry.
3 Decide whether to update access or rotate
Update the approved source when a legitimate network changed. Rotate the endpoint when its private value may have been exposed or an unknown client used it.
4 Replace the client configuration
After rotation, the old endpoint stops working. Install the new value on the intended client and remove old copies from password managers, configuration systems, or tickets where appropriate.
5 Check fresh endpoint activity
Select Start traffic check and generate a new request. Confirm the selected device reports recent activity before closing the trusted session.
Confirm the result
The intended device uses a current private endpoint from an authorized source, while obsolete or disallowed requests remain rejected.
Protect the account while you work
- Rotation is the correct response to suspected endpoint disclosure; adding Any IP does not invalidate a leaked identifier.
- Never ask QueryWarden support to test the complete private endpoint on your behalf.
When the expected result does not appear
The public IP changes repeatedly.
Use Any IP with strict endpoint secrecy, a deliberate supported network range, or an architecture better suited to roaming. Avoid constant broad allowlist edits.
The old endpoint still appears in a client.
Clear the DNS client configuration, restart it if required, and confirm the complete new URL is active.
Relay reports a credential error.
Use Relay enrollment or credential rotation in the Relay workspace; direct-device source-IP steps do not replace Relay credentials.