PROTECTION AND RULES

Import AdGuard DNS rules into QueryWarden

QueryWarden Migration Assistant converts a deliberately narrow subset of AdGuard-style domain rules into native QueryWarden allow and block rules. It creates a read-only preview first; it does not execute the source as an AdGuard filter or import an AdGuard account, app, server configuration, subscription, client list, upstream resolver, or query history.

Available now Account owners and policy operators migrating selected custom rules
BEFORE YOU START

Prepare the safe path

  • Export or copy only the custom rule lines you intend to own in QueryWarden. A preview accepts at most 1 MB of text and 1,000 parsed candidates, while the rules that can be applied must also fit the current account plan limit.
  • Choose the intended audience before previewing: Entire account, one existing profile, or one existing device. Imported rules are permanent until edited, removed, or rolled back.
  • AdGuard is a third-party trademark. QueryWarden is not affiliated with, sponsored by, or endorsed by the trademark owner.
  1. 1

    Keep only syntax that QueryWarden can convert safely

    The supported AdGuard subset is `||domain.example^` for a block rule and `@@||domain.example^` for an allow rule. Both become Domain and subdomains rules in QueryWarden. Local-address hosts lines beginning with `0.0.0.0`, `127.0.0.1`, `::`, or `::1` are also accepted and become exact-hostname block rules. Blank lines, lines beginning with `!` or `#`, and section headers such as `[Adblock Plus 2.0]` are ignored.

  2. 2

    Remove unsupported AdGuard features from the import

    Rules with `$` modifiers, regular-expression rules, URL paths, ports, DNS rewrites, and other AdGuard-specific syntax are not converted. A full AdGuard Home YAML file or product export is not a supported input. Invalid hostnames, duplicate candidates, the QueryWarden service safety domain, and local-only host entries such as `localhost` are skipped rather than applied.

  3. 3

    Create a read-only preview in Migration Assistant

    Sign in, open Operations → Migration, enter a batch name, choose AdGuard domain rules, and select the account, profile, or device scope. Choose a local text file or paste the rule text, then select Create read-only preview. The browser sends the text to the authenticated preview endpoint for parsing; creating the preview does not change DNS policy.

  4. 4

    Read every preview outcome before applying

    Ready means the line normalized into a supported rule and does not match an active rule at the same hostname, match scope, and audience. Conflicts are identical or opposite active rules at that same scope. Skipped covers duplicate candidates, invalid or protected hostnames, and ignored local host entries. Unsupported identifies syntax QueryWarden cannot convert, including modifiers and regular expressions. The details show up to 100 representative diagnostics, so use the totals as the complete count.

  5. 5

    Apply only the ready rules

    Review the displayed action, hostname, match scope, and audience, then choose Apply safe rules. QueryWarden applies the ready set as one database transaction; conflicts, skipped lines, and unsupported lines are not applied. If current policy now conflicts with a candidate, the target disappeared, or the batch would exceed the plan rule limit, apply stops without partially importing the batch and you should create a fresh preview.

  6. 6

    Roll back the untouched batch when necessary

    An applied batch offers Roll back untouched import. Rollback removes only rules created by that batch that have not been edited since import. QueryWarden preserves imported rules you edited afterward and reports how many edited rules were retained. It does not delete or alter rules that existed before the batch. A rolled-back batch cannot be applied again; create a new preview if you need to re-import it.

WHAT SUCCESS LOOKS LIKE

Confirm the result

The batch history shows the preview as applied, only its Ready rules appear at the selected QueryWarden scope, and a later rollback can remove the still-untouched rules from that specific batch while preserving edited or pre-existing rules.

SECURITY NOTES

Protect the account while you work

  • A local file is read by the browser and its text is sent to QueryWarden for the authenticated preview. The stored batch keeps normalized candidates, representative diagnostics, and a content fingerprint rather than the complete raw source; a diagnostic can still retain a short excerpt of an affected line.
  • An allow rule is a security exception. Confirm the destination and use the narrowest account, profile, or device audience that meets the requirement.
  • Accounts under organization-managed policy can create a preview for review, but personal-policy controls prevent applying or rolling back that batch.
TROUBLESHOOTING

When the expected result does not appear

A valid-looking AdGuard line is marked Unsupported.

Confirm that it is exactly `||domain.example^` or `@@||domain.example^` with no `$` modifier, path, port, regular expression, rewrite, or additional syntax. QueryWarden intentionally supports only the documented subset.

A line is Skipped instead of Ready.

Check for a duplicate candidate, an invalid hostname label, a local-only hostname, or the protected QueryWarden safety domain. The diagnostic beside the representative input states the reason.

The preview reports a Conflict.

Open Rules and inspect the existing active rule with the same hostname, match scope, and audience. Resolve it deliberately, then create a new preview; conflicts are never overwritten by an import.

Apply reports a plan-limit or stale-preview error.

Remove unnecessary custom rules or narrow the source, confirm the selected profile or device still exists, and create a fresh preview against current policy. The failed transaction does not partially apply the batch.

Rollback preserved some imported rules.

This is expected when those rules were edited after import. Review and remove preserved rules individually if they are no longer required.

PRODUCT STATE

Capabilities used in this guide

Custom allowlist · Available nowCustom blocklist · Available now