Prepare the safe path
- Check the DNS client documentation for custom DoH URL support.
- Create the device with the correct platform so the dashboard displays the most relevant instructions.
1 Copy the complete endpoint
Open the selected device and copy the endpoint from Connection setup. Keep the `https://` prefix, host, path, and private identifier unchanged.
2 Choose the correct encrypted DNS setting
In Windows, Linux, a browser, or a DNS client, choose the option for a custom DNS-over-HTTPS provider. Router support varies; use the URL only when the router or local forwarder explicitly supports DoH.
3 Understand the Android limitation
Android system Private DNS asks for a DNS-over-TLS provider hostname. It cannot accept the current QueryWarden DoH URL. Use a compatible Android DNS client that accepts custom DoH instead.
4 Save and check fresh endpoint activity
Save the client setting, select Start traffic check in QueryWarden, and request a new domain. Inspect the client for fallback behavior if QueryWarden records nothing.
Confirm the result
New DNS requests reach the selected QueryWarden endpoint without the client silently falling back to another resolver.
Protect the account while you work
- Do not use one private endpoint as a public resolver address.
- A router endpoint may represent many LAN clients as one QueryWarden device. Use Relay when its Beta limitations better match the network requirement.
When the expected result does not appear
The setting accepts only an IP address.
It is not a custom DoH URL field. Choose compatible software or a supported local forwarder.
Browsing works but QueryWarden sees no requests.
The client may be falling back to the system resolver. Disable fallback only after understanding the availability impact, then test again.
The router rejects the URL.
Check its firmware documentation. Do not paste the private URL into a plain DNS server field.