Warda-DNSDocs v0.6.4

9. Encrypted DNS on your devices

In short

DoT (853/TCP), DoH (443) and DoQ (853/UDP) with a certificate of Let's Encrypt for xxxxxxxxxx.warda-dns.net, renewed by Warda; a .mobileconfig profile for Apple; stable links https://docs.warda-dns.com/<lang>/link/dns-<device>/ from the interface.

The encrypted DNS lets a phone keep its "private DNS", and a browser ask its names over HTTPS, while still going through Warda: nobody on the network reads the names asked. It is set in Network → DNS services, in two steps: 1. Certificate (the name of your encrypted DNS, xxxxxxxxxx.warda-dns.net with A name given by Warda, and its certificate, renewed by itself), then 2. Protocols and devices (DNS over TLS, HTTPS and QUIC, and the settings of each kind of device, each with a Guide link to the part below). Every 15 minutes Warda asks a question over each protocol, as a device would: the result is on the page and in the card Online services of the dashboard.

These addresses work on the network of the house only: a phone set to this name gets no names at all outside. Set it back to Automatic before leaving, or keep the encrypted DNS for the devices that stay home.

Android#

  1. Open Settings → Network & internet → Private DNS (Samsung: Connections → More connection settings → Private DNS).
  2. Choose Private DNS provider hostname and type the name shown on the page (xxxxxxxxxx.warda-dns.net), without https://.
  3. Save. The phone now appears in the queries of Warda with its names.

Android refuses a certificate made by Warda (self-signed): use A name given by Warda or your own domain.

iPhone and iPad#

  1. On the iPhone, in Safari, open the interface of Warda, page DNS services, and tap Download the profile (or send the file warda-dns.mobileconfig by AirDrop).
  2. Open Settings: Profile Downloaded appears at the top; tap it, then Install.
  3. To stop: Settings → General → VPN & Device Management → the profile of Warda → Remove Profile.

When Warda makes its certificate again (a message says so on the page), install the profile again.

Mac#

  1. Download the profile from the page DNS services (the same file as for the iPhone) and open it.
  2. Open System Settings → Privacy & Security → Profiles (on an older macOS: General → Device Management), double-click the profile of Warda and Install.

Windows 11#

  1. Settings → Network & internet → Wi-Fi or Ethernet → the network → DNS server assignment → Edit → Manual.
  2. Turn IPv4 on; Preferred DNS: the address of Warda shown on the page (192.168.1.53 for example).
  3. DNS over HTTPS: On (manual template), then the template shown on the page (https://xxxxxxxxxx.warda-dns.net/dns-query). Save.

Windows 10 has no encrypted DNS of its own: set it in the browser.

Linux#

With systemd-resolved (Ubuntu, Debian, Fedora…), in /etc/systemd/resolved.conf:

ini
[Resolve]
DNS=192.168.1.53#xxxxxxxxxx.warda-dns.net
DNSOverTLS=yes

Then sudo systemctl restart systemd-resolved; resolvectl status shows the server and +DNSOverTLS.

Browsers#

  • Firefox: Settings → Privacy & Security → DNS over HTTPS → Max Protection → Choose provider → Custom, then the address shown on the page (https://xxxxxxxxxx.warda-dns.net/dns-query).
  • Chrome, Edge, Brave: Settings → Privacy and security → Security → Use secure DNS → Custom (Edge: With: Enter custom provider), then the same address.

Only the browser is covered: the other applications of the computer use the DNS of the network.

TV, consoles and connected objects#

Nothing to set: they use Warda through the network (the box, or the DHCP of Warda, gives its address), and inside the house the names do not need to be encrypted. A device that asks another server by itself is shown on the page Protections (the ways around the filter).