Any router (DHCP and IPv6)
When a router cannot forward over TLS or HTTPS, have it tell every device to ask opdns directly. On IPv6 the profile has its own addresses, so no linking is needed. On IPv4 the addresses are shared, so your public IPv4 must be linked.
IPv6: per-profile addresses
Section titled “IPv6: per-profile addresses”The profile’s IPv6 addresses (Setup page) encode the profile id: any query sent to them is filtered by that profile, from any network. Configure the router to advertise them:
- Router advertisements (RDNSS, RFC 8106): the option most devices, including Android, read. On most routers this is “DNS servers” in the IPv6 or RA settings.
- DHCPv6 option 23: for devices that use stateful or stateless DHCPv6.
Set both when the router offers both.
IPv4: DHCP option 6
Section titled “IPv4: DHCP option 6”-
Link your network’s public IPv4 address to the profile, and set up DDNS if it changes.
-
In the router’s DHCP server settings, set the DNS servers handed to clients (DHCP option 6) to the IPv4 resolver addresses on the Setup page.
-
Renew leases (reconnect devices, or wait for the lease time).
On a client, confirm what it received (ipconfig /all on Windows,
resolvectl status on Linux, Wi-Fi → (i) on iOS), then
check it works.
Limits
Section titled “Limits”- Plain DNS: not encrypted, no device names; every device shows without a name.
- Devices with their own encrypted DNS (Android Private DNS, browsers with DoH) ignore what DHCP says. That is fine if they use opdns too.
- If the network has IPv6 but you set only IPv4 (or the reverse), devices may use the other family’s servers from your ISP. Set both.