Skip to content

OpenWrt

https-dns-proxy runs on the router, listens locally, and sends every query from dnsmasq to opdns over DNS-over-HTTPS. Every device on the network is filtered without touching it.

  1. Install the package and its LuCI page (SSH to the router, or System → Software in LuCI):

    Terminal window
    opkg update
    opkg install https-dns-proxy luci-app-https-dns-proxy
  2. Replace the default resolvers with opdns. Either in LuCI under Services → HTTPS DNS Proxy (choose a custom provider and paste the URL), or in the config file:

    /etc/config/https-dns-proxy
    config main 'config'
    option update_dnsmasq_config '*'
    option force_dns '1'
    config https-dns-proxy
    option resolver_url 'https://dns.opdns.net/<profile-id>/<device>'
    option listen_addr '127.0.0.1'
    option listen_port '5053'

    Use a device name for the router, such as openwrt. Delete any other config https-dns-proxy sections, or queries are shared between them.

  3. Restart it:

    Terminal window
    /etc/init.d/https-dns-proxy restart

    The package points dnsmasq at the local proxy by itself (update_dnsmasq_config), and force_dns redirects LAN devices that hard-code another DNS server back to the router.

  4. Check it works: queries from every device appear under the router’s device name.

  • One device name for the whole network. The router makes the queries, so every LAN device appears as the router. Per-client names need a forwarder that adds them per LAN client, which is the planned opdns CLI and OpenWrt package. For per-device names today, configure encrypted DNS on each device as well.
  • Bootstrap. https-dns-proxy resolves dns.opdns.net once at start through its bootstrap servers (set with option bootstrap_dns). Those lookups are plain DNS to the listed servers.
  • Browsers with their own DoH bypass the router. Firefox respects the canary domain that force_dns setups can block; Chrome follows the system.