https-dns-proxy runs on the router, listens locally, and sends every query
from dnsmasq to opdns over DNS-over-HTTPS. Every device on the network is
filtered without touching it.
Install the package and its LuCI page (SSH to the router, or System →
Software in LuCI):
Replace the default resolvers with opdns. Either in LuCI under
Services → HTTPS DNS Proxy (choose a custom provider and paste the
URL), or in the config file:
Use a device name for the router, such as openwrt. Delete any other
config https-dns-proxy sections, or queries are shared between them.
Screenshot to comeLuCI HTTPS DNS Proxy page with one instance using the opdns resolver URL.OpenWrt 24.10
Restart it:
Terminal window
/etc/init.d/https-dns-proxyrestart
The package points dnsmasq at the local proxy by itself
(update_dnsmasq_config), and force_dns redirects LAN devices that
hard-code another DNS server back to the router.
Check it works: queries from every device appear
under the router’s device name.
One device name for the whole network. The router makes the queries,
so every LAN device appears as the router. Per-client names need a
forwarder that adds them per LAN client, which is the planned opdns CLI and
OpenWrt package. For per-device names today, configure
encrypted DNS on each device as well.
Bootstrap.https-dns-proxy resolves dns.opdns.net once at start
through its bootstrap servers (set with option bootstrap_dns). Those
lookups are plain DNS to the listed servers.
Browsers with their own DoH bypass the router. Firefox respects the
canary domain that force_dns setups can block; Chrome follows the system.