Linux (systemd-resolved)
Most current distributions (Ubuntu, Fedora, Debian 12 with it enabled, Arch)
resolve through systemd-resolved, which speaks DNS-over-TLS. It needs an
address to connect to and a TLS server name, written address#name; the name
selects your profile and device.
You need: your profile id, a device name (the host name is a good
choice), and <resolver-ipv4> / <resolver-ipv6> from the Setup page (see
the note on Windows about when these appear).
-
Create a drop-in file:
/etc/systemd/resolved.conf.d/opdns.conf [Resolve]DNS=<resolver-ipv4>#<device>-<profile-id>.dns.opdns.netDNS=<resolver-ipv6>#<device>-<profile-id>.dns.opdns.netDNSOverTLS=yesDomains=~.DNSOverTLS=yesis strict: no fallback to unencrypted DNS.Domains=~.sends every name here rather than to a per-link server from DHCP. -
Restart the service:
Terminal window sudo systemctl restart systemd-resolved -
Make sure programs use it.
/etc/resolv.confshould point to the stub resolver127.0.0.53:Terminal window readlink /etc/resolv.conf # ../run/systemd/resolve/stub-resolv.conf -
Confirm the settings took:
Terminal window resolvectl statusresolvectl query example.com
Without systemd-resolved
Section titled “Without systemd-resolved”Any stub that supports DoT with a server name works the same way (Stubby,
Unbound with forward-tls-upstream: yes and forward-addr: <resolver-ipv4>@853#<device>-<profile-id>.dns.opdns.net). For DoH, a local
forwarder such as dnscrypt-proxy or https_dns_proxy with the URL
https://dns.opdns.net/<profile-id>/<device>. An opdns CLI forwarder is
planned.