Skip to content

Linux (systemd-resolved)

Most current distributions (Ubuntu, Fedora, Debian 12 with it enabled, Arch) resolve through systemd-resolved, which speaks DNS-over-TLS. It needs an address to connect to and a TLS server name, written address#name; the name selects your profile and device.

You need: your profile id, a device name (the host name is a good choice), and <resolver-ipv4> / <resolver-ipv6> from the Setup page (see the note on Windows about when these appear).

  1. Create a drop-in file:

    /etc/systemd/resolved.conf.d/opdns.conf
    [Resolve]
    DNS=<resolver-ipv4>#<device>-<profile-id>.dns.opdns.net
    DNS=<resolver-ipv6>#<device>-<profile-id>.dns.opdns.net
    DNSOverTLS=yes
    Domains=~.

    DNSOverTLS=yes is strict: no fallback to unencrypted DNS. Domains=~. sends every name here rather than to a per-link server from DHCP.

  2. Restart the service:

    Terminal window
    sudo systemctl restart systemd-resolved
  3. Make sure programs use it. /etc/resolv.conf should point to the stub resolver 127.0.0.53:

    Terminal window
    readlink /etc/resolv.conf # ../run/systemd/resolve/stub-resolv.conf
  4. Confirm the settings took:

    Terminal window
    resolvectl status
    resolvectl query example.com
  5. Check it works.

Any stub that supports DoT with a server name works the same way (Stubby, Unbound with forward-tls-upstream: yes and forward-addr: <resolver-ipv4>@853#<device>-<profile-id>.dns.opdns.net). For DoH, a local forwarder such as dnscrypt-proxy or https_dns_proxy with the URL https://dns.opdns.net/<profile-id>/<device>. An opdns CLI forwarder is planned.