Skip to content

macOS

macOS 11 (Big Sur) and later accept encrypted DNS through a configuration profile, the same .mobileconfig file iOS uses. It applies to every app and every network interface.

  1. In the dashboard, open the profile’s Setup page.

  2. Under Encrypted DNS, fill in Name a device (optional), for example Work MacBook, so the Mac shows as work-macbook in Logs and Analytics.

  3. In iOS and macOS configuration profile, choose DNS-over-HTTPS (recommended) or DNS-over-TLS, and click Download configuration profile. The file lands in your Downloads folder as opdns-<profile-id>-<device>-doh.mobileconfig.

The profile is not signed yet (signing is planned), so macOS shows it as Unverified; that is expected. It holds only the DNS setting. Downloading again with the same device name replaces the installed profile instead of adding a second one.

  1. Double-click the downloaded file. macOS says the profile was downloaded and needs review.

  2. Open System Settings, search for Profiles, and open it (under General → Device Management on macOS 15, Privacy & Security → Profiles on earlier versions).

  3. Double-click the opdns profile, click Install, and authenticate.

  4. Check it works.

To remove it, select the profile in the same place and click the minus button.

If your network has IPv6, you can instead enter the profile’s IPv6 addresses from the Setup page under System Settings → Network → (your connection) → Details → DNS. This is not encrypted and carries no device name.

If you cannot download the file from the dashboard, the template on the iOS page works on macOS too: fill it in, save it as opdns.mobileconfig, and install it as above.