macOS 11 (Big Sur) and later accept encrypted DNS through a configuration
profile, the same .mobileconfig file iOS uses. It applies to every app and
every network interface.
Under Encrypted DNS, fill in Name a device (optional), for
example Work MacBook, so the Mac shows as work-macbook in Logs and
Analytics.
In iOS and macOS configuration profile, choose DNS-over-HTTPS
(recommended) or DNS-over-TLS, and click Download configuration
profile. The file lands in your Downloads folder as
opdns-<profile-id>-<device>-doh.mobileconfig.
The profile is not signed yet (signing is planned), so macOS shows it as
Unverified; that is expected. It holds only the DNS setting. Downloading
again with the same device name replaces the installed profile instead of
adding a second one.
Double-click the downloaded file. macOS says the profile was downloaded
and needs review.
Open System Settings, search for Profiles, and open it (under
General → Device Management on macOS 15, Privacy & Security →
Profiles on earlier versions).
Double-click the opdns profile, click Install, and authenticate.
Screenshot to comemacOS System Settings showing the opdns profile under Device Management with its DNS settings payload.macOS 15
If your network has IPv6, you can instead enter the profile’s IPv6
addresses from the Setup page under System Settings → Network → (your
connection) → Details → DNS. This is not encrypted and carries no device
name.
If you cannot download the file from the dashboard, the template on the
iOS page works on
macOS too: fill it in, save it as opdns.mobileconfig, and install it as
above.