Windows 11
Windows 11 can send DNS over HTTPS natively. It needs two things per server: an IP address to connect to, and the DoH URL (Windows calls it a template). The IP address only says where to connect; the template’s path is what selects your profile and device.
You need: your profile id, a device name, and a resolver address:
<resolver-ipv4>: one of the IPv4 resolver addresses on your profile’s Setup page;<resolver-ipv6>: one of the profile’s IPv6 addresses, if your network has IPv6.
-
Open Settings → Network & internet, then Wi-Fi or Ethernet, and the connection you use. For Wi-Fi choose Hardware properties.
-
Next to DNS server assignment, click Edit and choose Manual.
-
Turn on IPv4. In Preferred DNS, enter
<resolver-ipv4>. -
Set DNS over HTTPS to On (manual template) and enter:
https://dns.opdns.net/<profile-id>/<device> -
Set Fallback to plaintext to Off. With it on, Windows silently uses unencrypted DNS when DoH fails, and those queries are not identified.
-
If you have IPv6, turn on IPv6 and repeat with
<resolver-ipv6>and the same template. -
Click Save, then check it works.
Repeat for each network adapter you use: the setting is per adapter.
Register the template once for the address, then point the adapter at it:
netsh dns add encryption server=<resolver-ipv4> ` dohtemplate=https://dns.opdns.net/<profile-id>/<device> ` autoupgrade=yes udpfallback=no
Set-DnsClientServerAddress -InterfaceAlias "Wi-Fi" -ServerAddresses <resolver-ipv4>Check with netsh dns show encryption server=<resolver-ipv4>.