Your endpoints
Every profile has its own addresses. The dashboard’s Setup page shows
them for your profile, computed by the API (endpoints on
the profile resource).
Placeholders in these guides
Section titled “Placeholders in these guides”The guides are written once for everyone, so they use two placeholders. The dashboard’s Setup page fills them in for you.
| Placeholder | Means | Example |
|---|---|---|
<profile-id> |
Your profile’s 6-character id: lowercase letters and digits | abc123 |
<device> |
A name you choose for the device | Pixel-8, living-room-tv |
Device names are optional. The resolver keeps ASCII letters (lowercased)
and digits, turns spaces, dots, underscores and hyphens into a single hyphen,
drops everything else, and keeps at most 32 characters. Anna's iPad becomes
annas-ipad. Use the same name on the same device every time: the name is
what logs and analytics group by.
The addresses
Section titled “The addresses”| Transport | Address | Identifies |
|---|---|---|
| DNS-over-HTTPS (HTTP/2 and HTTP/3) | https://dns.opdns.net/<profile-id>/<device> |
profile and device |
| DNS-over-TLS (port 853) | <device>-<profile-id>.dns.opdns.net |
profile and device |
| DNS-over-QUIC (port 853) | <device>-<profile-id>.dns.opdns.net |
profile and device |
| Plain DNS over IPv6 | the profile’s own IPv6 addresses (one per anycast prefix), shown on the Setup page | profile only |
| Plain DNS over IPv4 | the shared anycast IPv4 addresses, with your network’s IPv4 linked | profile only |
Without a device name, drop the last path segment (https://dns.opdns.net/<profile-id>)
or the <device>- prefix (<profile-id>.dns.opdns.net).
Which one to use
Section titled “Which one to use”Prefer encrypted DNS: DNS-over-HTTPS in browsers and on Windows, iOS and macOS; DNS-over-TLS for Android’s Private DNS and for Linux and routers. Both carry a device name and work on any network.
Use plain DNS only where nothing else is possible, typically a router’s DHCP settings for devices you cannot configure one by one. Plain DNS is not encrypted and cannot name devices. See Identification for the full rules.
Check the id carefully
Section titled “Check the id carefully”A wrong id fails loudly on every transport. A well-formed profile id that
does not exist is refused (REFUSED) with an Extended DNS Error, a DoT or
DoQ server name that does not encode a well-formed id (five or seven
characters, say, or a device name joined without the hyphen) is refused
the same way, and a DoH path that is not a profile id gets HTTP 404. None
of them is ever answered unfiltered: the device gets no answers, so you
notice. Only the bare dns.opdns.net, with no id at all, is the unfiltered
public path. After any setup,
check it works.