Skip to content

Your endpoints

Every profile has its own addresses. The dashboard’s Setup page shows them for your profile, computed by the API (endpoints on the profile resource).

The guides are written once for everyone, so they use two placeholders. The dashboard’s Setup page fills them in for you.

Placeholder Means Example
<profile-id> Your profile’s 6-character id: lowercase letters and digits abc123
<device> A name you choose for the device Pixel-8, living-room-tv

Device names are optional. The resolver keeps ASCII letters (lowercased) and digits, turns spaces, dots, underscores and hyphens into a single hyphen, drops everything else, and keeps at most 32 characters. Anna's iPad becomes annas-ipad. Use the same name on the same device every time: the name is what logs and analytics group by.

Transport Address Identifies
DNS-over-HTTPS (HTTP/2 and HTTP/3) https://dns.opdns.net/<profile-id>/<device> profile and device
DNS-over-TLS (port 853) <device>-<profile-id>.dns.opdns.net profile and device
DNS-over-QUIC (port 853) <device>-<profile-id>.dns.opdns.net profile and device
Plain DNS over IPv6 the profile’s own IPv6 addresses (one per anycast prefix), shown on the Setup page profile only
Plain DNS over IPv4 the shared anycast IPv4 addresses, with your network’s IPv4 linked profile only

Without a device name, drop the last path segment (https://dns.opdns.net/<profile-id>) or the <device>- prefix (<profile-id>.dns.opdns.net).

Prefer encrypted DNS: DNS-over-HTTPS in browsers and on Windows, iOS and macOS; DNS-over-TLS for Android’s Private DNS and for Linux and routers. Both carry a device name and work on any network.

Use plain DNS only where nothing else is possible, typically a router’s DHCP settings for devices you cannot configure one by one. Plain DNS is not encrypted and cannot name devices. See Identification for the full rules.

A wrong id fails loudly on every transport. A well-formed profile id that does not exist is refused (REFUSED) with an Extended DNS Error, a DoT or DoQ server name that does not encode a well-formed id (five or seven characters, say, or a device name joined without the hyphen) is refused the same way, and a DoH path that is not a profile id gets HTTP 404. None of them is ever answered unfiltered: the device gets no answers, so you notice. Only the bare dns.opdns.net, with no id at all, is the unfiltered public path. After any setup, check it works.