GET CONNECTED

Your device.
Your connection.

Set up HQDNS with classic DNS, DNS-over-TLS or DNS-over-HTTPS.

QUICK SETUP

The endpoints you need.

DNS server: dns.hqdns.sarl

Save your current DNS settings before making changes.

IPv4
185.215.166.168
IPv6
2a02:c207:2355:6761::1
DNS-over-TLS
dns.hqdns.sarlPort 853
DNS-over-HTTPS
https://dns.hqdns.sarl/dns-query
01Windows

Windows 11 — DNS-over-HTTPS

  1. Open Settings → Network & internet and select your active Wi-Fi or Ethernet connection.
  2. Under DNS server assignment → Edit, select Manual, enable IPv4, and enter 185.215.166.168 as the preferred DNS.
  3. Set DNS over HTTPS to On (manual template). Enter https://dns.hqdns.sarl/dns-query as the template.
  4. Turn Fallback to plaintext off if you want DNS to stay encrypted, then save. If DoH cannot connect with fallback disabled, DNS resolution will stop.

If you configure an IPv6 DNS field, use 2a02:c207:2355:6761::1 with the same DoH template. Menu names vary by Windows version. Windows 10 does not offer this native DoH setting: use classic DNS or a compatible encrypted-DNS client.

Classic DNS

Use 185.215.166.168 in the DNS server field with DNS encryption off. Keep your IP address settings unchanged. To undo either method, restore automatic DNS or your previous configuration. Microsoft setup reference.

02Android

Android Private DNS — DNS-over-TLS

  1. Open Settings → Network & internet → Private DNS. If the menu differs, search Settings for Private DNS.
  2. Select Private DNS provider hostname.
  3. Enter dns.hqdns.sarl and save.

Enter only the hostname, without https://, a path, an IP address or a port. Android uses DoT on port 853. If the connection is unavailable, check your network or return to your previous setting; choose Automatic to undo. Android Private DNS reference.

03Linux

Linux — DNS-over-TLS

For a client computer already using systemd-resolved with DoT support:

  1. Create /etc/systemd/resolved.conf.d/hqdns.conf as an administrator, creating the directory if needed. Add:
[Resolve]
DNS=185.215.166.168#dns.hqdns.sarl 2a02:c207:2355:6761::1#dns.hqdns.sarl
DNSOverTLS=yes
Domains=~.
  1. Restart the local resolver with sudo systemctl restart systemd-resolved.
  2. Check resolvectl status and try resolvectl query example.com.

This requires an active systemd-resolved service used by your applications. VPNs and per-connection DNS settings may take precedence; consult your distribution if another resolver is used. To undo, remove only the file you added and restart systemd-resolved. systemd configuration reference.

DNS-over-HTTPS

In a client or browser that supports a custom DoH provider, choose custom DNS-over-HTTPS and enter https://dns.hqdns.sarl/dns-query. A browser setting applies to that browser, not the whole system.

Classic DNS

In NetworkManager, edit your connection’s IPv4 settings, keep automatic IP assignment, disable automatic DNS only, and enter 185.215.166.168. Save and reconnect; re-enable automatic DNS to undo.

04iOS / macOS

iOS / iPadOS / macOS — DNS-over-HTTPS

On versions supporting Apple’s encrypted DNS profiles (iOS/iPadOS 14+ and macOS 11+), you can use this optional HQDNS profile. Installation requires your approval on your own device.

  1. Download the HQDNS DoH profile. It selects https://dns.hqdns.sarl/dns-query with the advertised IPv4 and IPv6 addresses.
  2. On iPhone or iPad, open Settings → General → VPN & Device Management, select the downloaded profile and review it. On Mac, open the downloaded file and look for Profiles or Device Management in System Settings.
  3. Review the HQDNS — DNS-over-HTTPS profile and install it only if you want this device to use HQDNS for DNS.

The profile is unsigned and contains only DNS settings, with no VPN, certificate or device-management enrollment. It can be removed from the same settings to restore your prior DNS configuration. Device policies, other DNS profiles or VPNs may override it. Compatibility can vary on newer releases; if installation is unsupported, use a compatible encrypted-DNS client with the same DoH URL or DoT hostname dns.hqdns.sarl. Apple DNS profile reference.

Classic DNS on iOS

For one Wi-Fi network, go to Settings → Wi-Fi → information button → Configure DNS → Manual, note the existing servers, and replace them with 185.215.166.168. This IP-only method does not enable encrypted DNS. Restore Automatic to undo.

05Router

Classic DNS

  1. Open your router’s administration interface and find its DNS server settings. Save the current values.
  2. Enter 185.215.166.168 as the DNS server. If an IPv6 DNS field is supported, use 2a02:c207:2355:6761::1.
  3. Save the DNS settings and reconnect your device if needed. Keep other network settings unchanged.

Encrypted DNS, when supported

If your router offers a custom DoT provider, use dns.hqdns.sarl on port 853. For a custom DoH provider, use https://dns.hqdns.sarl/dns-query. Support and menu names depend on your router. If encrypted DNS is unavailable, configure it on individual devices instead.

To undo, restore your previous DNS values. Router DNS settings may be overridden by a device, browser or VPN.

Menu names vary by device and version. These guides configure your own device. View service status.