Clientless DNS Filtering via DNS-over-HTTPS (DoH)
now
Minetta Gould
DNSFilter's network and device coverage is powerful — but getting it there has always required something: a static IP, a Relay, or a Roaming Client install. For Linux environments, devices without agent support, or anyone tired of managing dynamic IP headaches, that friction adds up.
Clientless DNS filtering via DoH changes the deployment model. Each registration generates a unique DoH address tied directly to a DNSFilter policy. Point a device, browser, or OS-level DNS setting at that address, and filtering applies — no agent, no Relay, no static IP required.
What This Means for You
- Filter any device that supports DoH natively — including Linux, where no Roaming Client exists today
- Eliminate dynamic IP management by using a stable DoH endpoint instead
- Reduce deployment complexity for environments where agent installation isn't practical
Eric Nix
This is awesome! Can we one up the request to include ability to go to specific filtering policies with unique DoH addresses? (i.e., doh.dnsfilter.com/[filter_id] or doh.dnsfilter.com/dns-query?[filter_id]) This could work much like NAT addresses do for filtering policies.
Thanks for the continued innovation!
Marvin
This is awesome for Android too. There is an option to set a private DNS ( https://developer.android.com/reference/android/net/LinkProperties#getPrivateDnsServerName() ). �
Minetta Gould
Marvin: Thanks for flagging this, and for the link!
Android's native Private DNS setting has historically been DoT-based rather than DoH, so this isn't quite there yet — but Google has been evolving Android's handling of DoH, and we're keeping an eye on it. Once DoH support is universally available on the platform, this should work on Android too.
Appreciate you pushing on this — it's exactly the kind of detail that helps us build the right thing!
Minetta Gould
updated the status to
now
Minetta Gould
Merged in a post:
Installation on Gateways/Routers
Eric Nix
Has DNSFilter considered reaching out to various router manufacturers (PAN, Cisco, Fortinet, Ubiquiti, etc.) about incorporating DNSFilter's client identification natively into the router? In other words, allow DoT lookups with sending the client data (LAN IP, hostname, etc.) upstream to DNSFilter. This would allow elimination of relay servers, which add a point of failure requiring redundancy.
Minetta Gould
Merged in a post:
Clientless filtering through DoH/DoQ
Nehul
We would like to setup the private DNS similar to how we have with Cloudflare. We can use a unique endpoint for DoH or DoT, so that no agent is necessary. https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/agentless/dns/dns-over-https/
M
Matis Stocco
I posted a solution for this, they should add the flag for local IP logs.
Eric Nix
Also looking for something similar.