Encrypted DNS: one setting, and it covers the things that cannot run an app
Every device asks “where is this website?” before it loads anything. Encrypted DNS sends that question to us over an encrypted connection, and we refuse to answer for domains that have been reported as malicious. It is one line typed into a settings screen — no app, no account, nothing installed — and on a router it covers the television, the console, the printer and a guest’s phone at the same time.
Read the last section before you change anything. This helps with some attacks and cannot see others at all, and two of its limits change what you are actually getting. They are listed further down in the resolver’s own words.
Helix Counter’s encrypted-DNS service is built but is not yet accepting the public. There is no address to enter, and this page will not invent one — an address that does not answer would leave a device with no internet at all, rather than with the internet it had before.
Which device are you setting up?
The line you type is different on each one — they are not interchangeable, and the wrong sort is either refused or silently ignored. Pick the device and this page will show you the one that belongs to it.
Did it work?
There is no “protected” light to show you, here or anywhere else.
A resolver only ever hears from devices that have already found it, so we cannot tell you whether a phone is using us — only whether a lookup arrived. The check below asks this browser to look up a name we invent for the purpose, and then tells you whether that question reached us. It is one observation about one query, a moment ago, on this network. It is not a status, and it says nothing about the other devices in the house.
What this does not do
Written on this page until the resolver answers — then replaced by the limits this deployment states for itself.
- encrypted to us onlyThe question from your device to us is encrypted. The lookup we then make on your behalf is not, unless the operator of this service configured an encrypted one — so the network between us and the resolver we ask can still see the name. “Encrypted DNS” does not mean the whole path is covered.
- exact names onlyA domain is refused only when it is on the list by name. A malicious page hosted under a domain that is not listed still resolves — on purpose: blocking a whole suffix would take every unrelated site sharing that host off the air for your household.
- names, not contentThis answers the question “where is this site?”. It never sees the page, the file or the message, so an attack that uses no domain name is invisible to it.
- only what we may republishSome intelligence reaches us under terms that forbid acting on it publicly. A domain held under one of those resolves normally here.
- no cache, no DNSSEC validationThis passes questions to a configured resolver rather than working them out from scratch, and keeps no copy of the answers.
There is no weekly “what we blocked for you” summary, and there will not be one: it would need a record of the names your household looked up, which is exactly what this service is built not to keep. A question we forward is a local variable and is gone before the answer comes back.