DoH
DNS over HTTPS
https://doh.sbdmfp.dev/dns-queryUse this URL in browsers, operating systems, and resolver clients that accept a custom DoH endpoint.
The route accepts standard GET and POST DoH requests only.
Public service
A small, filtered resolver available over DoH. Query logging is disabled. Public DoT stays closed; tailnet clients can use the same service over TLS.
DoH
https://doh.sbdmfp.dev/dns-queryUse this URL in browsers, operating systems, and resolver clients that accept a custom DoH endpoint.
The route accepts standard GET and POST DoH requests only.
DoT
Public DoT is not offered. TCP 853 is not published on the internet, so the origin IP stays off public DNS.
DoT remains available on the Tailscale network at hostname dot.sbdmfp.dev port 853 (SNI must match). Point that name at the machine’s tailnet address, or connect to the tailnet IP with that SNI. Android “Private DNS” on the public internet cannot use this service; use the DoH URL instead.
Use it where
Browsers and modern resolver clients can use the public DoH URL directly. Android Private DNS requires DoT, so it must reach the tailnet address with the dot.sbdmfp.dev SNI.
Raw TCP and UDP port 53 are not part of this public surface. That keeps the resolver transport explicit and avoids publishing a general-purpose origin DNS listener.
Operational shape
Upstream resolution uses DNSCrypt. DNSSEC validation, rebinding protection, extended DNS errors, and a per-client rate limit are enabled at the resolver edge.
This is a personal best-effort service, not a general anonymity system or an uptime contract.
Privacy
DNS query logging is disabled. The resolver does not intentionally store queried names, answers, or a browsing history.
Rate-limit warnings may temporarily include a client IP address so repeated abuse can be blocked. Those warnings are operational security logs, not analytics, and follow the host journal’s bounded retention.
DoH is proxied and TLS-terminated by Cloudflare, so Cloudflare can process the DNS request as well as connection metadata. Public DoT is disabled. Tailnet DoT connects to this server over Tailscale. Upstream DNSCrypt resolvers receive queries from this server; their own retention policies apply.
Limits
The resolver allows an average of 50 DNS queries per second per client, with a short burst of 100. The HTTPS edge has an additional coarse abuse limit.
This is a best-effort personal service. There is no uptime guarantee, support contract, or promise of indefinite availability. Configuration may change to protect the service.
Please do not use it for stress testing, automated bulk resolution, censorship circumvention where doing so creates personal risk, or unlawful activity.
One practical note
Encrypted transport protects DNS traffic between your device and this resolver. It does not make all internet activity anonymous, and destination services can still observe connections made to them.