Public service

Encrypted DNS.
No account required.

A small, filtered resolver available over DoH. Query logging is disabled. Public DoT stays closed; tailnet clients can use the same service over TLS.

Resolver endpoints

DoH

DNS over HTTPS

Endpoint URLhttps://doh.sbdmfp.dev/dns-query

Use this URL in browsers, operating systems, and resolver clients that accept a custom DoH endpoint.

The route accepts standard GET and POST DoH requests only.

DoT

DNS over TLS

Public DoT is not offered. TCP 853 is not published on the internet, so the origin IP stays off public DNS.

DoT remains available on the Tailscale network at hostname dot.sbdmfp.dev port 853 (SNI must match). Point that name at the machine’s tailnet address, or connect to the tailnet IP with that SNI. Android “Private DNS” on the public internet cannot use this service; use the DoH URL instead.

Use it where

Choose the transport your client supports.

Browsers and modern resolver clients can use the public DoH URL directly. Android Private DNS requires DoT, so it must reach the tailnet address with the dot.sbdmfp.dev SNI.

Raw TCP and UDP port 53 are not part of this public surface. That keeps the resolver transport explicit and avoids publishing a general-purpose origin DNS listener.

Operational shape

Filtered, bounded, and honest about scope.

Upstream resolution uses DNSCrypt. DNSSEC validation, rebinding protection, extended DNS errors, and a per-client rate limit are enabled at the resolver edge.

This is a personal best-effort service, not a general anonymity system or an uptime contract.

Privacy

What is—and is not—kept

DNS query logging is disabled. The resolver does not intentionally store queried names, answers, or a browsing history.

Rate-limit warnings may temporarily include a client IP address so repeated abuse can be blocked. Those warnings are operational security logs, not analytics, and follow the host journal’s bounded retention.

DoH is proxied and TLS-terminated by Cloudflare, so Cloudflare can process the DNS request as well as connection metadata. Public DoT is disabled. Tailnet DoT connects to this server over Tailscale. Upstream DNSCrypt resolvers receive queries from this server; their own retention policies apply.

Limits

Fair use, not a SLA

The resolver allows an average of 50 DNS queries per second per client, with a short burst of 100. The HTTPS edge has an additional coarse abuse limit.

This is a best-effort personal service. There is no uptime guarantee, support contract, or promise of indefinite availability. Configuration may change to protect the service.

Please do not use it for stress testing, automated bulk resolution, censorship circumvention where doing so creates personal risk, or unlawful activity.

One practical note

Encrypted transport is not anonymity.

Encrypted transport protects DNS traffic between your device and this resolver. It does not make all internet activity anonymous, and destination services can still observe connections made to them.