New: one-click Cloud Apps
All documentation

App setup guides

AdGuard Home: private DNS for your devices

Use your AdGuard Home app as a DNS-over-HTTPS resolver on browsers, Windows, macOS and mobile -- and why the address AdGuard shows you is not the one to use.

AdGuard Home on Caliber Node runs as a DNS-over-HTTPS (DoH) resolver, not a traditional DNS server. That difference decides how you point your devices at it, so it is worth understanding before you start.

What you can and cannot do with it

Because our platform gives each app one HTTPS address and does not expose the classic DNS port (53), AdGuard here is a resolver your devices and browsers use over HTTPS. It follows the device anywhere — home, work, mobile data — which a router-based setup cannot.

  • Works: browsers (Chrome, Edge, Firefox, Brave), Windows 11, macOS and iOS via a profile.
  • Does not work: setting it as your home router's DNS. That needs plain DNS on port 53, which this platform does not provide. If whole-home, router-level filtering is your goal, AdGuard here is not the right fit.

The address to use

This is the one thing everyone gets wrong, because AdGuard's own "Configure your devices" screen shows the wrong address for our setup.

Your DoH address is your app's own URL with /dns-query on the end:

https://YOUR-APP.h1.cnpods.com/dns-query

Use the exact address shown on your app's page in the panel, then add /dns-query.

Ignore the addresses AdGuard lists on its Configure-your-devices screen. It shows things like https://…:4443/dns-query, tls://…:853 and quic://…:784. Those point at internal ports that are not reachable from the internet on our platform. Only the plain https://…/dns-query address above works — with no port number.

Setting it up

Firefox

Settings → Privacy & Security → scroll to DNS over HTTPSMax Protection (or Increased) → Choose provider → Custom → paste https://YOUR-APP.h1.cnpods.com/dns-query.

Chrome, Edge, Brave

Settings → Privacy and security → Security → Use secure DNSWith: Custom → paste https://YOUR-APP.h1.cnpods.com/dns-query.

Windows 11 (whole system)

Windows' built-in DNS settings are built around an IP address, not a URL, so the simplest reliable option on Windows is to set the DoH address in your browser (above). For system-wide DoH, use a DoH client such as YogaDNS and point it at your /dns-query address.

macOS and iOS

These use a small configuration profile (a .mobileconfig file) that carries the DoH address. Generate one with any "DoH mobileconfig generator" using your /dns-query address, then open it to install. Once installed, the whole device resolves through AdGuard.

Android

Android's built-in Private DNS uses DNS-over-TLS, not DoH, so it will not accept the /dns-query address. Use a DoH-capable app such as Intra or RethinkDNS and point it at your address.

Sign in and manage it

Open your app's address in a browser and sign in with the username and password shown on the app's Credentials panel in the Caliber Node dashboard. From there you choose blocklists, see query logs, and manage everything AdGuard does.

Important: restrict who can use it

By default your resolver answers anyone who knows the address. Leaving it fully open lets strangers route their DNS through your instance, which uses your plan's resources. After you sign in, open Settings → Client settings and restrict access — or simply treat the address as private and do not publish it.

Why AdGuard shows the wrong port

For the curious: AdGuard serves its dashboard and DoH endpoint over HTTPS on an internal port, and our edge presents that on the standard HTTPS port (443) at your app's public address. AdGuard only knows its own internal port, so its Configure-your-devices screen prints that instead of the public one. The address in this article is the correct, working one.

Still stuck? Get in touch — a person reads every message.

Ready to deploy?

Deploy an app from the catalog in minutes. No contracts, no setup fees.