Open-source project
paulmillr/encrypted-dns avatar
paulmillr/encrypted-dns

encrypted-dns-configs: Ready-to-Install DNS over HTTPS and TLS Profiles for iOS and macOS

DNS over HTTPS config profiles for iOS & macOS

4,832 stars436 forksJavaScriptUnlicense

At a glance

What is it?
paulmillr/encrypted-dns provides pre-built .mobileconfig profiles that configure DNS over HTTPS or DNS over TLS on iPhones, iPads, and Macs without any code. It covers dozens of providers worldwide, marks which ones apply censorship, and offers both signed and unsigned profile variants.
Who is it for?
encrypted-dns-configs is the right tool for iPhone, iPad, and Mac users who want to switch their DNS resolver to an encrypted provider without configuring anything manually. The profile table's censorship column is the key signal for privacy-focused users: a provider marked yes will intercept some DNS queries and return modified responses.
Can I use it commercially?
Yes. Unlicense is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 66 days ago.
What is it written in?
Mainly JavaScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 27, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What the Repository Provides and Who It Is For

The encrypted-dns repository is a collection of configuration profiles, not a software library. Each profile is a .mobileconfig file, an XML-based configuration format that Apple's operating systems use to configure system settings including DNS resolvers. By installing one of these profiles, an iPhone, iPad, or Mac will route all DNS queries through an encrypted channel (DNS over HTTPS or DNS over TLS) to the chosen provider instead of through plain UDP DNS.

The target user is anyone who wants their DNS traffic encrypted on an Apple device but does not want to manually enter DoH or DoT server addresses into system settings. The profiles handle all the configuration details. A user downloads a profile, opens it, confirms the installation, and the device begins using the encrypted resolver.

This matters because standard DNS resolvers send queries in plain text, making them readable to anyone on the same network or to the user's internet service provider. Encrypted DNS prevents that interception. It does not, however, prevent the DNS provider itself from seeing which domains you query.

Installing a Profile on iOS and iPadOS

iOS and iPadOS installation requires Safari specifically. Other browsers will download the file without triggering the installation flow:

1. Open the .mobileconfig file in Safari. A prompt to allow the download appears. Tap Allow. 2. Go to System Settings, then General, then VPN, DNS and Device Management. 3. Select the downloaded profile and tap Install.

The Safari requirement is a constraint, not a preference. The README states that other browsers "will just download the file and won't ask for installation." A file downloaded through Chrome or Firefox on iOS needs to be opened with the Files app and re-opened in Safari to trigger the system installation dialog.

Installing a Profile on macOS

macOS installation has one specific pitfall: the file extension. The README warns to "ensure the downloaded file has proper extension: NAME.mobileconfig, not NAME.mobileconfig.txt." Some browsers or download managers append .txt to the file name. A file named with .mobileconfig.txt will not open correctly in the Profiles pane.

The installation steps:

1. Open Apple menu, then System Settings. 2. Navigate to Privacy and Security in the sidebar. 3. Click Profiles on the right. If you need to scroll to find it, the README notes that too. 4. In the Downloaded section, double-click the profile. 5. Review the contents and click Continue, Install, or Enroll.

If an earlier version of the same profile is already installed, the new version replaces it. You can update a provider's profile by installing its latest version from the repository.

Reading the Provider Table: Censorship, Region, and Protocol

The README's provider table is the core of the repository. Each row lists a provider name, its operating region, whether it applies censorship, notes, and download links for the signed and unsigned profile variants.

Censorship in this table means that the provider "will not send true information about hostname=IP relation for some hosts." A provider marked yes blocks or redirects queries for certain domains, typically for ads, tracking, malware, or adult content, depending on the provider's policy. AdGuard DNS Default, for example, is marked yes because it blocks ads, tracking, and phishing. AdGuard DNS Non-filtering is marked no because it forwards queries without modification.

Selected entries from the table:

- AdGuard DNS Default (Russia): censorship yes, blocks ads, tracking, and phishing. Supports both HTTPS and TLS profiles. - AdGuard DNS Family Protection (Russia): censorship yes, blocks the same as Default plus malware and adult content. - AdGuard DNS Non-filtering (Russia): censorship no, non-filtering. - Alekberg Encrypted DNS (Netherlands): censorship no, independent. - Aliyun Public DNS (China): censorship no, operated by Alibaba Cloud. - BlahDNS CDN Filtered (United States): censorship yes, blocks ads, tracking, and malware. Independent. - BlahDNS CDN Unfiltered (United States): censorship no. - Canadian Shield Private (Canada): censorship no, operated by the Canadian Internet Registration Authority.

The region column indicates where the provider operates, which matters for latency. A resolver in the Netherlands will respond more slowly to a user in the United States than a resolver hosted in North America. The table covers providers across multiple continents.

Signed vs Unsigned Profiles

Each provider in the table has two profile variants: signed and unsigned. The signed column provides profiles that carry a cryptographic signature, which macOS and iOS display during installation as a trust indicator. The unsigned column provides profiles without a signature.

The build system in the repository (src/scripts/build.ts and sign.ts) generates both variants from source JSON definitions. The @noble/hashes and micro-key-producer dependencies in package.json are used by the signing script.

For most users, the signed profile is the appropriate choice. The signature allows the system to verify that the profile has not been modified after it was generated. The unsigned profile is available for users who want to inspect or modify the raw profile before installation, but modifications void the signature and require generating a new one.

The profiles/ directory contains the unsigned variants and the signed/ directory contains the signed ones. Both directories are generated by the build scripts from the same source data in src/.

Limitations and Scope

The .mobileconfig format is specific to Apple's operating systems. This repository provides no Windows, Android, or Linux configuration files. Users on those platforms must configure DoH or DoT through their operating system's DNS settings or through a browser's built-in encrypted DNS feature.

Encrypted DNS prevents network observers from seeing your DNS queries, but it does not prevent the DNS provider from seeing them. Choosing a provider from this list shifts trust from your ISP or network to the chosen resolver operator. A filtering provider also changes which domains resolve correctly, since it intercepts queries for blocked domains.

The repository uses the Unlicense, which places the content in the public domain with no restrictions. The Unlicense does not provide a warranty; the profiles are used as-is.

The last push to the repository was on 2026-07-25. New providers require a pull request contribution; the README points to the contributing section for the process. The build scripts require Node.js and npm.

Editorial conclusion

encrypted-dns-configs is the right tool for iPhone, iPad, and Mac users who want to switch their DNS resolver to an encrypted provider without configuring anything manually. The profile table's censorship column is the key signal for privacy-focused users: a provider marked yes will intercept some DNS queries and return modified responses. Anyone on Windows or Android cannot use these profiles; the .mobileconfig format is specific to Apple devices. The repository is not a library to compile or deploy; drop a profile onto your device and the system handles the rest.

Frequently asked questions

What is encrypted DNS?

Encrypted DNS refers to DNS over HTTPS (DoH) and DNS over TLS (DoT), two protocols that wrap standard DNS queries in an encrypted connection. They prevent network observers from reading which domains you look up, unlike plain UDP DNS which sends queries in clear text. This repository provides .mobileconfig files that configure encrypted DNS on Apple devices.

how to use encrypted dns on iphone

Download a .mobileconfig profile from the repository using Safari (not another browser). Tap Allow when prompted. Then go to System Settings, General, VPN, DNS and Device Management, select the downloaded profile, and tap Install. The device will use the encrypted DNS resolver immediately after installation.

Why is my Wi-Fi blocking encrypted DNS?

The repository does not explain why a network blocks encrypted DNS. Some routers, corporate networks, or ISPs block DoH or DoT traffic on ports 443 or 853. The profiles in this repository configure the DNS resolver but cannot override a network firewall that blocks encrypted DNS traffic.

Official sources

  1. Issues
  2. License: Unlicense
  3. paulmillr/encrypted-dns on GitHub
  4. Project website
  5. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/paulmillr-encrypted-dns.svg)](https://hysenlabs.com/projects/paulmillr-encrypted-dns)