DnsOverHttpsMode = off). Let the network signal Firefox to turn off its automatic DoH, and answer "no such domain" for iCloud Private Relay. Then decide your VPN policy.1. Hard-coded DNS servers
Some devices and apps ignore the DNS servers your network hands out and use their own, such as 8.8.8.8 or 1.1.1.1. The fix is a firewall rule:
- Allow outbound UDP and TCP port 53 only from your DNS servers (the firewall itself or your domain controllers) to the DNSAFE addresses.
- Block outbound port 53 from every other internal address.
- Also block outbound TCP 853 (DNS-over-TLS) except to
dns.dnsafe.net, if you use it.
Some firewalls can instead redirect stray port-53 traffic to your DNS server (often called DNS interception or a port-forward NAT rule). That's friendlier than blocking, because the device still gets filtered answers.
2. Browsers' own encrypted DNS (DoH)
DNS-over-HTTPS sends lookups inside normal HTTPS traffic on port 443, so a port rule can't catch it. Handle it at the browser:
Chrome and Edge
Chrome only upgrades to DoH automatically when the system's DNS provider supports it, but users can pick their own provider in settings. On managed computers, set the DnsOverHttpsMode policy to off:
- Group Policy: Computer Configuration → Administrative Templates → Google Chrome → Controls the mode of DNS-over-HTTPS → Enabled → Disable DNS-over-HTTPS. Edge has the same policy under Microsoft Edge.
- Registry:
HKLM\SOFTWARE\Policies\Google\Chrome, string valueDnsOverHttpsMode=off. - Intune or Google Admin console: the same setting is in their Chrome policy lists.
Firefox
Firefox checks a "canary" domain, use-application-dns.net. If the network's DNS says it doesn't exist, Firefox leaves its automatic DoH off. DNSAFE answers that way for every registered network, so this works without extra setup. It doesn't override a user who switched DoH on themselves, so on managed computers also set Firefox's DNSOverHTTPS policy to disabled and locked.
Known DoH providers
For extra coverage, block the hostnames of public DoH services at the DNS layer. With SafeSearch enforcement turned on for a network, DNSAFE blocks well-known DoH endpoints automatically.
3. iCloud Private Relay
On iPhones, iPads and Macs with iCloud+, Private Relay sends Safari traffic and its DNS through Apple's relays. Apple's guidance for networks that need filtering is to make mask.icloud.com and mask-h2.icloud.com fail to resolve (no answer, or "no such domain"). The device then tells the user that Private Relay is off for this network. Avoid silently dropping the traffic, which causes slow timeouts.
DNSAFE does this for networks with SafeSearch enforcement turned on. You can also add both names to your block list.
4. VPNs and proxies
A VPN app sends all traffic, including DNS, to its own servers. DNS filtering can't see inside it. Your options:
- Policy: an acceptable-use policy that forbids personal VPNs on company devices, enforced with device management.
- Block the VPN services' domains: add popular consumer VPN sites to your block list so they can't be downloaded or signed in to. This helps, but it's not airtight.
- Next-generation firewall: application control can recognize and block most VPN protocols.
Try DNSAFE on your own network: 14 days free, no card, set up in minutes.
Start free trialCheck your work
- From a test device, run
nslookup example.com 8.8.8.8. With the port-53 rule in place it should time out or be refused. - Open Chrome's
chrome://policyand confirmDnsOverHttpsModeshowsoff. - Run the DNS leak test in each browser. Every one should show DNSAFE.
Frequently asked questions
Is DNS-over-HTTPS bad for businesses?
No, encryption is good. It becomes a problem when a browser sends lookups to a provider you didn't choose. The fix is to use encrypted DNS to your own filtering provider (DNSAFE supports DoH and DoT) and turn off the browser's own choice.
Will blocking iCloud Private Relay break iPhones?
No. Following Apple's guidance, the device shows a notice that Private Relay isn't available on this network and carries on without it. Everything else works normally.
Can I stop every possible bypass?
Not with DNS alone. A determined user with admin rights can install a VPN. The steps above close the common routes; device management and a firewall with application control close most of the rest.