2.3 KiB
2.3 KiB
Built-in provider policy
Provider endpoints and capabilities must be verified against the provider's official documentation before they are added or changed. The built-in entries below were verified on 2026-08-13.
Candidate providers
| Provider | DoH endpoint | DoT endpoint / authentication name | QUIC support | DNSCrypt | Official documentation | Profile |
|---|---|---|---|---|---|---|
| Cloudflare | https://cloudflare-dns.com/dns-query |
one.one.one.one:853 |
DoH3 at the DoH endpoint | No verified built-in stamp | DoH and HTTP/3 / DoT | Unfiltered |
https://dns.google/dns-query |
dns.google:853 |
DoH3 at the DoH endpoint | No verified built-in stamp | Secure transports | Unfiltered | |
| Quad9 | https://dns.quad9.net/dns-query |
dns.quad9.net:853 |
Not enabled without an official endpoint statement | No verified built-in stamp | Quad9 services | Security filtered; HTTP/2 required |
| AdGuard | https://dns.adguard-dns.com/dns-query |
dns.adguard-dns.com:853 |
DoQ at dns.adguard-dns.com:853 |
Official stamp for 2.dnscrypt.default.ns1.adguard.com at 94.140.14.14:5443 |
AdGuard dnsproxy example / AdGuard public DNS | Ads, tracking, and security filtered |
Registry requirements
Each built-in provider entry must include:
- stable provider identifier;
- protocol and endpoint;
- authentication domain name;
- bootstrap addresses only when officially published;
- filtering/ECS profile;
- official source URL;
- last verification date.
The runtime Provider registry stores the official source URL and verification
date alongside each endpoint. Update both fields whenever an endpoint or
capability is re-verified; the markdown table alone is not authoritative for
runtime metadata.
Do not infer one protocol endpoint from another. Do not treat filtering and non-filtering services as interchangeable. Provider comparison results must remain separate.