Query logs#
Logging is off unless you turn it on. DNS queries are a detailed record of behavior, so we treat "no logs" as the normal state and every other mode as your deliberate choice, made per configuration.
The three modes#
None (default): queries are answered and forgotten. Nothing about them is stored anywhere.
Blocked only: only blocked lookups are recorded, giving you an audit trail of what the protection actually did without recording anyone's normal browsing. For most customers who want visibility, this is the right mode.
All: every query is recorded, including which client address asked. Choose it for troubleshooting or where you have a real auditing requirement, and be aware this is personal data about the people behind the devices; our privacy policy and data processing agreement cover your obligations.
What a log entry contains#
Timestamp, configuration, the domain asked for, the query type, the verdict (blocked, allowed, clean), which list matched for blocks, and the protocol used. The client address is included only in mode all; blocked-only logging deliberately omits it.
Where logs live: the region promise#
Each configuration selects a log region, and its logs are stored only there. The service refuses to accept a region it cannot honor, so the promise is enforced technically, not just by policy. EU (Germany) is the only region today; if we add regions later, your existing choice stays fixed until you change it.
Retention#
You control retention per configuration. Logs are deleted at the end of the period you set, or earlier on request, and switching a configuration to mode none stops collection immediately. See compliance for the full retention picture.
Back to features.