GraceDNS
Log in Setup Now
Get started

Two steps, and Grace is watching

Every new account starts with a sensible default configuration: scams and malware blocked, everything else untouched. You can tune it any time.

1Your configuration

The id is shown in your dashboard next to the configuration name. Type it here and every value below fills in for copy and paste. No account yet? The button creates a real configuration with sensible defaults, no signup needed. Or leave the field empty and the examples use 7f3a9c12.

2Please select your target device

Pick a device above and its three-step setup appears here.

iPhone and iPad

then open it on the device and install under Settings, General, VPN and Device Management. Done.

Prefer to do it by hand?

  1. Create a .mobileconfig profile with a DNS payload: DNS over HTTPS with https://dns.gracedns.eu/7f3a9c12, or DNS over TLS with 7f3a9c12.dns.gracedns.eu.
  2. Send the file to your device (AirDrop or email) and open it.
  3. Install it under Settings, General, VPN and Device Management.

A one-click signed profile download is being built; until then the profile is a small XML file you create once.

Full iPhone and iPad guide →

MacBook and Mac mini

then open the file and install it under System Settings, Privacy and Security, Profiles. Done.

Prefer to do it by hand?

  1. Create the same .mobileconfig profile as for iPhone: DNS over HTTPS with https://dns.gracedns.eu/7f3a9c12.
  2. Open the file, then install it under System Settings, Privacy and Security, Profiles.
  3. Prefer browser-only filtering? Set the same URL as custom secure DNS in Chrome or Firefox instead.

Full Apple guide →

Android phone or tablet

  1. Open Settings, Network and internet (Samsung: Connections), then Private DNS.
  2. Select Private DNS provider hostname.
  3. Enter 7f3a9c12.dns.gracedns.eu and tap Save.

Works on every network: home Wi-Fi, school Wi-Fi and mobile data. Android refuses to fall back to unencrypted DNS while this is set.

Full Android guide →

Windows PC

  1. Windows 11: open Settings, Network and internet, select your connection, then DNS server assignment: Edit.
  2. Choose Manual, turn on IPv4, enter the GraceDNS resolver address from your dashboard, and set DNS over HTTPS: On with template https://dns.gracedns.eu/7f3a9c12.
  3. On Windows 10, set the same URL as custom secure DNS in your browser instead.

Browser secure DNS guide →

Linux

  1. Edit /etc/systemd/resolved.conf and set DNS=<resolver-ip>#7f3a9c12.dns.gracedns.eu plus DNSOverTLS=yes. The resolver address is in your dashboard's setup panel.
  2. Run sudo systemctl restart systemd-resolved.
  3. Check with resolvectl status: your GraceDNS hostname should be listed as the DNS server.

All connection methods →

Chromebook

  1. Open Settings, Security and privacy.
  2. Turn on Use secure DNS and choose With: Custom.
  3. Paste https://dns.gracedns.eu/7f3a9c12.

On school-managed Chromebooks your administrator sets this centrally.

Secure DNS guide →

Wi-Fi router

  1. Add your network's public IP address as a linked client IP in your GraceDNS configuration (your router's status page shows the IP).
  2. On the router's admin page, set the DNS server to the GraceDNS resolver address from your dashboard and remove any other DNS servers.
  3. Reboot a device on the network and visit a blocked domain to confirm.

One change protects every device on the network, including guests and IoT.

Full router guide, including dynamic IPs →

Smart TV and game console

  1. TVs and consoles rarely support encrypted DNS themselves, so protect them through the network: follow the Wi-Fi router setup.
  2. Once the router points at GraceDNS, every TV, console and smart device on the network is covered automatically.
  3. Visit a blocked domain in the TV browser (or check your query log) to confirm.

Router setup →

Just my browser

  1. Chrome, Edge and Brave: Settings, Privacy and security, Security, Use secure DNS, With: Custom.
  2. Firefox: Settings, search "DNS", choose Max Protection with a Custom provider.
  3. Paste https://dns.gracedns.eu/7f3a9c12.

Filters this browser only; other apps keep using system DNS. Safari has no per-browser setting and needs the Apple profile instead.

Full browser guide →