<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS over HTTPS (DOH) and custom filtering on OpenDNS in OpenDNS</title>
    <link>https://community.cisco.com/t5/opendns/dns-over-https-doh-and-custom-filtering-on-opendns/m-p/5309215#M18404</link>
    <description>&lt;P&gt;You're absolutely right — OpenDNS (now Cisco Umbrella) supports DNS over HTTPS (DoH), but custom filtering (like content categories or domain blacklists) is only applied when requests come from your registered IP, not just any client using the public OpenDNS resolvers.&lt;/P&gt;&lt;P&gt;So, if you want to use DoH and benefit from your OpenDNS custom filtering, here's what you need to know:&lt;/P&gt;&lt;P&gt;Summary: Can OpenDNS Be Used with DoH and Custom Filtering?&lt;BR /&gt;Feature Supported&lt;BR /&gt;DNS-over-HTTPS (DoH)&amp;nbsp; &amp;nbsp;Yes (via &lt;A href="https://doh.opendns.com/dns-query" target="_blank"&gt;https://doh.opendns.com/dns-query&lt;/A&gt;)&lt;BR /&gt;Custom filtering with DoH&amp;nbsp; &amp;nbsp;Yes, but only if source IP is registered with your OpenDNS dashboard&lt;/P&gt;&lt;P&gt;You must register the public IP of the client or DoH resolver in your OpenDNS dashboard.&lt;/P&gt;&lt;P&gt;How to Use DoH with OpenDNS and Apply Custom Filtering&lt;BR /&gt;1. Register Your IP in OpenDNS&lt;BR /&gt;Go to dashboard.opendns.com/settings&lt;/P&gt;&lt;P&gt;Add your external/public IP address&lt;/P&gt;&lt;P&gt;Assign your custom filtering and security settings&lt;/P&gt;&lt;P&gt;This IP must match the source IP seen by OpenDNS when resolving DNS queries — i.e., the IP of your firewall/router, or the IP of the device doing DoH (if not behind NAT)&lt;/P&gt;&lt;P&gt;2. Use OpenDNS DoH Endpoint&lt;BR /&gt;Use the following DoH resolver:&lt;/P&gt;&lt;P&gt;arduino&lt;BR /&gt;Copy&lt;BR /&gt;Edit&lt;BR /&gt;&lt;A href="https://doh.opendns.com/dns-query" target="_blank"&gt;https://doh.opendns.com/dns-query&lt;/A&gt;&lt;BR /&gt;Supported by clients like Firefox, NextDNS CLI, or dnscrypt-proxy&lt;/P&gt;&lt;P&gt;Uses your public IP for filtering decisions&lt;/P&gt;&lt;P&gt;3. Configure DoH on the Client&lt;BR /&gt;Example: Firefox&lt;BR /&gt;Go to about:preferences#privacy&lt;/P&gt;&lt;P&gt;Enable DNS over HTTPS&lt;/P&gt;&lt;P&gt;Choose Custom Provider:&lt;/P&gt;&lt;P&gt;arduino&lt;BR /&gt;Copy&lt;BR /&gt;Edit&lt;BR /&gt;&lt;A href="https://doh.opendns.com/dns-query" target="_blank"&gt;https://doh.opendns.com/dns-query&lt;/A&gt;&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":magnifying_glass_tilted_left:"&gt;🔍&lt;/span&gt; Your public IP (not just doh.opendns.com) must be recognized in your OpenDNS account for filtering to apply.&lt;/P&gt;&lt;P&gt;4. Optional: Use myip.opendns.com to Verify&lt;BR /&gt;To verify what IP OpenDNS sees (via DNS):&lt;/P&gt;&lt;P&gt;bash&lt;BR /&gt;Copy&lt;BR /&gt;Edit&lt;BR /&gt;dig @208.67.222.222 myip.opendns.com +short&lt;BR /&gt;5. Troubleshooting&lt;BR /&gt;Issue Fix&lt;BR /&gt;Filtering not applied Confirm your public IP is registered in OpenDNS&lt;BR /&gt;Using VPN or NAT Your DoH source IP may differ — register the exit IP&lt;BR /&gt;Using 3rd-party DoH resolver Will bypass OpenDNS filtering&lt;/P&gt;&lt;P&gt;Important Limitation&lt;BR /&gt;OpenDNS does not support user-level or key-authenticated DoH — it relies only on source IP. So:&lt;/P&gt;&lt;P&gt;You can’t apply filtering rules per-device using just DoH.&lt;/P&gt;&lt;P&gt;Use Umbrella Roaming Client or Cisco Secure Client for per-device enforcement (that uses DoH with identity).&lt;/P&gt;&lt;P&gt;Best Practice&lt;BR /&gt;If you want to... Then...&lt;BR /&gt;Apply filtering via DoH to a known IP (e.g., your home firewall)&amp;nbsp; &amp;nbsp;Use &lt;A href="https://doh.opendns.com/dns-query" target="_blank"&gt;https://doh.opendns.com/dns-query&lt;/A&gt; and register your home IP in OpenDNS&lt;BR /&gt;Apply per-device filtering using DoH (e.g., on laptops)&amp;nbsp; &amp;nbsp;Use Cisco Umbrella Roaming Client or Secure Client&lt;BR /&gt;Use dynamic IP (home users)&amp;nbsp; &amp;nbsp;Use OpenDNS Updater tool to keep your IP updated in the dashboard&lt;/P&gt;</description>
    <pubDate>Mon, 14 Jul 2025 16:11:59 GMT</pubDate>
    <dc:creator>wajidhassan</dc:creator>
    <dc:date>2025-07-14T16:11:59Z</dc:date>
    <item>
      <title>DNS over HTTPS (DOH) and custom filtering on OpenDNS</title>
      <link>https://community.cisco.com/t5/opendns/dns-over-https-doh-and-custom-filtering-on-opendns/m-p/5301416#M18370</link>
      <description>&lt;P&gt;Hi.&amp;nbsp; I have set up some customer filtering using openDNS.&amp;nbsp; Can i access that via DOH, from what I read seems people only reference the public opendns server.&lt;/P&gt;&lt;P&gt;What settings should i use if I want to use DOH and opendns custom filtering&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&amp;nbsp; D&lt;/P&gt;</description>
      <pubDate>Sun, 22 Jun 2025 13:05:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/dns-over-https-doh-and-custom-filtering-on-opendns/m-p/5301416#M18370</guid>
      <dc:creator>Damien01001</dc:creator>
      <dc:date>2025-06-22T13:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: DNS over HTTPS (DOH) and custom filtering on OpenDNS</title>
      <link>https://community.cisco.com/t5/opendns/dns-over-https-doh-and-custom-filtering-on-opendns/m-p/5309215#M18404</link>
      <description>&lt;P&gt;You're absolutely right — OpenDNS (now Cisco Umbrella) supports DNS over HTTPS (DoH), but custom filtering (like content categories or domain blacklists) is only applied when requests come from your registered IP, not just any client using the public OpenDNS resolvers.&lt;/P&gt;&lt;P&gt;So, if you want to use DoH and benefit from your OpenDNS custom filtering, here's what you need to know:&lt;/P&gt;&lt;P&gt;Summary: Can OpenDNS Be Used with DoH and Custom Filtering?&lt;BR /&gt;Feature Supported&lt;BR /&gt;DNS-over-HTTPS (DoH)&amp;nbsp; &amp;nbsp;Yes (via &lt;A href="https://doh.opendns.com/dns-query" target="_blank"&gt;https://doh.opendns.com/dns-query&lt;/A&gt;)&lt;BR /&gt;Custom filtering with DoH&amp;nbsp; &amp;nbsp;Yes, but only if source IP is registered with your OpenDNS dashboard&lt;/P&gt;&lt;P&gt;You must register the public IP of the client or DoH resolver in your OpenDNS dashboard.&lt;/P&gt;&lt;P&gt;How to Use DoH with OpenDNS and Apply Custom Filtering&lt;BR /&gt;1. Register Your IP in OpenDNS&lt;BR /&gt;Go to dashboard.opendns.com/settings&lt;/P&gt;&lt;P&gt;Add your external/public IP address&lt;/P&gt;&lt;P&gt;Assign your custom filtering and security settings&lt;/P&gt;&lt;P&gt;This IP must match the source IP seen by OpenDNS when resolving DNS queries — i.e., the IP of your firewall/router, or the IP of the device doing DoH (if not behind NAT)&lt;/P&gt;&lt;P&gt;2. Use OpenDNS DoH Endpoint&lt;BR /&gt;Use the following DoH resolver:&lt;/P&gt;&lt;P&gt;arduino&lt;BR /&gt;Copy&lt;BR /&gt;Edit&lt;BR /&gt;&lt;A href="https://doh.opendns.com/dns-query" target="_blank"&gt;https://doh.opendns.com/dns-query&lt;/A&gt;&lt;BR /&gt;Supported by clients like Firefox, NextDNS CLI, or dnscrypt-proxy&lt;/P&gt;&lt;P&gt;Uses your public IP for filtering decisions&lt;/P&gt;&lt;P&gt;3. Configure DoH on the Client&lt;BR /&gt;Example: Firefox&lt;BR /&gt;Go to about:preferences#privacy&lt;/P&gt;&lt;P&gt;Enable DNS over HTTPS&lt;/P&gt;&lt;P&gt;Choose Custom Provider:&lt;/P&gt;&lt;P&gt;arduino&lt;BR /&gt;Copy&lt;BR /&gt;Edit&lt;BR /&gt;&lt;A href="https://doh.opendns.com/dns-query" target="_blank"&gt;https://doh.opendns.com/dns-query&lt;/A&gt;&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":magnifying_glass_tilted_left:"&gt;🔍&lt;/span&gt; Your public IP (not just doh.opendns.com) must be recognized in your OpenDNS account for filtering to apply.&lt;/P&gt;&lt;P&gt;4. Optional: Use myip.opendns.com to Verify&lt;BR /&gt;To verify what IP OpenDNS sees (via DNS):&lt;/P&gt;&lt;P&gt;bash&lt;BR /&gt;Copy&lt;BR /&gt;Edit&lt;BR /&gt;dig @208.67.222.222 myip.opendns.com +short&lt;BR /&gt;5. Troubleshooting&lt;BR /&gt;Issue Fix&lt;BR /&gt;Filtering not applied Confirm your public IP is registered in OpenDNS&lt;BR /&gt;Using VPN or NAT Your DoH source IP may differ — register the exit IP&lt;BR /&gt;Using 3rd-party DoH resolver Will bypass OpenDNS filtering&lt;/P&gt;&lt;P&gt;Important Limitation&lt;BR /&gt;OpenDNS does not support user-level or key-authenticated DoH — it relies only on source IP. So:&lt;/P&gt;&lt;P&gt;You can’t apply filtering rules per-device using just DoH.&lt;/P&gt;&lt;P&gt;Use Umbrella Roaming Client or Cisco Secure Client for per-device enforcement (that uses DoH with identity).&lt;/P&gt;&lt;P&gt;Best Practice&lt;BR /&gt;If you want to... Then...&lt;BR /&gt;Apply filtering via DoH to a known IP (e.g., your home firewall)&amp;nbsp; &amp;nbsp;Use &lt;A href="https://doh.opendns.com/dns-query" target="_blank"&gt;https://doh.opendns.com/dns-query&lt;/A&gt; and register your home IP in OpenDNS&lt;BR /&gt;Apply per-device filtering using DoH (e.g., on laptops)&amp;nbsp; &amp;nbsp;Use Cisco Umbrella Roaming Client or Secure Client&lt;BR /&gt;Use dynamic IP (home users)&amp;nbsp; &amp;nbsp;Use OpenDNS Updater tool to keep your IP updated in the dashboard&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2025 16:11:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/dns-over-https-doh-and-custom-filtering-on-opendns/m-p/5309215#M18404</guid>
      <dc:creator>wajidhassan</dc:creator>
      <dc:date>2025-07-14T16:11:59Z</dc:date>
    </item>
  </channel>
</rss>

