Step-by-step guide to configure Brave Browser to use our secure, token-gated DNS-over-HTTPS (DoH) service.
๐ฆ Brave Browser • Desktop โ Verified • Working ๐ DoH • Token AuthBrave Browser includes built-in support for DNS-over-HTTPS (DoH) with custom providers. This guide will help you configure Brave to use our secure DNSaaS service with token-based authentication.
| Service | Endpoint | Authentication |
|---|---|---|
| Primary DNS | https://dns1.oss.co.za/xxxxx?dsn |
Token in URL path |
| Protocol | DNS-over-HTTPS (DoH) • Port 443 • TLS 1.3 | |
| Brave Version | Version 1.50+ (all recent versions) | |
?dsn (not {?dns}).
Click the Brave menu (three horizontal lines in the top-right corner) โ select Settings.
Alternatively, type brave://settings/ in the address bar and press Enter.
In the left sidebar, click Privacy and security โ then click Security.
Alternatively, type brave://settings/security in the address bar.
Scroll down to the Advanced section.
Look for "Use secure DNS".
Toggle the switch to ON for "Use secure DNS".
Select "Add custom DNS service provider" from the dropdown menu.
Enter the following URL (replace token_testclient123 with your token):
/token_testclient123?dsn parameter tells Brave this is a DNS provider/dns-query suffix or {?dns} template neededThe setting saves automatically. Brave will validate the endpoint and should accept it without errors.
Use these test sites to verify your Brave configuration is working correctly.
| Test Domain | Expected Result | What You Should See |
|---|---|---|
http://zycdjz.com |
BLOCKED | "This site can't be reached" or DNS_PROBE_POSSIBLE |
http://malware.testcategory.com |
BLOCKED | "This site can't be reached" or DNS_PROBE_POSSIBLE |
http://phishing.testcategory.com |
BLOCKED | "This site can't be reached" or DNS_PROBE_POSSIBLE |
http://adult.filterdns.net |
BLOCKED | "This site can't be reached" or DNS_PROBE_POSSIBLE |
| Test Domain | Expected Result | What You Should See |
|---|---|---|
https://example.com |
LOAD | Normal page loads |
https://google.com |
LOAD | Normal page loads |
| Test Domain | Expected Result | What You Should See |
|---|---|---|
https://dnsleaktest.com |
Your DNS Server | Should show dns1.oss.co.za or 102.220.218.218 |
Here's how the same domain appears in different browsers:
503 Service Temporarily UnavailableDNS_PROBE_POSSIBLE - the domain is blocked!https://dns1.oss.co.za/xxxxx?dsn{?dns} - Brave accepts ?dsndns1.oss.co.zabrave://net-internals/#dns โ Clear host cache/etc/powerdns/siteslist.rpzhttp://adult.filterdns.net - should show "This site can't be reached"https://dnsleaktest.com - should show dns1.oss.co.zabrave://net-internals/#dns and check for DNS-over-HTTPS queriesTo revert to your previous DNS settings:
brave://settings/security
Toggle the "Use secure DNS" switch to OFF.
Alternatively, select "With your current service provider" from the dropdown.
Visit brave://net-internals/#dns and click "Clear host cache".
https://dns1.oss.co.za/xxxxx?dsn?dsn parameter is required - not {?dns}
Settings โ Privacy and Security โ Security โ Use secure DNS โ Add custom DNS service provider
https://dns1.oss.co.za/testclient123?dsn