Step-by-step guide to configure iPhone and iPad to use our secure, token-gated DNS service.
๐ iOS • Mobile โ Verified • Working ๐ DoH/DoT • Token AuthiOS does not have native GUI support for custom DNS-over-HTTPS (DoH) or DNS-over-TLS (DoT) with token authentication. This guide provides two methods to configure your iPhone or iPad to use our secure DNSaaS service.
| Service | Endpoint | Authentication |
|---|---|---|
| Primary DNS | https://dns1.oss.co.za/xxxxx/dns-query |
Token in URL path |
| Protocol | DNS-over-HTTPS (DoH) • Port 443 • TLS 1.3 | |
| iOS Version | iOS 14+ (supports DNS configuration profiles) | |
token_testclient123 (replace with your actual token)token_xxxxxxxxxx
This method creates a DNS configuration profile that you install on your iOS device. It's persistent, secure, and works system-wide.
Use an online profile generator or create a .mobileconfig file manually.
Option A: Use a Profile Generator
Option B: Create a .mobileconfig File Manually
token_testclient123 with your actual token in the URL above.
Save the file as dnsaas.mobileconfig on your computer.
Option A: Email - Email the .mobileconfig file to yourself and open it on your iPhone.
Option B: AirDrop - AirDrop the file to your iOS device.
Option C: Web Server - Host the file on a web server and download it via Safari.
On your iOS device, open the .mobileconfig file.
Tap Allow when prompted.
Go to Settings โ General โ VPN & Device Management.
Tap Install for the DNS profile.
Enter your device passcode if prompted.
Tap Install again and then Done.
Go to Settings โ Wi-Fi โ tap the (i) next to your connected network.
Scroll to DNS - it should show your DNSaaS server IPs.
If you prefer a graphical interface or don't want to create a profile, several third-party apps support DoH with custom providers.
Download AdGuard DNS from the App Store.
Configure with your DoH endpoint:
Download DNS Cloak from the App Store.
Add a custom DNS server with your DoH endpoint.
Download NextDNS from the App Store.
Configure with your DoH endpoint and token.
Use these test sites to verify your iOS configuration is working correctly.
| Test Domain | Expected Result |
|---|---|
https://example.com |
โ Should load normally |
http://zycdjz.com |
โ Should show "This site can't be reached" |
http://adult.filterdns.net |
โ Should show "This site can't be reached" |
| Test Domain | Expected Result |
|---|---|
https://dnsleaktest.com |
Should show dns1.oss.co.za or 102.220.218.218 |
| Test | Expected Result |
|---|---|
| Settings โ General โ VPN & Device Management โ Configuration Profiles | Should show DNSaaS Secure DNS profile |
| Settings โ Wi-Fi โ (i) โ DNS | Should show 102.220.218.218 and 102.220.218.219 |
.mobileconfig extensiondns1.oss.co.zahttps://dns1.oss.co.za/xxxxx/dns-queryhttp://adult.filterdns.net - should show "This site can't be reached"https://dnsleaktest.com - should show your DNS serverTo revert to your previous DNS settings:
Go to Settings โ General โ VPN & Device Management โ Configuration Profiles.
Tap the DNSaaS Secure DNS profile โ tap Remove.
Enter your device passcode if prompted.
Restart your iPhone or iPad to clear the DNS cache.
Go to Settings โ Wi-Fi โ tap the (i) next to your network.
DNS should now be set to Automatic (your ISP's DNS).
/dns-query format in the profile