SQNdns
DoH only · Blocky · Paris, France
French encrypted DNS

SQNdns

A French DNS-over-HTTPS resolver powered by Blocky and hosted in Paris. It blocks ads, trackers and malicious domains without exposing plain DNS.

Endpoint

DNS over HTTPS

For browsers, operating systems and applications that accept a DoH URL.

https://dns.sqn.dedyn.io/dns-query
Deployment

Blocky · Paris, France

Traefik terminates HTTPS, Blocky filters requests and Unbound resolves them recursively.

Hard rule

Encrypted only

Plain DNS on TCP or UDP port 53 is intentionally unavailable.

Device setup

Web BrowsersBrave / Chrome / Firefox

Open the secure DNS setting, choose a custom provider and paste this URL.https://dns.sqn.dedyn.io/dns-query

iOS & macOS

Open this page in Safari and download the profile. Within 8 minutes, open Settings > Profile Downloaded > Install. If Profile Downloaded does not appear outside a familiar location, temporarily disable Stolen Device Protection.
Download configuration profile

Windows 11

SQNdns only supports encrypted DNS over HTTPS. Plain DNS on port 53 is not available.

IPv4 :
158.178.212.166
DNS over HTTPS template:
https://dns.sqn.dedyn.io/dns-query
IPv6 :
2603:c027:c006:a200:0:9018:1fa2:91dc
DNS over HTTPS template:
https://dns.sqn.dedyn.io/dns-query

DNSveil

DNSveil is an open-source secure DNS client for Windows. It can configure a custom DoH resolver such as SQNdns for the whole system, test secure DNS servers and automatically reconnect at Windows startup. DNSveil is not a VPN and does not change your public IP address.

Download DNSveil from GitHub Releases

Routers and applications

Configure SQNdns only when the software accepts a DNS-over-HTTPS URL. A hostname or IP address alone will not work.
Filter lists

Lists are refreshed every hour by Blocky.

Public addresses

IPv4 & IPv6

These addresses do not provide plain DNS service on port 53.

158.178.212.1662603:c027:c006:a200:0:9018:1fa2:91dc
Architecture
Internet / DoH
Traefik
BlockyDNS
Unbound
Authoritative DNS

Traefik handles TLS, Blocky applies filtering and caching, then Unbound performs DNSSEC-validating recursive resolution with IPv6 preferred.