Ubiquiti ยท UniFi Network

DNS Setup on UniFi gateways

Classic DNS for the network โ€“ optionally encrypted via DoH.

Through the UniFi Network console you distribute DNS servers via DHCP to all clients and can additionally enable Encrypted DNS (DoH) via DNS Stamps on the gateway.

DNS Server Credentials

IPv4 Addresses

Classic DNS servers for IPv4 configuration.

theo.dremaxx.de85.215.153.54
fritz.dremaxx.de87.106.35.241
IPv6 Addresses

Native IPv6 reachability of the resolvers.

theo.dremaxx.de2a01:239:251:a800::1
fritz.dremaxx.de2a00:da00:f425:5800::1
DNS Stamps

Stamps for clients with DNSCrypt/DoH stamp support.

theo.dremaxx.desdns://AgcAAAAAAAAADTg1LjIxNS4xNTMuNTQAD3RoZW8uZHJlbWF4eC5kZQovZG5zLXF1ZXJ5
fritz.dremaxx.desdns://AgcAAAAAAAAADTg3LjEwNi4zNS4yNDEAEGZyaXR6LmRyZW1heHguZGUKL2Rucy1xdWVyeQ
01 ยท Classic

DHCP Name Server

Distributes DNS servers via DHCP to all devices in the respective network.

1
Open UniFi Network console

In the Web UI go to Settings โ†’ Networks and select the desired network.

UniFi Network overview
2
Advanced DHCP options

In the section Advanced โ†’ DHCP Service Management set the option DHCP Name Server to Manual.

UniFi DHCP Name Server
3
Enter DNS servers
DNS Server 185.215.153.54
DNS Server 287.106.35.241
4
Apply

Confirm with Apply Changes. Clients pick up the new servers on the next DHCP lease.

02 ยท Encrypted

Encrypted DNS (DoH) via DNS Stamp

Enables encrypted resolution at the gateway itself โ€“ the resolver is taken over by the UniFi router.

1
Enable Encrypted DNS

Under Settings โ†’ Internet โ†’ Primary (WAN) โ†’ Advanced enable Encrypted DNS and choose DNSCrypt v2.

UniFi Encrypted DNS configuration
2
Add DNS stamps

Under Custom Stamps add both stamps:

theosdns://AgcAAAAAAAAADTg1LjIxNS4xNTMuNTQAD3RoZW8uZHJlbWF4eC5kZQovZG5zLXF1ZXJ5
fritzsdns://AgcAAAAAAAAADTg3LjEwNi4zNS4yNDEAEGZyaXR6LmRyZW1heHguZGUKL2Rucy1xdWVyeQ
3
Save

Confirm with Apply Changes. The gateway now forwards DNS queries encrypted to the Dremaxx resolvers.

03 ยท Notes

Troubleshooting

DHCP lease

Clients have to renew their DHCP lease for the new resolver to take effect.

DoH at the gateway

Encrypted DNS at the gateway only encrypts the path from router to Internet โ€“ not within the LAN.

Firmware up to date

Encrypted DNS requires a current UniFi-OS or Network firmware.