DNS over TLS
Encrypts the query end-to-end over port 853, protecting lookups from passive observation on supported systems.
OxyDNS resolves fast and stays out of the way — Plain DNS for compatibility, DNS-over-TLS and DNS-over-HTTPS when you want the query encrypted in transit. No accounts, no apps, five minutes to set up.
Everything a modern resolver should do: encrypted transport where you want it, plain compatibility where you need it, and safeguards that keep answers clean.
Encrypts the query end-to-end over port 853, protecting lookups from passive observation on supported systems.
Resolves over standard HTTPS, so encrypted lookups blend in with ordinary web traffic in supported browsers and apps.
Standard DNS on port 53 for maximum compatibility with routers, IoT devices, and legacy network stacks.
Built to minimize unnecessary exposure, with public endpoints that keep setup simple for everyday users.
DNSSEC validation and response filtering are on out of the box — nothing extra to configure.
Reliable routing and continuous operational monitoring for consistent day-to-day resolution.
Pick the option that matches your device or client — copy the endpoint and you're resolving through OxyDNS.
dns.oxychain.xyzUse as the Private DNS provider hostname in Android network settings.
dns.oxychain.xyz:853Use in systems and apps that support DoT with an explicit hostname and port.
https://dns.oxychain.xyz/dns-queryUse in browsers, DoH-aware clients, and apps that accept a query URL.
87.120.126.55
87.120.126.46Use as IPv4 DNS server addresses in standard router or OS network settings.
OxyDNS processes every resolution using encrypted channels, minimal metadata, and zero logging. Your browsing activity never becomes a product.
Your device sends a DNS query wrapped in TLS or HTTPS. No plaintext on the wire. No passive observer can read it.
OxyDNS processes the query without storing identifying information. Clean resolution, predictable answers.
Cryptographic signatures are checked before the answer is returned — spoofed or tampered records are rejected.
The resolved IP is returned to your device. No query log, no user profile, no data sold to advertisers.
OxyDNS is a resolver, not a VPN replacement — it improves DNS behavior while keeping configuration clear and predictable.
Responses are checked for DNSSEC validity wherever the record supports it.
Safeguards reduce the risk of unsafe private or internal DNS answers leaking out.
Strong encrypted DNS options through DoT and DoH, side by side with plain compatibility.
Built for stable resolution with continuous operational checks behind the scenes.
Quick answers on how OxyDNS works and what it can do for you.
We analyze your network in real time — checking for DNS leaks, WebRTC exposure, timezone anomalies, and proxy signatures. All processing happens locally; no data leaves your device.
Point your devices at OxyDNS for a faster, cleaner, more reliable resolution experience — every day, on everything you use.