DNS over TLS
Encrypts the query end-to-end over port 853, protecting lookups from passive observation on supported systems.
OxyDNS resolves fast and stays out of the way — Plain DNS for compatibility, DNS-over-TLS and DNS-over-HTTPS when you want the query encrypted in transit. No accounts, no apps, five minutes to set up.
Everything a modern resolver should do: encrypted transport where you want it, plain compatibility where you need it, and safeguards that keep answers clean.
Encrypts the query end-to-end over port 853, protecting lookups from passive observation on supported systems.
Resolves over standard HTTPS, so encrypted lookups blend in with ordinary web traffic in supported browsers and apps.
Standard DNS on port 53 for maximum compatibility with routers, IoT devices, and legacy network stacks.
Built to minimize unnecessary exposure, with public endpoints that keep setup simple for everyday users.
DNSSEC validation and response filtering are on out of the box — nothing extra to configure.
Reliable routing and continuous operational monitoring for consistent day-to-day resolution.
Pick the option that matches your device or client — copy it in, and you're resolving through OxyDNS.
dns.oxychain.xyzUse as the Private DNS provider hostname in Android network settings.
dns.oxychain.xyz:853Use in systems and apps that support DoT with an explicit hostname and port.
https://dns.oxychain.xyz/dns-queryUse in browsers, DoH-aware clients, and apps that accept a query URL.
87.120.126.55
87.120.126.46Use as IPv4 DNS server addresses in standard router or OS network settings.
Public endpoints, modern protocols, and a setup experience that doesn't get in the way.
Reduces unnecessary DNS exposure wherever your device supports it.
Configured safeguards keep answers accurate and predictable.
DoT and DoH are ready to go on any compatible client.
Works well on mobile, desktop, routers, and browsers alike.
OxyDNS is a resolver, not a VPN replacement — it improves DNS behavior while keeping configuration clear and predictable.
Responses are checked for DNSSEC validity wherever the record supports it.
Safeguards reduce the risk of unsafe private or internal DNS answers leaking out.
Strong encrypted DNS options through DoT and DoH, side by side with plain compatibility.
Built for stable resolution with continuous operational checks behind the scenes.
We analyze your network in real time — checking for DNS leaks, WebRTC exposure, timezone anomalies, and proxy signatures. All processing happens locally; no data leaves your device.
Point your devices at OxyDNS for a faster, cleaner, more reliable resolution experience — every day, on everything you use.