ScotNet Secure DNS

Private DNS, without the marketing fog.

Encrypted DNS for approved users, with DNSSEC validation and network-level filtering. It protects DNS transport; it is not a VPN and does not hide the rest of your traffic.

  • DNS over TLS
  • DNS over HTTPS
  • DNSSEC validation
  • Manual access control
  • Real resolver verification

Start here

Four routes, depending on what you need

Connect a device

Use platform-specific instructions, endpoint checks and rollback steps.

Understand the service

Read the transport, access, logging, retention, filtering and availability disclosures.

Report a problem

Prepare a structured report for a false positive, outage, certificate issue or setup failure.

What it does

A resolver with clear boundaries

Encrypted transport

DoT and DoH encrypt DNS traffic between your device and ScotNet DNS, reducing plain-text observation on local and access networks.

Answer validation

DNSSEC validation checks signed DNS data. A failed validation is returned as a lookup failure rather than a trusted answer.

Network filtering

Known advertising, telemetry and abusive domains may be blocked before a connection is made. False positives remain possible.

Threat model

What this changes — and what it does not

Helps protect against

  • Plain-text DNS observation on local networks
  • Basic DNS tampering and resolver hijacking
  • Invalid DNSSEC-signed responses
  • Connections to domains covered by active filter policy

Does not protect against

  • Malware, hostile extensions or stolen credentials
  • Destination-IP visibility elsewhere on the path
  • Tracking performed inside websites or apps
  • Every malicious domain or every false-positive block

Published facts

Operational claims that can be checked

  • DoH is served only at /dns-query and approved ClientID paths.
  • DoT is available on port 853.
  • DNSSEC validation is tested with a deliberately bogus signed domain.
  • The AdGuard Home administration interface is not public.
  • The public website uses no advertising or third-party analytics.

Privacy and operations

Specific wording, not a “no logging” slogan

The website runs no advertising or third-party analytics. ScotNet avoids behavioural profiling and does not sell resolver data. Short-lived operational and security records may exist for diagnosis, abuse mitigation and reliability. ScotNet’s general policy says typical retention does not exceed 30 days unless an active investigation or legal obligation requires a temporary extension.

Filtering review

A legitimate domain blocked?

Report the domain, approximate time, device, transport and observed response. Reports are reviewed; they never trigger an automatic allow-list change.