This document describes the public behaviour and policy boundaries of ScotNet Secure DNS. It follows the disclosure themes in RFC 8932 while avoiding claims that are not operationally verified.
Effective date. Version 1.2.0, reviewed 31 July 2026. Material changes are recorded below.
Service identity
Who and what
Operator
ScotNet, independently operated.
Public hostname
dns.scott.ovh
Supported transports
DNS over TLS on port 853 and DNS over HTTPS at https://dns.scott.ovh/dns-query.
Intended users
Approved users and devices. The service is not an open recursive resolver.
Administration
The AdGuard Home administration interface is bound to loopback and is not exposed as a public website route.
Encryption and validation
Transport and answer integrity
DoH
HTTPS requests are accepted at the exact /dns-query
DoT
TLS-protected DNS is available at dns.scott.ovh:853.
Certificates
Clients must validate the certificate for dns.scott.ovh. Certificate warnings must not be bypassed.
DNSSEC
Validation is enabled and monitored. Deliberately bogus signed responses are expected to fail with SERVFAIL.
Plain DNS
Port 53 may be enabled for approved clients, but encrypted transports are the published user-facing service.
Access control
Restricted by design
Access approval is manual.
AdGuard Home allowed_clients restricts resolver use.
Source-address approval may stop working when a mobile or residential address changes.
Approved ClientIDs may be supported for encrypted-DNS clients, but identifiers must not be published.
Access may be rotated, limited or withdrawn to protect reliability and other users.
Data handling
What the service can observe
Information the resolver may receive
DNS question names and record types
Response status and filtering action
Timestamp and encrypted transport
Source network address or approved client identity
Operational errors and performance events
What is not promised
This is not a zero-log or anonymous resolver
Encrypted DNS does not hide queries from ScotNet
It does not hide destination IP addresses elsewhere
It does not prevent tracking inside websites or apps
Minimisation and retention. The public website uses no advertising or third-party analytics. ScotNet avoids behavioural profiling and does not sell resolver data. Operational and security records may be retained for diagnosis, abuse mitigation and reliability. ScotNet’s general privacy policy states that typical retention does not exceed 30 days unless an active investigation or legal obligation requires a temporary extension.
Access to records
Limited operational use
Records are used for service operation, fault diagnosis, capacity work, abuse prevention and security investigations.
Administrative access is limited to the operator and authorised maintenance activity.
Information is not sold to advertisers or data brokers.
Disclosure may occur when required by law or necessary to investigate serious abuse or protect the service.
Security evidence may be retained longer than routine records while an active case remains open.
DNS behaviour
Filtering, ECS and upstreams
Filter scope
Known advertising, telemetry and abusive infrastructure may be filtered. Sources and categories change as policy and evidence change.
Filter response
No single public response code is guaranteed. Current policy can use address rewrites, NXDOMAIN, REFUSED or another controlled response.
False positives
Reports are reviewed manually. Submission does not guarantee an allow-list entry or immediate change.
EDNS Client Subnet
No contractual ECS behaviour is published. Clients must not rely on ECS being forwarded, stripped or disabled without operator confirmation.
Recursion and upstreams
The internal recursive or forwarding architecture is not published as a fixed dependency and may change without changing the public endpoints.
Availability
Best effort, monitored, no formal SLA
No formal uptime guarantee is offered.
Maintenance, abuse controls and emergency security work can interrupt service.
Website availability does not prove that DoH or DoT is healthy; transports are tested separately.
The public status page is the source for incident and availability information.
Expanded platform onboarding, data-handling disclosure, access-control wording, reporting categories, status URL and machine-readable service facts. Resolver behaviour is unchanged.
30 July 2026
1.1.1
Production acceptance release; public AdGuard administration removed, operational checks added and website security headers tightened.
30 July 2026
1.1.0
First dedicated resolver-practices disclosure and setup pages.