Choose the guide for the device or browser you actually use. Menu wording changes between releases, but the endpoint values remain the same.
Approval comes first. A correct client configuration will still fail when the device, ClientID or current source address has not been approved.
Endpoint values
Copy exactly — do not add spaces
DNS over TLS
dns.scott.ovh
Standard port: 853. Android Private DNS expects the hostname only.
DNS over HTTPS
https://dns.scott.ovh/dns-query
Use the complete HTTPS URL where a custom DoH template is requested.
Android Private DNS
System-wide DNS over TLS on supported Android devices.
DoT
Open Settings, then Network & internet or your manufacturer’s equivalent.
Open Private DNS.
Select Private DNS provider hostname.
Enter dns.scott.ovh — no scheme, path or port.
Save. Android validates the TLS connection before accepting the setting.
Mobile-address warning. Source-address approval may stop working when a carrier changes your public address. Android Private DNS cannot supply a username and password.
Verify
Open several sites, then temporarily enter an invalid Private DNS hostname. Android should report that Private DNS cannot connect. Restore dns.scott.ovh afterward.
Undo this configuration
Select Automatic or Off in the same Private DNS screen.
Choose the protection level that permits a custom provider.
Enter https://dns.scott.ovh/dns-query.
Save and restart Firefox if requested.
Scope. This changes Firefox lookups only. Other applications continue using the operating-system resolver.
Verify
Open Firefox’s DNS over HTTPS settings again and confirm the ScotNet URL is still selected. Run the real resolver verification check to prove whether this browser's one-use query reached ScotNet DNS.
Undo this configuration
Return DNS over HTTPS to Default protection or Off.
System-wide encrypted DNS is normally delivered through a DNS Settings configuration profile.
DoH / DoT
Request an operator-supplied ScotNet DNS profile after access approval.
Review the profile’s organisation, DNS protocol, hostname and server URL before installation.
Install it using the profile or device-management workflow appropriate to the device.
Confirm the profile appears under VPN, DNS or device-management settings.
No generic profile is published. Access controls and permitted server addresses must match the approved device. Never install a DNS profile from an untrusted source.
Undo this configuration
Remove the ScotNet DNS profile from device-management or profile settings, then reconnect the network.
Confirm the saved hostname or URL, verify ordinary DNS resolution, and check that strict modes do not silently fall back to plain DNS.
Authoritative resolver identity test
A website loading successfully does not prove that the browser or operating system used ScotNet DNS. The v1.3 resolver check creates a one-use hostname and confirms whether the query reached ScotNet's resolver-local authority.