---
metadata:
  - name: generator
    content: Diplodoc Platform v5.50.2
alternate:
  - https://yandex.com/support/dns/en/settings-windows.md
  - https://yandex.com/support/dns/ru/settings-windows.md
---
> **Documentation Index:** Fetch the complete configuration index at https://yandex.com/support/dns/en/llms.txt

# Setup in Windows

{% cut "**Setting up DoH on Windows 11**" %}

{% note warning %}

The DoH protocol is available only for Windows 11. 

{% endnote %}

  1. Navigate to **Start** → **Settings** → **Network & internet** → **Wi‑Fi** or **Ethernet**, then select **<Wireless_network> properties** if you're using Wi‑Fi.

  1. Under **DNS server assignment**, click **Edit** → **Manual** and enable **IPv4**.
  
  1. In the **Preferred DNS** and **Alternate DNS** fields, enter the primary and secondary IPv4 addresses for your selected operating [mode](https://yandex.com/support/dns/en/ya-dns-modes.md#ya-dns-mode):

     <br>

     #|
     || **Mode** | **IPv4** ||
     || Basic | 
     Primary: `77.88.8.8`

     Secondary: `77.88.8.1`
     ||
     || Safe | 
     Primary: `77.88.8.88`

     Secondary: `77.88.8.2`
     ||
     || Family |
     Primary: `77.88.8.7`

     Secondary: `77.88.8.3`
     ||
     |#


  1. Configure DNS encryption (DoH) by following the steps for your Windows version.

     {% note tip %}
     
     To check your version number on Windows 11, type `winver` in the search bar and press **Enter**. This opens a window with information about your current system version.
     
     {% endnote %} 
     
     {% list tabs %}

     - Version 21H1

       For each DNS server, select your desired option in the **Preferred DNS encryption** field:
 
       - **Unencrypted only**: Use standard DNS without encryption.
       - **Encrypted only (DNS over HTTPS)**: Use DoH only.
       - **Encrypted preferred, unencrypted allowed**: Attempt to use DoH and fall back to unencrypted DNS if DoH isn't available.

     - Version 21H2 and above

       For each DNS server, in the **DNS over HTTPS** field, select **On (manual template)** and specify the DoH template corresponding to your selected operating mode.

       #|
       || **Mode**  | **DoH template** ||
       || Basic    | `https://common.dot.dns.yandex.net` or `https://common.dot.dns.yandex.net/dns-query` ||
       || Safe | `https://safe.dot.dns.yandex.net` or `https://safe.dot.dns.yandex.net/dns-query` ||
       || Family   | `https://family.dot.dns.yandex.net` or `https://family.dot.dns.yandex.net/dns-query` ||
       |#

     {% endlist %}

  1. Apply your changes and [verify](#check) that encryption is active.

#### Testing {#check}

Verify that DNS traffic is encrypted using Packet Monitor (Pktmon), the network diagnostic tool included in Windows:

1. Open Command Prompt or PowerShell as an administrator.
1. Run the following command to clear any existing network traffic packet filters in Pktmon:

   ```
   pktmon filter remove
   ```
1. Add a filter for DNS port 53:
   
   ```
   pktmon filter add -p 53
   ```
1. Activate real-time monitoring:

   ```
   pktmon start --etw -m real-time
   ```

   Command Prompt should output all port 53 packets. If DoH is enabled, nothing will appear because Windows is routing DNS requests over HTTPS instead of port 53.
   
   If the output shows traffic on port 53, it means that DoH isn't configured properly. Check your DNS server settings and verify that the servers support DoH.

{% endcut %}

{% cut "**Windows 11**" %}

1. Open the **Start** menu and select **Settings**.

   ![](_images/win11-parameters.png)

1. In the side menu, select **Network & internet**.

   ![](_images/win11-network-view.png)

1. Select **Properties**.

   ![](_images/win11-change-adapter-params.png)

1. Next to **DNS server assignment**, select **Edit**.

   ![](_images/win11-adapter-properties.png)

1. In the window that opens, select **Manual**.

   ![](_images/win11-ipv4-properties.png)

1. Select the protocol version you're using.

   ![](_images/win11-dns-custom.png)

1. In the **Preferred DNS** and **Alternate DNS** fields, enter the IP addresses of the DNS servers that you [selected](https://yandex.com/support/dns/en/ya-dns-modes.md#ya-dns-ip).
 
   ![](_images/win11-dns-custom-yandex.png)

{% endcut %}

{% cut "**Windows 10**" %}

1. In the search box on the taskbar, type `control panel` and select the **Control Panel** in the results.

1. Under **View by**, select **Category**.

   ![](_images/win10-categorie.png)

1. In the **Network and Internet** section, click **View network status and tasks**.

   ![](_images/win10-network-view.png)

1. Click **Change adapter settings**.

   ![](_images/win10-change-adapter-params.png)

1. Right-click your network connection, then select **Properties**.

   ![](_images/win10-adapter-properties.png)

1. Click **Internet Protocol Version 4 (TCP/IPv4)** → **Properties**.

   ![](_images/win10-ipv4-properties.png)

1. Enable the option **Use the following DNS server addresses**.

   ![](_images/win10-dns-custom.png)

1. In the **Preferred DNS server** and **Alternate DNS server** fields, enter the IP addresses of the DNS servers that you [selected](https://yandex.com/support/dns/en/ya-dns-modes.md#ya-dns-ip).

   ![](_images/win10-dns-custom-yandex.png)

{% endcut %}

{% cut "**Windows 8 or 8.1**" %}

1. Swipe left from the right edge of the screen or move the mouse pointer to the upper-right corner of the screen and then down. Click **Search**. In the search box, type `control panel` and select the **Control Panel** in the results.

   ![](_images/search.png)

1. Under **View by**, select **Category**.

   ![](_images/categorie-w8.png)

1. In the **Network and Internet** section, click **View network status and tasks**.

   ![](_images/condition-w8.png)

1. Click **Change adapter settings**.

   ![](_images/change.png)

1. Right-click your network connection, then select **Properties**.

   ![](_images/properties-w8.png)

1. Click **Internet Protocol Version 4 (TCP/IPv4)** → **Properties**.

   ![](_images/features-w8.png)

1. Enable the option **Use the following DNS server addresses**.

   ![](_images/without-protocols-w8.png)

1. In the **Preferred DNS server** and **Alternate DNS server** fields, enter the IP addresses of the DNS servers that you [selected](https://yandex.com/support/dns/en/ya-dns-modes.md#ya-dns-ip).

   ![](_images/dns-servers.png)

{% endcut %}

{% cut "**Windows 7**" %}

1. Click **Start** → **Control Panel**. Under **View by**, select **Category**.

   ![](_images/categories.png)

1. In the **Network and Internet** section, click **View network status and tasks**.

   ![](_images/condition.png)

1. Under **View your active networks**, click the link next to **Connections**.

   ![](_images/link.png)

1. Click **Properties**.

   ![](_images/properties.png)

1. Click **Internet Protocol Version 4 (TCP/IPv4)** → **Properties**.

    {% note info %}

    If your operating system is password-protected, enter the administrator password.

    {% endnote %}

1. Enable the option **Use the following DNS server addresses**.
1. In the **Preferred DNS server** and **Alternate DNS server** fields, enter the IP addresses of the DNS servers that you [selected](https://yandex.com/support/dns/en/ya-dns-modes.md#ya-dns-ip).

{% endcut %}

{% cut "**Windows XP**" %}

1. Click **Start** → **Control Panel** → **Network Connections**.

   ![](_images/connect.png)

1. Right-click your network connection, then select **Properties**.

   ![](_images/choose-network.png)

1. Click **Internet Protocol (TCP/IP)** → **Properties**.

   ![](_images/features.png)

1. Enable the option **Use the following DNS server addresses**.

   ![](_images/without-protocols.png)

1. In the **Preferred DNS server** and **Alternate DNS server** fields, enter the IP addresses of the DNS servers that you [selected](https://yandex.com/support/dns/en/ya-dns-modes.md#ya-dns-ip).

   ![](_images/protocol.png)

{% endcut %}


<!-- source: en/_includes/button-index.md -->
<a href="en/index">
  <span class="button">Go to the table of contents</span>
</a>



<!-- endsource: en/_includes/button-index.md -->

<!-- source: en/_includes/button-faq.md -->
<a href="en/faq">
  <span class="button">Contact support</span>
</a>



<!-- endsource: en/_includes/button-faq.md -->


