Overview
Last 24 hours
Loading…
Total Queries
Blocked
AI Tools
Unique Domains
Top Domains
AI Tool Usage
Top Blocked
No blocked queries in the last 24h.
| Domain | Count | Reason |
|---|---|---|
Query Log
Top domains, refreshed every 5s · last update
Loading…
No queries in the last hour.
| Domain | Queries | Unique Clients |
|---|---|---|
Threats
Blocks, AI-flagged DGA suspects, and brand typosquats — last 24h
Loading…
Top Blocked Domains
No blocks recorded yet.
| Domain | Count | Reason |
|---|---|---|
By Reason
Typosquat Detections
Lookups matching your protect-list with Damerau-Levenshtein ≤ 2 (post-homoglyph)
No typosquat lookups detected. Add brands via
PUT /policies/protect-list to start scoring.| Looked-up domain | Looks like | Count | Clients |
|---|---|---|---|
DGA Suspects
Feature-based score (entropy, ngram, vowel ratio). Surfaced for review; not auto-blocked.
No DGA-flagged queries in the last 24h.
| Domain | Score | Count |
|---|---|---|
Devices
Per-device DoH endpoints. Point each laptop / phone / router at its URL to attribute lookups.
Loading…
These enrolled themselves with a join code. They are not
filtering yet and cannot resolve through olladns until you
approve them.
| Reported hostname | Name | Enrolled | |
|---|---|---|---|
Enrollment join codes
Give a code to an employee. They run
powershell -ExecutionPolicy Bypass -File .\Set-OllaDns.ps1 -JoinCode <code>
from an elevated PowerShell, and the machine appears above for approval. A code can only add a pending machine —
it cannot read reports, change policy, or approve itself.
The Windows script could not be loaded just now.
It is always available at
.Copy this now — it is shown once.
Everything the employee needs, as one message
| Label | Created | Expires | Used | Status | |
|---|---|---|---|---|---|
No devices yet. Create one via
POST /api/v1/devices (slug + display_name) or ask your AI agent through mcp.olladns.com. Both need an API key — mint one on API Keys.
| Slug | Display name | DoH URL | Last seen | Queries (24h) |
|---|---|---|---|---|
Setup
Point a machine at olladns. Pick the device, then follow the row for its Windows version.
Loading…
1. Which device?
No devices yet. You can use the tenant-wide URL below, but every machine
then reports as one client and per-device analytics stay empty. Create
devices with
POST /api/v1/devices or via your MCP-connected agent —
both need a key, which you mint on
API Keys.
Queries will appear under client_id
3. Did it work?
Yes — traffic from this tenant is reaching olladns.
Most recent query we attributed to you:
at from device id (tenant-wide, no device attributed).
Nothing yet — no query has arrived from this tenant.
That is expected until you run the script above and browse
something. Give it a few seconds, then press Check again.
Test it from the machine itself, not from a browser.
In an ordinary PowerShell or terminal:
Resolve-DnsName ads.yahoo.com -Type A -DnsOnly
It should answer
66.163.115.233 — our block address. A real
address means the machine is still using its previous resolver, so DNS
works but is not going through us.
Why a browser is the wrong test. Chrome and Edge ship
their own DNS-over-HTTPS and do not ask Windows, so a blocked site can
still load even when this machine is configured correctly. And a blocked
HTTPS site shows a certificate error rather than our block page — no
filter can present a valid certificate for a domain it is blocking. To
make browsers obey this, turn off their "Use secure DNS" setting or point
it at the same DoH URL; at scale, push
DnsOverHttpsMode by policy.
2a. Windows 11 (22H2 or newer) — nothing to install
Windows 11 has a built-in DoH client. Download the script, then run it from an
elevated PowerShell. -Rollback restores your previous DNS settings.
2b. Windows 10, or DoH blocked by policy
Windows 10 has no built-in DoH. Run the small olladns-stub forwarder instead:
it listens on 127.0.0.1:53 and relays to your DoH URL. Save the
config beside the executable, start it, then set the adapter's DNS server to
127.0.0.1.
This build is not present on the server yet — ask your operator to run
scripts/build_stub.sh windows.
Not code-signed yet, so Windows SmartScreen will warn on first run.
Check the SHA-256 above before trusting the download.
API Keys
Scoped tokens for the REST API and MCP. Send as
X-API-Key.Loading…
Copy this key now
Label: . It is stored only as a hash —
if you lose it, rotate the key to get a new value.
Create a key
This key will hold
.
tenants:write lets the holder delete this entire tenant.
You are signed in as a viewer. Only tenant admins can view, create, rotate or revoke API keys.
Ask an admin on your tenant if you need one.
Existing keys
No API keys yet. Create one above to start using the REST API or MCP.
| Label | Scopes | Created | Last used | Expires | Actions |
|---|---|---|---|---|---|
| legacy:full — full access |
Policies
Current state of every policy lever. Edit via
PUT /api/v1/policies/* or your MCP-connected AI agent.Loading…
Filtering
Default Mode
NRD Blocking
Blocked TLDs
Custom rules
No custom rules.
| Verdict | Domain |
|---|---|
| block | |
| allow |
Protected brands
No protect-list entries. Typosquat scoring is off.
| Domain | Description |
|---|---|
DNS rewrites
No rewrites configured.
| Domain | Kind | Value |
|---|---|---|
Blocklist preferences
These are recorded preferences, not active filtering. Every tenant currently
receives the same shared blocklist set, so selecting or clearing a list here
does not change what is blocked. Your enforced controls are under
Policies and Protection.
No blocklists selected.
| List | Category | URL |
|---|---|---|
AI Detection
SaaS AI tools detected via DNS
Loading…
No AI tool usage detected in the last 24h.
| Tool | Queries | Unique Clients |
|---|---|---|
Audit Log
Every config change attributed to a human session or an agent token. Read-only.
Loading…
| When | Actor | Action | Detail |
|---|---|---|---|
| No audit events match these filters. | |||