AdGuardDNS icon indicating copy to clipboard operation
AdGuardDNS copied to clipboard

Ubiquity routers and AdGuard DNS

Open trparky opened this issue 5 months ago • 5 comments

I can't for the life of me figure out how to get my Ubiquity router to connect to AdGuard DNS using DoH. Sure, it connects using standard DNS but that's not good.

The Ubiquity interface says that I need something called a DNS stamp and have tried to make one using the tool at https://dnscrypt.info/stamps/ but even then, my Ubiquity router won't connect using DoH.

Can someone help me? Perhaps AdGuard can officially add a DNS stamp generator for those of us using Ubiquity routers

trparky avatar Jul 26 '25 14:07 trparky

I am also experiencing this issue when trying to connect my AdGuard Private DNS server information to a Dream Router 7 via the Encrypted DNS feature. I follow the steps outlined in the AdGuard knowledge base, but I am still unable to connect properly.

endocrine7132 avatar Aug 11 '25 13:08 endocrine7132

Is there any chance that AdGuard will do anything about this?

trparky avatar Oct 01 '25 17:10 trparky

@trparky If using public AGDNS, try using the DNSCrypt sdns:// addressing from https://adguard-dns.io/en/public-dns.html

@endocrine7132 If needing subscribed AGDNS sdns, we're SOL, because, evidently, not enough people are lobbying for https://github.com/AdguardTeam/AdGuardDNS/issues/670#issuecomment-3345480392

TPS avatar Oct 03 '25 11:10 TPS

I tried taking the DNS crypt string and inputting it into the DNS Crypt Stamps page, replaced the IP and the URL and apparently, that's not enough—the public key needs to be updated as well. The GUI of my Unifi Router accepted it but I kept getting logs in my system log that reads like this...

[2025-10-03 09:16:14] [WARNING] [AdGuardDNS] uses a non-standard provider name ('e5cd.adguard-dns.com.' doesn't start with '2.dnscrypt-cert.')

trparky avatar Oct 03 '25 13:10 trparky

According to https://github.com/AdguardTeam/AdGuardDNS/issues/670, it'll take a full custom cert per private address. I guess they never thought to use wildcard certs when building that spec, like can be used for SSL/TLS?

TPS avatar Oct 03 '25 19:10 TPS