FRITZ!OS 7.20 and newer: DNS-over-TLS
AVM added encrypted upstream DNS in FRITZ!OS 7.20. The Fritz!Box resolves for every device in the home and forwards to dnsdome over TLS. The token in the hostname identifies your profile, so the box does not need a fixed public IP.
- In the dnsdome panel, open your profile and copy the DNS-over-TLS hostname from the Encrypted DNS card:
<token>.dns.dnsdome.com. - Open fritz.box in a browser and go to Internet → Account Information → DNS Server. Enable Advanced View at the bottom right if the tab is missing.
- Under DNSv4 Servers, choose Use other DNSv4 servers and enter
87.244.198.165as preferred. Leave the alternative empty. - Under DNS over TLS (DoT), tick Encrypted name resolution in the Internet (DNS over TLS), tick Enforce certificate check, untick Allow fallback to unencrypted name resolution, and in Resolver names enter
<token>.dns.dnsdome.com. - Click Apply. The status line under the DoT section turns green once the TLS session is up.
If you also have IPv6, set DNSv6 Servers to Use other DNSv6 servers with no address and disable the ISP's DNSv6 hand-out, or clients may resolve through your ISP over IPv6 and skip dnsdome. Alternatively disable IPv6 DNS advertisement under Home Network → Network → Network Settings → IPv6.
Older FRITZ!OS: plain DNS
- Add the Fritz!Box's public IP to the profile's allowlist in the panel. You find it under Overview → Connections.
- Go to Internet → Account Information → DNS Server, choose Use other DNSv4 servers and enter
87.244.198.165. - Apply. Note that most consumer connections change their public IP now and then, so you will need to update the allowlist when filtering stops. FRITZ!OS 7.20 or newer with DoT avoids this.
Verify
On any device at home, load a website, then check the query log in the panel. With Ads & Tracking enabled, nslookup doubleclick.net returns the block response. The Fritz!Box event log under System → Event Log notes DoT connection problems if the hostname was mistyped.
Devices that ignore the router
The Fritz!Box cannot redirect port 53. A device with a hard-coded DNS server bypasses filtering. For phones, set Android Private DNS or install the Apple profile instead, see the Android and iOS guides; the token then follows the phone anywhere.