REDCASCADE ← redcascade.io
RESOLVER LIVE PRERELEASE

Encrypted DNS,
open to everyone.

Free. Private. No accounts. Operational monitoring only — queries are never sold or shared. DNSSEC-validating resolution over every modern encrypted transport, on Wi-Fi and cellular. Currently in prerelease.

Resolver dns.redcascade.io
DoT · 853 DoH · /dns-query DoH3 · HTTP/3 DoQ · QUIC 853 DNSSEC validating Let's Encrypt · Verified
Open & free
No accounts, no sign-up, no fees. Point any device at the resolver and go.
Private by design
Operational monitoring for reliability and abuse prevention — your lookups are never sold, shared, or profiled.
Advanced security
DNSSEC validation plus encrypted transport (DoT, DoH, DoH3, DoQ) end to end.

Set up in minutes

Pick your device — everything you need is below.

Endpoints

Transport Address Port
Plain DNS 185.25.149.131 · 2a02:1778::110:1f 53
DoT (DNS over TLS) tls://dns.redcascade.io 853
DoH (DNS over HTTPS) https://dns.redcascade.io/dns-query 443
DoH3 (DoH over HTTP/3) https://dns.redcascade.io/dns-query 443 / UDP
DoQ (DNS over QUIC) quic://dns.redcascade.io 853 / UDP

Verify it's working

Your public IP

From a terminal with kdig (Knot DNS utils):

kdig +tls   @dns.redcascade.io example.com     # DoT
kdig +https @dns.redcascade.io example.com     # DoH
kdig +quic  @dns.redcascade.io example.com     # DoQ

Each should return NOERROR. On phones, a DNS leak test should show only Red Cascade resolving your queries.

Red Cascade — security-first, self-hosted. Prerelease service — monitored for reliability. Resolver: dns.redcascade.io redcascade.io →