Encrypted DNS as a new level of security
We constantly work to make your internet not only fast but also secure. Our network now has its own encrypted DNS servers that automatically protect your queries. For most subscribers nothing needs to be configured – everything works automatically.
DNS (Domain Name System) translates site names (e.g. google.com) into IP addresses. Until now DNS queries were transmitted in the open – attackers could see or spoof them.
We have implemented DoH (DNS over HTTPS) and DoT (DNS over TLS). Your DNS queries are now encrypted, protected from spoofing and hidden from third parties. If you use our internet, our encryption-capable DNS servers are assigned to you automatically.
We also implemented modern auto-configuration via SVCB (Service Binding) DNS records. This lets modern devices:
- automatically detect DoH/DoT support;
- switch to the encrypted mode on their own;
- work without manual configuration.
Encrypted DNS gives you:
- privacy – nobody sees which sites you open;
- protection from phishing and DNS spoofing;
- security;
- stability and speed (the servers are inside our network, so latency is minimal).
If you want to configure DNS manually – e.g. your device does not support auto-configuration, you use your own router, or you want to explicitly enable encryption – for both IPv4 and IPv6 use dns1v6.kopiyka.org (port 853) for DoT and https://dns1v6.kopiyka.org/dns-query for DoH. After configuration all DNS traffic will be encrypted.
In Chrome, Edge and Firefox specify https://dns1v6.kopiyka.org/dns-query. On Android go to Settings → Network & internet → Private DNS and enter dns1v6.kopiyka.org.
Even without any configuration, modern devices can use encrypted DNS automatically thanks to our SVCB and TXT records.
So: DNS used to be like an open postcard. Now it is an encrypted channel.
Questions and answers
Will dns1v6.kopiyka.org work if I switch to mobile internet?
Yes. The server is reachable from any Ukrainian network, including all mobile operators. The key is that your device is manually configured to use our DNS (via Private DNS on Android or the browser).
Do I need to configure anything to get the protection?
For subscribers of our network – no. Encryption-capable DNS is assigned automatically. Modern devices also switch to the encrypted mode themselves thanks to our SVCB records.
Why use your DNS if I can set Google (8.8.8.8) or Cloudflare (1.1.1.1)?
Our servers are geographically closer to you, giving faster responses. Using the provider's local DNS also supports internal network security, and your data does not leave the country.
How does DoH differ from DoT?
Both encrypt DNS queries, but differently. DoT (DNS over TLS) uses a separate port 853 and suits routers and system settings. DoH (DNS over HTTPS) sends queries over regular HTTPS and suits browsers – it looks like normal web traffic.
Will encryption slow my internet down?
No. The servers are inside our network, so latency is minimal. In practice you won't notice any speed difference. DoT is slightly faster than DoH as it has less overhead than HTTPS.
Does encrypted DNS protect against viruses and hackers?
Partially. It protects against DNS spoofing and tracking of the sites you visit. But it does not replace an antivirus and does not protect against all threats.
What is SVCB and why is it needed?
SVCB is a special DNS record type that tells a device: "This server supports encryption, switch automatically". Thanks to it modern browsers and systems enable DoH/DoT on their own.
How do I check whether encrypted DNS is actually used?
In Firefox check Settings → Privacy & Security → DNS over HTTPS. There are also online tools like 1.1.1.1/help or browserleaks.com/dns that show which DNS server is really used, though their data is not always precise.
Do I have to pay extra for this service?
No, encrypted DNS is our network's security standard, available to all subscribers completely free of charge.