---
title: Configuring pfSense® to use Lumiun DNS via the DoT protocol
description: Configuring the Lumiun DNS content filter via dnsmasq. This will cause pfSense® to forward DNS requests to Lumiun DNS using the secure DoT (DNS-over-TLS) protocol. The configuration is done in pfSense®'s default DNS Resolver service, which is Unbound.
---

[Skip to content](https://help.lumiun.com/en-us/hc/configurando-pfsense-para-usar-lumiun-dns-via-dot#main-content)

- [English - United States](https://help.lumiun.com/en-us/hc/configurando-pfsense-para-usar-lumiun-dns-via-dot)
- [Português - Brasil](https://help.lumiun.com/pt-br/hc/configurando-pfsense-para-usar-lumiun-dns-via-dot)

English - United States

Show submenu for translations

[Request Support](https://help.lumiun.com/en-us/hc/kb-tickets/new?hsLang=en-us) [My Tickets](https://tickets.lumiun.com/tickets?hsLang=en-us)

[![logo lumiundns](https://help.lumiun.com/hubfs/lumiundns-x-color.svg)](https://help.lumiun.com/?hsLang=en-us)

Open main navigation

Close main navigation

- - [English - United States](https://help.lumiun.com/en-us/hc/configurando-pfsense-para-usar-lumiun-dns-via-dot)
    - [Português - Brasil](https://help.lumiun.com/pt-br/hc/configurando-pfsense-para-usar-lumiun-dns-via-dot)

  English - United States
  
  Show submenu for translations
- [Request Support](https://help.lumiun.com/en-us/hc/kb-tickets/new)
- [My Tickets](https://tickets.lumiun.com/tickets)
- [Go to Dashboard](https://dns.lumiun.com/)

[Go to Dashboard](https://dns.lumiun.com/)

 How can we help?

- There are no suggestions because the search field is empty.

1. [Lumiun DNS Help Center](https://help.lumiun.com/en-us/hc?hsLang=en-us)
2. [Integrations](https://help.lumiun.com/en-us/hc/integrations?hsLang=en-us)
3. [Firewalls](https://help.lumiun.com/en-us/hc/integrations?hsLang=en-us#firewalls)

# Configuring pfSense® to use Lumiun DNS via the DoT protocol

## This configuration will cause pfSense® to forward DNS requests to Lumiun DNS using the secure DoT (DNS-over-TLS) protocol. The configuration is done in pfSense®'s default DNS Resolver service, which is Unbound.

All devices on the local network that use this pfSense® (and its DNS Resolver) as a DNS server will now observe the rules defined in the Policy assigned to the site selected in the configuration.

### Step-by-step

1. Go to the **Services** → **DNS Resolver** menu.
2. Under Network Interfaces, hold down the Ctrl key and select **LAN** and **Localhost**.
3. Uncheck the **DNSSEC** option.
4. At the bottom of the page, click the **Show Custom Options** button to open the custom options box.
5. Enter the following in the Custom Options box — *replacing **abcd1234** with the ID of the desired site - see the [sites](https://dns.lumiun.com/sites) page for the ID. Also replace “**dns\_server\_1,**” “**dns\_server\_2**,” “**dns6\_server\_1,**” and “**dns6\_server\_2**” with the respective DNS servers for your site, located on the [sites](https://dns.lumiun.com/sites) page.*
   
   ```
   server:  forward-zone:    name: "."    forward-tls-upstream: yes    forward-addr: dns_server_1#abcd1234.dot.ldns.io    forward-addr: dns_server_2#abcd1234.dot.ldns.io    forward-addr: dns6_server_1#abcd1234.dot.ldns.io    forward-addr: dns6_server_2#abcd1234.dot.ldns.io
   ```
6. Save the configuration by clicking the **Save button** and confirm by clicking **Apply Changes**.

 That's it! You can now view [reports](https://dns.lumiun.com/relatorios) on your Lumiun DNS dashboard and also define [policy](https://dns.lumiun.com/politicas) rules.

- [Integrations](https://help.lumiun.com/en-us/hc/integrations?hsLang=en-us#main-content)

    - [Routers](https://help.lumiun.com/en-us/hc/integrations?hsLang=en-us#routers)
    - [Firewalls](https://help.lumiun.com/en-us/hc/integrations?hsLang=en-us#firewalls)
    - [Servers](https://help.lumiun.com/en-us/hc/integrations?hsLang=en-us#servers)
    - [Computers](https://help.lumiun.com/en-us/hc/integrations?hsLang=en-us#computers)
    - [Smartphones](https://help.lumiun.com/en-us/hc/integrations?hsLang=en-us#smartphones)
    - [Browser](https://help.lumiun.com/en-us/hc/integrations?hsLang=en-us#browser)
    - [General](https://help.lumiun.com/en-us/hc/integrations?hsLang=en-us#general)
- [Policies and Filters](https://help.lumiun.com/en-us/hc/policies-and-filters?hsLang=en-us)
- [Networks and Sites](https://help.lumiun.com/en-us/hc/networks-and-sites?hsLang=en-us)
- [Reports](https://help.lumiun.com/en-us/hc/reports?hsLang=en-us)
- [Your Account](https://help.lumiun.com/en-us/hc/your-account?hsLang=en-us#main-content)

    - [Plans and Billing](https://help.lumiun.com/en-us/hc/your-account?hsLang=en-us#plans-and-billing)
- [Partners](https://help.lumiun.com/en-us/hc/partners?hsLang=en-us)
- [FAQ](https://help.lumiun.com/en-us/hc/faq?hsLang=en-us#main-content)

    - [General](https://help.lumiun.com/en-us/hc/faq?hsLang=en-us#general)
    - [pfSense](https://help.lumiun.com/en-us/hc/faq?hsLang=en-us#pfsense)

[![logo lumiun dns](https://help.lumiun.com/hubfs/lumiun-dns.svg "logo lumiun dns")](https://help2.lumiun.com/?hsLang=en-us)

<https://www.linkedin.com/company/lumiuntecnologia> <https://www.instagram.com/lumiuntecnologia> <https://www.facebook.com/LumiunTecnologia>

Copyright © 2026, Lumiun