Private DNS (DNS-over-TLS) not configurable via Esper; Static IP DNS is supported
Android
Improved Title: Static IP DNS works in Esper — Private DNS (DNS-over-TLS) is not managedWhen configuring network settings for a managed Android device fleet, Esper supports DNS server assignment through Static IP network profiles but does not manage Android's Private DNS (DNS-over-TLS) feature. Attempting to enforce Private DNS centrally through the Esper Console, Blueprints, or API will have no effect.
Why this happens
Android exposes Private DNS (DNS-over-TLS) as a system-level setting that is separate from standard network interface configuration. Esper's network management layer controls IP-level parameters — including DNS server addresses — only when a network profile uses Static IP assignment. The Android Private DNS setting lives outside that scope and has no corresponding managed configuration key available to Esper.
Configure DNS servers using a Static IP Blueprint
- Open the Esper Console and navigate to Blueprints.
- Open an existing blueprint or create a new one by selecting Create Blueprint.
- Navigate to the Network section of the blueprint and open or add a Wi-Fi network profile.
- Set the IP assignment to Static. This unlocks the DNS server fields — they are not available when DHCP is selected.
- Enter your DNS server addresses in the DNS Server 1 and DNS Server 2 fields.
- Save the blueprint and select Publish.
- Apply the blueprint to your target device or group via Devices & Groups by selecting the group and choosing the updated blueprint.
Private DNS (DNS-over-TLS) — what you can do instead
Because Esper does not manage the Android Private DNS setting, enforcing DNS-over-TLS centrally is not possible through the Esper Console. Two alternatives are worth considering:
- Check OEM MDM keys: Some manufacturers expose a proprietary managed configuration key for DNS-over-TLS. Review your device OEM's EMM or Android Management API documentation to determine whether a custom key can be delivered through Apps & Configuration → Managed Configurations in Esper.
- Submit a feature request: Contact Esper Support with your use case, the device models and Android versions in your fleet, and the DNS-over-TLS provider you need to enforce. This helps prioritize future platform support.
If this doesn't resolve it
If Static IP DNS values are configured in a blueprint but are not appearing on the device after sync, collect the following before contacting support:
- The blueprint name and the specific Wi-Fi network profile settings (screenshot or export)
- The device serial number or Esper device ID
- The current network settings visible on the device (screenshot of Modify network)
- The timestamp of the last blueprint application, visible in the device's Activity Feed
Submit a support request at support.esper.io with this information included.
Still need help?
If you need to configure Private DNS (DNS-over-TLS) or have questions about static IP DNS configuration on your devices, please submit a support ticket and include your device model, current DNS setup, and desired configuration details.
Please sign in to leave a comment.
Comments
0 comments