Set Up a Device
Mint a resolve-only credential, install it on the machine, and confirm the answers now come from your account.
On this page (6)
Set Up a Device Documentation
One device, start to finish. Do this once per machine; the credential is per device, so a phone and a laptop get one each.
1. Mint the credential
whisper device add --label "work-laptop"
The response carries the device's routable address, its encrypted DNS URL, the Apple one-tap profile URL, the Android Private DNS host, and the token itself. The token is shown once, so capture it before you move on, and treat any URL that contains it as a password: it lets the holder resolve names as this device, and it can touch nothing else on your account. The Devices page in the console mints the same credential and shows a QR code for the phone flow.
2. Install it on the device
On Apple platforms the credential arrives as a signed, DNS-only configuration profile named Whisper Encrypted DNS. On Android it is a Private DNS hostname, so there is nothing to install.
Settings > Network & internet > Private DNS
choose: Private DNS provider hostname
enter: <your-selector>.dot.whisper.onlineThe Apple profile needs iOS 14 or later, or macOS 11 or later, and it asks for the one approval the operating system requires before a DNS profile takes effect.
On Windows and Linux a script does the work. The Windows one needs an elevated PowerShell.
The Linux one installs a small local forwarder on loopback and points the system resolver at
it, writing a drop-in at /etc/systemd/resolved.conf.d/whisper-dns.conf and leaving a copy
of the previous configuration at /etc/resolv.conf.whisper-backup.
curl -fsSL https://resolver.whisper.online/linux/<your-token>.sh | sudo bash3. Confirm the device is behind Whisper
Open the device's own history page. It lists each lookup with the time, the name, the type, the decision and the reason for it, which is the quickest confirmation that answers are now coming from your account:
https://resolver.whisper.online/logs/<your-token>
Add .json to the same path for a machine-readable copy.
4. Confirm the identity is published
The device has a routable address of its own, and anyone can check it with stock tools and no key:
dig -x 2a04:2a01:b69a:6717:e3b0:51ff:3bf7:f478 +short
curl -s https://rdap.whisper.online/ip/2a04:2a01:b69a:6717:e3b0:51ff:3bf7:f478 | jq '.handle, .name'
5. Take the device back off
Releasing the identity withdraws its forward and reverse records and de-provisions its encrypted DNS, so the credential stops resolving:
whisper kill --revoke <the device address>
Releasing it also locks that device's lookup history, after which every read of it is refused, including yours. Export anything you still need from the history page first.
Then put the machine's own settings back. On Apple platforms remove the profile. On Android set Private DNS back to automatic or off. On Windows:
Get-NetAdapter | Reset-DnsClientServerAddress
Get-DnsClientDohServerAddress | Remove-DnsClientDohServerAddress
On Linux, remove the drop-in the script wrote and restore the configuration from the backup it left beside it.
What the device may resolve
Names are decided by the account, not by the device, so one change covers every machine you have installed. That is Resolver Policy, and what happens to a name before your own lists are consulted is How Resolution Works.