Manually configure Sophos DNS Protection on macOS
There are two ways to use Sophos DNS Protection manually on a Mac: Traditional DNS adds the two resolver IP addresses to a macOS network service, while Secure DNS installs a configuration profile containing the tenant- and location-specific DNS-over-HTTPS URL. Both approaches are suitable for individual test devices; for a managed fleet, deploy the configuration through an MDM solution.
An important product limitation applies: the Sophos Fusion (formerly Sophos Central) DNS Protection Endpoint Policy does not currently support macOS. A manually installed DoH profile also does not turn the Mac into an endpoint managed by that policy. It only configures the macOS DNS settings.
Using a firewall as the central resolver is a different deployment model. It is described in Configure Sophos DNS Protection with Sophos Firewall.
Choose Traditional DNS or Secure DNS
Secure DNS (DoH) is usually the better choice for a directly configured Mac: DNS requests are encrypted over HTTPS, and the Secure DNS location is identified by its unique URL. The profile applies system-wide and remains effective when switching between Wi-Fi networks. Before deploying it, however, determine how it will interact with VPN clients, internal domains, captive portals, and other DNS or filtering profiles.
Traditional DNS over IPv4 is simpler and is suitable for a limited test or a network whose public egress IP is registered in a Traditional DNS location. The location is identified by this public source IP. The setting applies per macOS network service, so services such as Ethernet and any other active services must be checked separately in addition to Wi-Fi. Outside a registered egress IP, requests cannot be reliably associated with the location.
Do not configure both methods at the same time as a supposed fallback. A DoH profile can override manually entered resolvers, and multiple DNS or VPN profiles can also conflict. Choose and document exactly one method for the pilot.
Prepare before making changes
You need:
- Access to My Products > DNS Protection in Sophos Fusion.
- An appropriate location with an assigned Filtering Policy.
- For Traditional DNS: Traditional DNS over IPv4 enabled, the registered public IPv4 address or FQDN, and the two IP addresses under Installers.
- For Secure DNS: a location with Secure DNS enabled and its generated DNS over HTTPS URL.
- Local administrator privileges to install the profile.
- A record of the existing DNS settings and a tested rollback procedure.
Before making changes, note the active network services under System Settings > Network. Back up any statically configured DNS server values. If the servers are supplied automatically through DHCP, document Automatic/DHCP as the initial state. Also choose at least one internal and one public test domain. Do not publish real DoH URLs in tickets or script repositories because they associate requests with the location.
Option A: Configure Traditional DNS
- In Sophos Fusion, open My Products > DNS Protection > Installers and click Copy next to IP addresses. This copies both resolver IP addresses. Use only values from your own tenant.
- On the Mac, open System Settings > Network.
- Select the active service, such as Wi-Fi, then open Details > DNS.
- Under DNS Servers, use + to add both Sophos addresses and remove any previously configured third-party resolvers. A third-party resolver is not merely a backup and could bypass filtering and reporting.
- Confirm with OK.
- Repeat the process for every other network service that is actually used.
The names and arrangement of individual buttons can vary slightly between macOS versions. What matters is that you change the DNS servers for the selected network service—not in a browser or only in a single application.
Then briefly disconnect and reconnect Wi-Fi, or reconnect the affected service. Do not switch every Mac at once: first test one pilot device on each relevant network type.
Option B: Configure Secure DNS with a profile
1. Copy the DoH URL
When creating or editing the Secure DNS location in Sophos Fusion, copy the generated DNS over HTTPS URL. Use the complete URL; do not construct the hostname or path yourself.
2. Generate the profile
On the Mac, create a file named sophos-dns.sh in Terminal and paste in this script:
#!/bin/bash
set -eu
DOH_URL=${1:?Usage: $0 <doh_url>}
case "$DOH_URL" in
https://*) ;;
*) echo "The DoH URL must start with https://" >&2; exit 1 ;;
esac
OUTPUT="dns-config.mobileconfig"
UUID1=$(uuidgen)
UUID2=$(uuidgen)
cat > "$OUTPUT" <<EOF
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>PayloadContent</key>
<array>
<dict>
<key>PayloadDescription</key>
<string>Configures DNS settings</string>
<key>PayloadDisplayName</key>
<string>DNS Settings</string>
<key>PayloadIdentifier</key>
<string>com.apple.dnsSettings.managed.custom</string>
<key>PayloadType</key>
<string>com.apple.dnsSettings.managed</string>
<key>PayloadUUID</key>
<string>$UUID1</string>
<key>PayloadVersion</key>
<integer>1</integer>
<key>DNSSettings</key>
<dict>
<key>DNSProtocol</key>
<string>HTTPS</string>
<key>ServerURL</key>
<string>$DOH_URL</string>
</dict>
</dict>
</array>
<key>PayloadDescription</key>
<string>DNS Protection DoH</string>
<key>PayloadDisplayName</key>
<string>DNS-Global DNS over HTTPS</string>
<key>PayloadIdentifier</key>
<string>com.example.dns.profile</string>
<key>PayloadRemovalDisallowed</key>
<false/>
<key>PayloadType</key>
<string>Configuration</string>
<key>PayloadUUID</key>
<string>$UUID2</string>
<key>PayloadVersion</key>
<integer>1</integer>
<key>PayloadScope</key>
<string>System</string>
</dict>
</plist>
EOF
plutil -lint "$OUTPUT"
open "$OUTPUT"
The script changes local state: it overwrites any existing dns-config.mobileconfig file in the current directory and then opens the installation dialog. Replace the placeholder with the Sophos URL; quotation marks protect special characters:
chmod +x sophos-dns.sh
./sophos-dns.sh 'https://<tenant-specific-doh-url>/dns-query'
Proceed only if plutil reports OK for dns-config.mobileconfig. The example domain in PayloadIdentifier is only a stable technical identifier, not a destination for DNS requests.
3. Review and install the profile
- After the file opens, acknowledge the notification with OK. Then open Device Management.
- Double-click DNS-Global DNS over HTTPS.
- Review the contents:
DNS Settings, theHTTPSprotocol, and the expected tenant-specific server URL must be displayed. - Select Install, accept the second confirmation, and authenticate with a local administrator account when prompted.
- In Device Management, confirm that the profile is now shown as installed.
A profile installed from a file is manual, even though macOS describes its payload as managed. Sophos Fusion does not deploy, inventory, or remove it. For multiple Macs, an administrator should deploy the same DNS Settings payload through the approved MDM solution rather than having users run scripts individually. Validate MDM-specific fields and conflict rules in the relevant MDM solution.
Verify functionality
First, check the active resolver state and normal name resolution:
scutil --dns
dig example.com
scutil --dns can show multiple resolvers for VPNs, search domains, and system-wide services. Do not look for only a single IP address; determine which resolver is responsible for the test domain. dig confirms that a response is returned, but by itself it proves neither that the Sophos policy was applied nor which transport was used.
Acceptance testing must therefore cover every layer:
- Run the configuration test under DNS Protection > Installers.
- Resolve a normal public domain.
- Use a harmless domain that is deliberately blocked for the pilot by the assigned Filtering Policy.
- In the DNS Protection reports, confirm that the request, location, and decision appear. Allow for a short reporting delay.
- Test internal names, the VPN, a guest network or captive portal, and at least one switch to another network.
After configuring Traditional DNS, also verify that the current public egress IP belongs to the location. After configuring Secure DNS, confirm that another DNS, VPN, or filtering profile is not taking control of the resolver.
Handle the block page and certificate separately
Successful DNS blocking does not mean that an HTTPS block page will appear without a certificate warning. For that, install the DNS Protection Root Certificate from DNS Protection > Installers on the Mac through a controlled trust process. This is not the Sophos Firewall certificate used for TLS Inspection.
Assign this certificate task its own owner and pilot validation. On managed Macs, deploy the certificate through MDM. On an individual test Mac, verify its origin and fingerprint before trusting it. If only name resolution is being tested, a certificate warning on an HTTPS block page is not evidence that DNS Protection has failed.
Rollback and removal
Revert Traditional DNS
Under System Settings > Network >
Remove the Secure DNS profile
- Open Device Management.
- Select DNS-Global DNS over HTTPS and choose the option to remove the profile.
- Authenticate the removal and confirm that the profile is no longer listed.
- Reconnect to the network and use
scutil --dnsanddig example.comto verify that the previous resolver is active again.
The generated profile permits removal (PayloadRemovalDisallowed is false). If the removal option is missing or removal is denied, the device or profile may be managed by an organization. Do not attempt to work around that management locally; the responsible MDM administrator must remove the assignment. The sophos-dns.sh and dns-config.mobileconfig files can be safely deleted after a documented, successful installation, but deleting them does not remove a profile that is already installed.
Troubleshoot by symptom
The internet stops working after the change
Roll back first. Then distinguish the network connection, captive portal, and connectivity by IP address from DNS behavior. For Traditional DNS, verify that both resolvers were entered correctly and that the firewall or ISP allows DNS over UDP/TCP port 53. For Secure DNS, the tenant-specific DoH URL must be reachable over HTTPS.
Public domains work, but internal names do not
With a system-wide DoH profile, the Mac generally sends DNS requests to the configured service. DNS Protection does not automatically know about internal zones. Plan split DNS over VPN or internal resolvers before rollout and test it with the VPN and MDM profiles actually in use. Public allowlisting is not a substitute for an authoritative internal DNS server.
The configuration test does not detect DNS Protection
For Traditional DNS, compare the current public source IP with the location, especially after a network, multi-WAN, or ISP change. For Secure DNS, verify the complete URL in the installed profile and look for competing DNS or VPN profiles. Then reconnect and test again.
The profile cannot be installed
First run plutil -lint dns-config.mobileconfig. Then check Device Management for an already downloaded or installed profile with the same identifier and for organizational restrictions. Do not layer multiple slightly different profiles on top of one another; remove the old profile in a controlled manner or replace it through MDM.
A blocked HTTPS page displays a certificate warning
Check the DNS policy and root certificate trust separately. If the block appears in the report, the DNS decision is probably already working. The responsible certificate owner should then check certificate deployment, the trust chain, and block-page reachability instead of relaxing the Filtering Policy prematurely.