# GraceDNS Documentation

GraceDNS is a protective DNS service. You point your devices or your network at our resolvers, and lookups for known-malicious, unwanted or inappropriate domains stop resolving before a connection is ever made. Everything runs on servers in Germany, and what gets blocked, how blocks look, and what gets logged is decided by you, per configuration.

A **configuration** is the unit everything hangs on: it holds your rules, your protection toggles, your logging mode, and its own id (`configid`). Devices connect using that id, so one account can run separate configurations for the office, the kids' tablets and the guest Wi-Fi.

## Getting connected

**Start here:** [How to connect](connect.md) explains the three ways in and which one fits your situation. Configurations work with or without an account; [Accounts](account.md) explains what signing in adds and how claiming an anonymous configuration works.

Per-platform guides: [Router](setup/router.md), [Android](setup/android.md), [iOS and macOS](setup/ios.md), [Browser (DNS over HTTPS)](setup/browser-doh.md).

## Features

**Overview:** [What GraceDNS protects against](features/index.md), with one page per protection:

[Threat protection](features/threat-protection.md) (malware, phishing, botnets), [Rebind protection](features/rebind-protection.md), [Custom rules](features/custom-rules.md) (your own allow and deny lists), [Network rules](features/network-rules.md) (client and answer IP ranges), [Block types](features/block-types.md) (how a block looks to the user), [Query logs](features/query-logs.md) (none, blocked only, or all; stored in the EU).

## Honesty pages

[What DNS filtering cannot do](limitations.md) covers the structural limits of the approach. [About us](about-us.md) says who builds and runs GraceDNS.

Legal and compliance information lives at [/legal/](../legal/index.md). Questions: support@gracedns.eu.
