I followed the setup, but the check still says this device is not protected
The check is honest and it is usually right: something on this device is still answering DNS questions itself. Four things do that, and they are easy to tell apart.
What is probably going on
The settings were saved on a different network adapter than the one you are actually using — a laptop typically has Wi-Fi and Ethernet, and a Windows machine usually has several more from Hyper-V, WSL, Docker or a VPN client.
- Run the Haven setup script rather than typing the numbers by hand — it applies the change to every adapter that will accept it, so there is no adapter left to pick wrongly.
- If you prefer to do it by hand, set 1.1.1.3 and 1.0.0.3 on the connection currently marked Connected.
- Disconnect and reconnect that connection, then run the check again.
Your browser is doing its own DNS. Chrome, Edge and Firefox each ship a "Secure DNS" setting that is on by default in many builds, and when it is on the browser asks its own resolver and never consults the device setting you just changed.
- Chrome or Edge: Settings → Privacy and security → Security → turn off "Use secure DNS".
- Firefox: Settings → Privacy & Security → scroll to DNS over HTTPS → choose "Off" (or set the provider to a custom URL of https://family.cloudflare-dns.com/dns-query).
- Close the browser fully and reopen it before checking again — the setting takes effect on new connections.
A VPN or a security suite is handling DNS for the whole machine. Most VPNs push their own resolver by design, and several antivirus products have a "secure DNS" or "web shield" feature that does the same thing quietly.
- If the VPN has a DNS setting, point it at 1.1.1.3 and 1.0.0.3, or at family.cloudflare-dns.com if it accepts a hostname.
- If it does not, decide which one you want on this device — a VPN and family DNS both want to be the last word, and only one can be.
- In an antivirus suite, look for "secure DNS", "DNS protection" or "web shield" and either disable that specific feature or set its resolver to the same addresses. Do not disable the antivirus.
The change was made but the device has not picked it up. DNS answers are cached, and an existing Wi-Fi session keeps using what it had.
- Turn Wi-Fi off and on again, or unplug and replug the Ethernet cable.
- Restart the device if that does not do it.
- Run the check again.
What Haven cannot fix here
Stated plainly, because a product that hides its edges is how you end up trusting a surface nobody is covering.
Next door to this
Still stuck?
Two doors, and neither of them is a queue you never hear back from.
Last checked 2026-08. Nothing on this page was written by a model — a made-up menu path is worse than no instruction at all, and this is the page somebody reads when they are already stuck.