DNS Settings (com.apple.dnsSettings.managed)

Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
com.apple.dnsSettings.managed

The payload that configures encrypted DNS settings.

iOS(14.0 - 27.0)macOS(11.0 - 27.0)visionOS(1.0 - 27.0)
Branch: release

Settings (25)

SettingTypeRequiredDefaultManual InstallSupported OS
DNS settings
DNSSettings
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
A dictionary that defines a configuration for an encrypted DNS server.
7 subkeys
dictionaryrequired—
✓Yes
iOS (14.0 - 27.0)macOS (11.0 - 27.0)visionOS (1.0 - 27.0)
└─
DNS protocol
DNSProtocol
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
The encrypted transport protocol used to communicate with the DNS server.
stringrequired—
✓Yes
iOS (14.0 - 27.0)macOS (11.0 - 27.0)visionOS (1.0 - 27.0)
└─
Server URL
ServerURL
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
The URI template of a DNS-over-HTTPS server, as defined in RFC 8484. This URL needs to use the `https://` scheme, and the system uses the hostname or address in the URL to validate the server certificate. If no `ServerAddresses` are provided, the system uses the hostname or address in the URL to determine the server addresses. Required if `DNSProtocol` is `HTTPS`.
stringoptional—
✓Yes
iOS (14.0 - 27.0)macOS (11.0 - 27.0)visionOS (1.0 - 27.0)
└─
Server name
ServerName
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
The hostname of a DNS-over-TLS server used to validate the server certificate, as defined in RFC 7858. If no `ServerAddresses` are provided, the system uses the hostname to determine the server addresses. This key must be present only if the DNSProtocol is `TLS`.
stringoptional—
✓Yes
iOS (14.0 - 27.0)macOS (11.0 - 27.0)visionOS (1.0 - 27.0)
└─
DNS server addresses
ServerAddresses
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
An unordered list of DNS server IP address strings. These IP addresses can be a mixture of IPv4 and IPv6 addresses.
1 subkey
arrayoptional—
✓Yes
iOS (14.0 - 27.0)macOS (11.0 - 27.0)visionOS (1.0 - 27.0)
└─ └─
Server address element
ServerAddressesElement
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
string—
✓Yes
iOS (14.0 - 27.0)macOS (11.0 - 27.0)visionOS (1.0 - 27.0)
└─
Allow failover
AllowFailover
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
If `true`, the device allows failover to the default system DNS resolver.
booleanoptionalfalse
✓Yes
iOS (26.0 - 27.0)macOS (26.0 - 27.0)visionOS (26.0 - 27.0)
└─
Certificate UUID
PayloadCertificateUUID
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
The UUID that points to an identity certificate payload. The system uses this identity to authenticate the user to the DNS resolver.
stringoptional—
✓Yes
iOS (16.0 - 27.0)macOS (13.0 - 27.0)
└─
Supplemental match domains
SupplementalMatchDomains
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
A list of domain strings used to determine which DNS queries use the DNS server. If not set, all domains use the DNS server. The system supports a single wildcard (`\*`) prefix, but it's not required. For example, both `\*.example.com` and `example.com` match against `mydomain.example.com` and `your.domain.example.com`, but don't match against `mydomain-example.com`.
1 subkey
arrayoptional—
✓Yes
iOS (14.0 - 27.0)macOS (11.0 - 27.0)visionOS (1.0 - 27.0)
└─ └─
Supplemental match domains element
SupplementalMatchDomainsElement
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
string—
✓Yes
iOS (14.0 - 27.0)macOS (11.0 - 27.0)visionOS (1.0 - 27.0)
On demand rules
OnDemandRules
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
An array of rules that define the DNS settings. If not set, the system always applies the DNS settings. These rules are identical to the `OnDemandRules` array in VPN payloads.
1 subkey
arrayoptional—
✓Yes
iOS (14.0 - 27.0)macOS (11.0 - 27.0)visionOS (1.0 - 27.0)
└─
On demand rules element
OnDemandRulesElement
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
7 subkeys
dictionary—
✓Yes
iOS (14.0 - 27.0)macOS (11.0 - 27.0)visionOS (1.0 - 27.0)
└─ └─
On demand action
Action
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
The action to take if this dictionary matches the current network. Allowed values: - `Connect`: Apply DNS Settings when the dictionary matches. - `Disconnect`: Don't apply DNS Settings when the dictionary matches. - `EvaluateConnection`: Apply DNS Settings with per-domain exceptions when the dictionary matches.
stringrequired—
✓Yes
iOS (14.0 - 27.0)macOS (11.0 - 27.0)visionOS (1.0 - 27.0)
└─ └─
Action parameters
ActionParameters
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
An array of dictionaries that provide per-connection rules. The system uses this array only for settings where the `Action` value is `EvaluateConnection`.
1 subkey
arrayoptional—
✓Yes
iOS (14.0 - 27.0)macOS (11.0 - 27.0)visionOS (1.0 - 27.0)
└─ └─ └─
Action parameter
ActionParameter
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
A dictionary that provides per-connection rules. The keys allowed in each dictionary are described below. Note: This array is only for dictionaries in which `EvaluateConnection` is the `Action` value.
2 subkeys
dictionaryoptional—
✓Yes
iOS (14.0 - 27.0)macOS (11.0 - 27.0)visionOS (1.0 - 27.0)
└─ └─ └─ └─
[Structure continues recursively]
↻
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
This structure continues with 2 subkeys (deeply nested - 2 subkeys). See Apple's documentation for the complete structure.
—
✓Yes
iOS (14.0 - 27.0)macOS (11.0 - 27.0)visionOS (1.0 - 27.0)
└─ └─
DNS domain match
DNSDomainMatch
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
An array of domain names. This rule matches if any of the domain names in the specified list matches any domain in the device's search domains list. The system supports a single wildcard (`\*`) prefix, but it's not required. For example, both `\*.example.com` and `example.com` match against `mydomain.example.com` and `your.domain.example.com`, but don't match against `mydomain-example.com`.
1 subkey
arrayoptional—
✓Yes
iOS (14.0 - 27.0)macOS (11.0 - 27.0)visionOS (1.0 - 27.0)
└─ └─ └─
DNS domain match element
DNSDomainMatchElement
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
string—
✓Yes
iOS (14.0 - 27.0)macOS (11.0 - 27.0)visionOS (1.0 - 27.0)
└─ └─
DNS server address match
DNSServerAddressMatch
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
An array of IP addresses. This rule matches if any of the network's specified DNS servers match any entry in the array. The system supports matching with a single wildcard. For example, `17.\*` matches any DNS server in the 17.0.0.0/8 subnet.
1 subkey
arrayoptional—
✓Yes
iOS (14.0 - 27.0)macOS (11.0 - 27.0)visionOS (1.0 - 27.0)
└─ └─ └─
DNS server address match element
DNSServerAddressMatchElement
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
string—
✓Yes
iOS (14.0 - 27.0)macOS (11.0 - 27.0)visionOS (1.0 - 27.0)
└─ └─
Interface type match
InterfaceTypeMatch
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
An interface type. If specified, this rule matches only if the primary network interface hardware matches the specified type.
stringoptional—
✓Yes
iOS (14.0 - 27.0)macOS (11.0 - 27.0)visionOS (1.0 - 27.0)
└─ └─
SSID match
SSIDMatch
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
An array of SSIDs to match against the current network. If the network isn't a Wi-Fi network or if the SSID doesn't appear in this array, the match fails. Omit this key and the corresponding array to match against any SSID.
1 subkey
arrayoptional—
✓Yes
iOS (14.0 - 27.0)macOS (11.0 - 27.0)visionOS (1.0 - 27.0)
└─ └─ └─
SSID match element
SSIDMatchElement
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
string—
✓Yes
iOS (14.0 - 27.0)macOS (11.0 - 27.0)visionOS (1.0 - 27.0)
└─ └─
URL string probe
URLStringProbe
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
A URL to probe. This rule matches if this URL is successfully fetched and returns a 200 HTTP status code without redirection.
stringoptional—
✓Yes
iOS (14.0 - 27.0)macOS (11.0 - 27.0)visionOS (1.0 - 27.0)
Prohibit disablement
ProhibitDisablement
Deprecated (iOS 27.0, macOS 27.0, visionOS 27.0)
If `true`, the system prohibits users from disabling DNS settings. This key is only available on supervised devices.
booleanoptionalfalse
✗No

Apple MDM & DDM Policy Explorer

Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.

Reference: policy categories & common keys

Policy categories

  • Configuration Profile
  • Declarative Configuration
  • Declarative Activation
  • Declarative Asset
  • Declarative Management

Common policy keys

  • com.apple.wifi.managed – Wi-Fi network configuration
  • com.apple.vpn.managed – VPN configuration
  • com.apple.applicationaccess – App and feature restrictions
  • com.apple.security.pkcs1 – Certificate (PKCS#1) payload
  • com.apple.security.pkcs12 – Identity certificate (PKCS#12) payload
  • com.apple.security.scep – SCEP certificate enrolment
  • com.apple.mail.managed – Mail account configuration
  • com.apple.eas.account – Exchange ActiveSync account
  • com.apple.MCX – Managed Client (macOS) preferences
  • com.apple.MCX.FileVault2 – FileVault 2 disk encryption
  • com.apple.dock – macOS Dock configuration
  • com.apple.screensaver – Screensaver configuration
  • com.apple.loginwindow – macOS login window configuration
  • com.apple.systempolicy.managed – Gatekeeper / system policy
  • com.apple.systempreferences – System Preferences pane restrictions
  • com.apple.SoftwareUpdate – Software update behaviour
  • com.apple.TCC.configuration-profile-policy – Privacy Preferences Policy Control (PPPC)
  • com.apple.notificationsettings – Per-app notification settings
  • com.apple.webcontent-filter – Web content filter
  • com.apple.dnsSettings.managed – DNS settings (DoH / DoT)
  • com.apple.relay.managed – Network relay configuration
  • com.apple.extensiblesso – Extensible Single Sign-On
  • com.apple.configuration.passcode.settings – DDM: passcode policy
  • com.apple.configuration.softwareupdate.enforcement.specific – DDM: enforced software update
  • com.apple.configuration.services.configuration-files – DDM: service configuration files
  • com.apple.configuration.management.status-subscriptions – DDM: status subscriptions
  • com.apple.activation.simple – DDM: simple activation predicate
  • com.apple.management.organization-info – DDM: organization information