Fix it yourself, in minutes.

The most common Koru Shield issues and exactly how to resolve them. Last updated September 30, 2026.

Quick checks first. Before anything else, open the Koru Shield portal at my.korushield.com and look at the protection status card on Overview. If it says your devices are protected, the problem is probably with one site or app, not your setup. Then check Activity > Query logs for the device. If you see recent entries, your device is talking to Koru Shield and protection is active.

DNS over HTTPS is not resolving

Sites will not load, or protection seems off even though everything looks configured.

  1. Make sure you are using the correct resolver address from Setup in the portal. Do not guess the address; copy it from the setup page for your device.
  2. On the device, confirm the DNS setting is set to DNS over HTTPS (DoH), not plain DNS. The setup guides for each platform show exactly where this toggle lives.
  3. If you are on a VPN, a work network, or hotel/cafe Wi-Fi, that network may be forcing its own DNS. Disconnect the VPN or try a different network to test.
  4. Some ISP routers intercept DNS. If you set DoH on the device itself (not the router), the router cannot override it.
  5. Still nothing? Run the verification challenge from Setup > Verify this device in the portal and email us the result.

iOS / iPadOS profile install issues

The configuration profile will not download or will not install.

  1. Download the profile from Setup in the portal (the .mobileconfig file for your device).
  2. After downloading, open Settings > General > VPN & Device Management. The profile appears under "Downloaded Profile". Tap it, then tap Install and enter your device passcode.
  3. If you do not see "Downloaded Profile", the file may have been blocked by your browser. Re-download it in Safari (not Chrome or another browser) and check again.
  4. If installation fails with a trust error, delete the old profile first (Settings > General > VPN & Device Management, tap the old Koru Shield profile, Remove), then install the fresh one.
  5. iOS may show a warning that the profile will change DNS settings. That is expected; this is how the protection works.

Android profile install issues

The QR code does nothing, or Private DNS will not stick.

  1. From Setup in the portal, open the Android QR code for your device and scan it with your phone camera.
  2. On most Android versions this opens the Private DNS setting directly. Paste the hostname and choose Private DNS provider hostname (not "Off" or "Automatic").
  3. If nothing happens when you scan the code, open Settings > Network & Internet > Private DNS manually and type the hostname shown in the portal.
  4. Some Samsung and Xiaomi phones hide Private DNS under Settings > Connections > More connection settings. Use the phone search bar and type "Private DNS" to find it.
  5. Mobile carriers rarely block Private DNS, but some work-device management apps (MDM) force the company DNS. If your phone is managed by an employer, you may need their IT team to allow it.

Verification challenge failing

The portal can ask your device to look up a random hostname to prove protection is active. If the challenge keeps failing:

  1. Wait 60 seconds and try again. A change you just made can take a moment to take effect.
  2. Make sure the device you are testing is the one you configured. The challenge checks the device the portal is testing, not your other devices.
  3. If the device uses both Wi-Fi and mobile data, test on one connection at a time. A phone can answer the challenge over mobile data while you configured Wi-Fi.
  4. Copy the exact error message from the portal and send it to contact@korushield.com with your device type (for example, "iPhone 15, iOS 18").

A site is blocked but should not be

Something you need is getting stopped by a filter.

  1. In the portal go to Activity > Query logs and find the blocked request. It shows which rule or category blocked it.
  2. If you believe the block is wrong, use the Report button on that log entry. This sends us the domain and the reason, which is the fastest way to get it reviewed.
  3. You can allow the site yourself right away: Protection > Rules, add an allow rule for the domain. This takes effect within a minute.
  4. If a whole category of sites you need is blocked (for example, a work tool), check Protection > Filter categories to see if that category is enabled for your profile.

A site loads that you expected to be blocked

A filter should be catching something, but it is not.

  1. Check that the device is actually using Koru Shield (see "Quick checks first" above). A device that fell back to its normal DNS will not be filtered.
  2. In Protection, confirm the rule or category you expect is enabled on the correct profile, and that the device is assigned to that profile.
  3. Some apps use their own built-in DNS or proxy and bypass system DNS entirely. This is common with some VPN apps and browsers with "secure DNS" turned on. Disable the app's own secure-DNS setting so it uses the system resolver.

How to check whether Koru Shield is working

Four quick ways to confirm protection is active.

  1. Portal Overview shows protection status per profile.
  2. Setup > Verify this device runs a live lookup challenge against your resolver.
  3. Activity > Query logs shows every lookup and whether it was allowed or blocked in the last 24 hours.
  4. Devices shows when each device was last seen.

See Test your protection for a fuller walkthrough, including what the block page looks like and what to do if a bad site loads.

Still stuck?

Email contact@korushield.com with what you were trying to do, the device type and OS version, the exact error message or a screenshot, and the time it happened. We aim to reply within one business day. If a site is wrongly blocked and it is urgent, allow it yourself with a rule (see above) and then email us so we can fix the underlying list.