---
title: "Adding DoH Feeds to a Security Policy"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35436047/Adding%20DoH%20Feeds%20to%20a%20Security%20Policy"
format: markdown
---
To add **DoH Policy for known DoH domains **and/or **DoH Policy for known DoH IPs** to your security policy, see [*Adding Policy Rules and Setting Precedence*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35403288). <span style="color: #0d0d0d">You can find the updated DoH policy feeds in the </span>*<span style="color: #0d0d0d">Feeds and Threat Insight</span>*<span style="color: #0d0d0d"> panel.</span> Infoblox recommends setting rule actions for both DoH domains policy feeds to "**BLOCK – No Redirect**." For information on configuring your security policy, see[ ](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35371559)*[Configuring Security Policies](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35371559)*.

Infoblox offers the following DoH RPZ feeds.  

| **Feed Name** | **Level ** | **Confidence** | **Description** |
| --- | --- | --- | --- |
| DOH Public Hostnames | **Low** - Exposure to this threat may cause low or no damage to your network. | **High** - This feed has a low probability of resulting in false positives. | The Public DOH feed provides a list of known public DNS services that tunnel their traffic over HTTP. This may be from a browser (such as Mozilla Firefox), a piece of malware, or a user attempting to bypass your organization's DNS policies. This feed contains “canary” domains. We recommend all organizations enable this blocking rule. |
| DoH Public IPs | Low - Exposure to this threat may cause low or no damage to your network. | High - This feed has a low probability of resulting in false positives. | The Public DOH IP feed provides a list of known public DNS services that tunnel their traffic over HTTP. This may be from a browser (such as Mozilla Firefox), a piece of malware, or a user attempting to bypass your organization's DNS policies. This feed contains “canary” addresses. We recommend all organizations enable this blocking rule. |

.

.For information on how to add the DoH feeds to On-Prem DNS Firewall Service, see *[Configuring On-Prem DNS Firewall Service](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35468259)*.