๐Ÿ”’ iOS Configuration Profiles

DNS-based protection profiles for certificate security and ad-blocking

โš ๏ธ

IMPORTANT: Keep OCSP Profile Active

Never remove the "NextDNS Anti-Revoke" profile! This protects your certificates from revocation. All other profiles can be safely added or removed.

๐ŸŽฏ ONE Profile Does It All

๐Ÿ›ก๏ธ NextDNS Switchable (3 AdBlock Levels)

Certificate protection + toggle-able adblock (100+ domains). Switch levels in Settings!

REQUIRED
Level 1: OCSP Only (21 domains) - No adblock
Level 2: + Adult AdBlock (61 domains)
Level 3: + Full AdBlock (121 domains) โญ STRONGEST
Toggle: โœ… Switch in Settings > DNS (no reinstall!)
VPN: โœ… Works with WireGuard
Shopping: โœ… Safe for Cashkaro (all levels)
Install Switchable Profile
๐Ÿ”„

How to Toggle AdBlock Levels

After installing the profile:

  1. Open Settings app
  2. Go to General โ†’ VPN & Device Management โ†’ DNS
  3. Tap the current config name
  4. Select your preferred level:
    • OCSP Only - No adblock (see all ads)
    • OCSP + Adult AdBlock - Blocks adult ads only
    • OCSP + Full AdBlock - Blocks ALL ads/trackers โญ
  5. Done! Takes 3 seconds to switch!

โœจ No reinstall needed! Switch anytime between the 3 levels.

๐Ÿ’ก How the Switchable Profile Works

This single profile contains 3 different DNS configs that you can toggle between in iOS Settings.

Level 1: OCSP Only (21 domains)
OR
Level 2: + Adult Ads (61 domains)
OR
Level 3: + All Ads/Trackers (121 domains) โญ

Key fact: iOS can only use ONE DNS profile at a time. That's why this profile has all 3 levels built-in - you switch between them instead of installing separate profiles!

Profile Management

โœ… To Activate/Deactivate

  1. View: Settings โ†’ General โ†’ VPN & Device Management
  2. Remove: Tap profile โ†’ Remove Profile
  3. Reinstall: Safari โ†’ Profile URL โ†’ Install

Takes 30 seconds to switch!

๐Ÿ›’ For Cashkaro Shopping

Keep installed:

  • โœ… OCSP Blocking
  • โœ… Adult Ad-Blocker

DO NOT install:

  • โŒ Maximum Privacy profiles

๐Ÿงช Testing Your Profiles

1
Test OCSP Blocking:

With VPN ON, visit http://ocsp.apple.com

Expected: โŒ Fails to load

2
Test Adult Ads:

Visit sxyprn.com or similar site

Expected: โœ… Site loads, no ads

3
Test VPN:

Visit https://whatismyip.com

Expected: Shows VPS IP

Note: All profiles are VPN-compatible and use DNS-over-HTTPS (DoH) for privacy. They work alongside your WireGuard VPN without conflicts.