STIGQter STIGQter: STIG Summary: Mozilla Firefox Security Technical Implementation Guide Version: 6 Release: 8 Benchmark Date: 01 Jul 2026:

Firefox must be configured so that DNS over HTTPS is disabled.

DISA Rule

SV-251577r960963_rule

Vulnerability Number

V-251577

Group Title

SRG-APP-000141

Rule Version

FFOX-00-000033

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Windows group policy:
1. Open the group policy editor tool with "gpedit.msc".
2. Navigate to Policy Path: Computer Configuration\Administrative Templates\Mozilla\Firefox\DNS Over HTTPS
Policy Name: Enabled
Policy State: Disabled

macOS "plist" file:
<key>DNSOverHTTPS</key>
<dict>
<key>Enabled</key>
<false/>

Linux "policies.json" file:
Add the following in the policies section:
"DNSOverHTTPS": {"Enabled": false}

Check Contents

Type "about:policies" in the browser address bar.

If "DNSOverHTTPS" is not displayed under Policy Name or the Policy Value does not have "Enabled" with a value of "false", this is a finding.

Vulnerability Number

V-251577

Documentable

False

Rule Version

FFOX-00-000033

Severity Override Guidance

Type "about:policies" in the browser address bar.

If "DNSOverHTTPS" is not displayed under Policy Name or the Policy Value does not have "Enabled" with a value of "false", this is a finding.

Check Content Reference

M

Target Key

5446