Google has shed more light on how Android's app verification rules will work, which will block sideloading apps from unverified developers.
You may have noticed a setting on Android called Private DNS. It's on by default, and you're best off leaving it that way.