4 ms·
Cloudflare returns a proper response for me. nslookup archive.is 1.1.1.1 Server: 1.1.1.1 Address: 1.1.1.1#53 Non-authoritative answer: Name: archiv
by regnerba 7y ago
Cloudflare returns a proper response for me.
nslookup archive.is 1.1.1.1
Server: 1.1.1.1
Address: 1.1.1.1#53
Non-authoritative answer:
Name: archive.is
Address: 134.119.220.26
- akerro 7y agodig @1.1.1.1 archive.is ; <<>> DiG 9.14.1 <<>> @1.1.1.1 archive.is ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 46862 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 1452 ;; QUESTION SECTION: ;archive.is. IN A ;; ANSWER SECTION: archive.is. 2998 IN A 127.0.0.4 ;; Query time: 52 msec ;; SERVER: 1.1.1.1#53(1.1.1.1) ;; WHEN: Sat May 04 21:03:36 CEST 2019 ;; MSG SIZE rcvd: 55 dig @8.8.8.8 archive.is ; <<>> DiG 9.14.1 <<>> @8.8.8.8 archive.is ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 5893 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 512 ;; QUESTION SECTION: ;archive.is. IN A ;; ANSWER SECTION: archive.is. 299 IN A 94.16.117.236 ;; Query time: 79 msec ;; SERVER: 8.8.8.8#53(8.8.8.8) ;; WHEN: Sat May 04 21:04:28 CEST 2019 ;; MSG SIZE rcvd: 55
- 1f60c 7y agoNot for me: Server: 1.1.1.1 Address: 1.1.1.1#53 Non-authoritative answer: Name: archive.is Address: 127.0.0.4
- V99 7y agoIt's possible your ISP is intercepting all traffic for port 53 and sending it to their own nameservers (which do send client subset) instead of you actually taking to cloudflare's 1.1.1.1 at all.
- abtinf 7y agoLinks for documented instances of this practice?
- V99 7y agoI don't know of any particular popular concrete instance, but why is it hard to believe? It's trivial to implement and would be brought to you by the same people who think serving ads for NXDOMAIN is a good idea. https://www.dnsleaktest.com/what-is-transparent-dns-proxy.html https://www.dnsleaktest.com/what-is-transparent-dns-proxy.ht...
- abtinf 7y agoThat link was useful, thank you. I don't find it hard to believe technically, but it strikes me as a fundamentally different practice than what I'd head of before. If I request for traffic to go to a certain IP, I expect it to be sent to that IP. MITMing and manipulating that traffic is bad, but not delivering it at all is qualitatively different. I suspect it could be grounds for a serious civil or criminal action.
- LogicX 7y agoI can confirm we run across transparent dns proxying with customers at DNSFilter all the time. Mobile carriers are the worst for doing this. A few days ago it was a customers compromised router doing it.
- AndyMcConachie 7y agohttps://labs.ripe.net/Members/babak_farrokhi/operator-level-dns-redirection https://labs.ripe.net/Members/babak_farrokhi/operator-level-...
- andreareina 7y agoISPs in several countries I've been to do this to blacklist "objectionable" sites (which apparently includes reddit now) at the DNS level. Turning on DNS-over-HTTPS solves that.
- logixlemon 7y agoIf you don't mind could you look through: https://ooni.torproject.org/about/risks/ https://ooni.torproject.org/about/risks/ And if they sound acceptable run https://ooni.torproject.org/install/ https://ooni.torproject.org/install/ It'll show you more about likely interception of your traffic.