4 ms·
I found this basically only helped for laptops. Our phones and smart devices all use either DoH or hardcode a specific DNS resolver. I haven't spent the time g
by codemac 4y ago
I found this basically only helped for laptops.
Our phones and smart devices all use either DoH or hardcode a specific DNS resolver. I haven't spent the time going all the way down to re-routing all port 53 traffic, but I doubt it'll do much.
To me the future of the home network is largely dead as long as I can't reasonably manage the software on these devices.
- goodburb 4y agoHardcoded devices/software is a very good point, not sure why the text is faded/downvoted.
- Gigachad 4y agoProprietary software and hardware is malware. Stallman told us this decades ago.
- cassianoleal 4y ago> Our phones and smart devices all use either DoH or hardcode a specific DNS resolver My phone uses whatever DNS I configure it to use. When I'm at home, it uses my PiHole. If you mean individual apps going their own way, that's a different problem.
- vonseel 4y agoI'm not sure about Android, but you can disable iCloud Private Relay by returning NXDOMAIN for the domains below. These are Adguard filtering rules, but you can configure something similar using dnsmasq or Pihole. ||mask.icloud.com^$dnsrewrite=NXDOMAIN;; ||mask-h2.icloud.com^$dnsrewrite=NXDOMAIN;; ||mask-api.icloud.com^$dnsrewrite=NXDOMAIN;; ||mask-t.apple-dns.net^$dnsrewrite=NXDOMAIN;; ||mask.apple-dns.net^$dnsrewrite=NXDOMAIN;; ||mask-api.fe.apple-dns.net^$dnsrewrite=NXDOMAIN;; I use these to automatically disable iCloud private relay, and I also have rules on my edgerouter to force certain devices to use my adguard instances for port 53 traffic, and it works well.