3 ms·
> ..., DNS-over-HTTPS are blocked Not trying to be facetious, but how do you know you are blocking them all? I thought one of the reasons for using DNS-over-HT
by ralferoo 4mo ago
> ..., DNS-over-HTTPS are blocked
Not trying to be facetious, but how do you know you are blocking them all? I thought one of the reasons for using DNS-over-HTTPS was to be able to avoid detection.
- h4kunamata 3mo agoYou aer mixing two things together, and popular misundertanding: You cant never truly hide your DNS requests, your ISP can still see the traffic. There are plenty of videos showing how you can use WireShark within your network to identify packages flagged as DNS, no matter if DNS, DOT, DOH, they have identifiers making it easier to identify them by analysing the packages. You just need to know how. If your ISP really wanna know what you are accessing, they can, DOH isn't VPN. 1. Icannot just block 443, I have an aliases with every known public DOT and DOH on OPNSense 2. The firewall blocks any requests to those IPs on port 443-DOH and 853-DOT If I type on my browser 8.8.8.8:443, it does not work and OPNSense firewall log shows the block message, so DOT:853 and DOH:443 are fully blocked.