Blocked that hard-coded google dns garbage.

  • blackstrat@lemmy.fwgx.uk
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    How do you block the DoH servers in the pihole? Pihole is a DNS server, devices using a third party DoH server would just bypass the pihole as they’re using the IP of the DoH with no DNS lookup required. No?

    To block DoH I think you need to block it at the firewall level with a list of blocked IPs for the DoH servers you want to block over 443

    • jubilationtcornpone
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      You’re probably better off blocking it at the firewall level. It would be more thorough but also more effort. In my experience, most devices/apps that use DoH call a domain name rather than an IP. If you block the domain in piHole, the app cant resolve the DoH server IP and therefore won’t be able to use DoH.