Replies: 5 comments
-
Good question. Also unclear which servers are reliable for ip-only doh and which are not and have variable ip |
Beta Was this translation helpful? Give feedback.
-
That has to be tested on per-server basis, but I know for sure that all AdGuard, Cloudflare, and Quad9 servers support encrypted DoH without bootstrapping. AdGuard: Cloudflare: Quad9: |
Beta Was this translation helpful? Give feedback.
-
Can you make a signed version of a AdGuard MobilConfig that uses IP instead of domain name for me to test? |
Beta Was this translation helpful? Give feedback.
-
Its also strange that AdGuard's official MobileConfig (https://cdn.adtidy.org/public/Dns/adguard-dns.mobileconfig) lists DNS over HTTPS URL, but my Apple TV sometimes sends queries over TCP port 853 (DNS over TLS) as well. Is DoT in that profile just a fallback for DoH? It is either that or someone is spoofing on my network... |
Beta Was this translation helpful? Give feedback.
-
I figured it out. Earlier-listed AdGuard DNS MobileConfig profile was out-dated. The correct one was the one from here - https://adguard-dns.io/en/public-dns.html and it didn't require plaintext UDP port 53 bootstrapping. |
Beta Was this translation helpful? Give feedback.
-
At the moment I use AdGuard's official MobileConfig for AdGuard DoH, but it only lists "https://dns.adguard.com/dns-query" for DNS resolver address, which requires resolution over UDP port 53 in plaintext before DNS-over-HTTPS kicks in. That process is also known as bootstrapping. However, if IP address is used in URL for domain name, such as "https://94.140.14.14/dns-query" , then bootstrapping is not necessary and even the initial DNS query is encrypted and sent over TCP port 443.
These profiles do list IP addresses for AdGuard DNS, but they don't list , but they don't specifically list "https://94.140.14.14/dns-query" anywhere. Would iOS accept MobileConfig profiles with "https://94.140.14.14/dns-query" ? I would be willing to try if someone makes one and uploads it.
Beta Was this translation helpful? Give feedback.
All reactions