Just to confirm, your settings for Cloudflare Secure are correct. As dave14305 noted disable DNSSEC then run the Cloudflare help page again. It will tell you that you are connected to 1.1.1.1 and 1.0.0.1 but that is normal.I can't seem to get verification that DNS-over-TLS works. I've followed the wiki, and these are my settings:
View attachment 34916
However, both tenta.com and 1.1.1.1/help report that DNS-over-TLS is not working:
View attachment 34917
What am I doing wrong?
It's a flaw/bug/limitation with the test site.I ran the test again with DNSSEC disabled, and I am happy to report it worked:
View attachment 35033
I am interested to know why DNSSEC invalidates the test when it is enabled? Does that mean DNSSEC and DNS over TLS can't be on at the same time?
The cloudflare.com domain is DNSSEC signed, but the temporary hosts it creates on-the-fly for the test aren't properly signed, causing DNSSEC signature failure.I am interested to know why DNSSEC invalidates the test when it is enabled? Does that mean DNSSEC and DNS over TLS can't be on at the same time?
The cloudflare.com domain is DNSSEC signed, but the temporary hosts it creates on-the-fly for the test aren't properly signed, causing DNSSEC signature failure.
Cloudflare were advised years ago of this issue, they acknowledged it on their support forums, but never addressed it. Solution would be fairly simple - just dedicate a non-signed domain for these temporary DNS allocations, so they won't require DNSSEC validation.
Doubt it. To accurately test DoT, you need to be the provider of that server itself.Is there a better test site?
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!