What's new
  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

DNS-over-TLS Not Showing On Win11 PC

dsneed

Occasional Visitor
I setup DNS-over-TLS, but they don't show on my Win 11 PC. The router's IP shows instead. Is this expected?
01 - WAN DNS.png


02 - LAN DNS.png


03 - PC DNS.png
 
I setup DNS-over-TLS,

I find Cloudflare's documentation to be a bit confusing... I don't think 1.1.1.1 filters anything(?)

You may want to consider Cloudflare's DNS filtering options... block malware or block malware+adult content:

I use the following router WAN DNS configuration to block malware, i.e., block access to known malicious websites (no kids here):
1739561018459.png


This tool will give you feedback on your DNS configuration:

OE
 
I find Cloudflare's documentation to be a bit confusing... I don't think 1.1.1.1 filters anything(?)

You may want to consider Cloudflare's DNS filtering options... block malware or block malware+adult content:

I use the following router WAN DNS configuration to block malware, i.e., block access to known malicious websites (no kids here):
View attachment 63959

This tool will give you feedback on your DNS configuration:

OE
Thanks for the tip. It's just me in the house, and I have Malwarebytes and Kaspersky on my PC. I don't think I need more malware protection. Plus, most of my activities are on my iPhone and iPad, which I have Malwarebytes and Apple's Safari anti-malware settings.
 
Thanks for the tip. It's just me in the house, and I have Malwarebytes and Kaspersky on my PC. I don't think I need more malware protection. Plus, most of my activities are on my iPhone and iPad, which I have Malwarebytes and Apple's Safari anti-malware settings.

DNS filtering blocks your entire network of users from reaching known malicious websites... since you are already using Cloudflare DNS-over-TLS, you might as well using their Security option settings as shown configured in the pic I posted above. Security comes in layers.

OE
 
For this type of protection the reaction time is most important. I don't know where Cloudflare gets the blocklists, but seems like they regularly score lower than other popular filtering DNS services.


AiProtection with once a month signature updates is mostly useless.
 
For this type of protection the reaction time is most important. I don't know where Cloudflare gets the blocklists, but seems like they regularly score lower than other popular filtering DNS services.


AiProtection with once a month signature updates is mostly useless.

Anyone reading the test article should click through to view the 9/2024 test results.

I've been going back and forth between Cloudflare Security and Quad9. It may be time to settle on Quad9.
1739570075474.png


AiProtection on my AX88U Pro has done nothing since I got the router, but my safe computing habits do not challenge it much.

OE
 
I use lately infiltered DNS upstream and local filtering. Makes it easier to diagnose when something isn't working.
 
@OzarkEdge Do you have have random/intermittent but very short-lived outages with Quad9?

In the distant past, I have had random/intermittent delays (Q9 growing pains?)... I can't recall full outages, but possible. I have not used Quad9 yet with my current router. I'll report back if I experience anything unusual.

I did try Quad9 briefly a little while ago and noticed a laggy speedtest, so backed out. But that turned out to be Spectrum cable service 'time of day' behavior, imo.

For my location, DNS Check shows more routing and finishes a bit slower than when using Cloudflare Security.

OE
 
Last edited:
I setup DNS-over-TLS, but they don't show on my Win 11 PC. The router's IP shows instead. Is this expected?
View attachment 63956

View attachment 63957

View attachment 63958
Hi there! It's a correct behavior because router can not propagate a DoT settings as they are managed by client. Technically your device is the client of router while router is a client of DoT. You can feel safe.
I use for a couple of years the NextDNS service. They works awesome and has a checker page that allows you to ensure you are behind DoT.
Here it is https://test.nextdns.io/
It also supports profiling so that all my devices that goes outside router also behind NextDNS.
 
Last edited:
Hi there! It's a correct behavior because touted is nit a le to propagate a DoT settings as they are managed by client. Technically your device is the client of router while router is a client of DoT. You can feel safe.
I use for a couple of years the NextDNS service. They works awesome and has a checker page that allows you to ensure you are behind DoT.
Here it is https://test.nextdns.io/
It also supports profiling so that all my devices that goes outside router also behind NextDNS.
NextDNS. I have been using it for a while on several devices and it's great. It blocks about 32% of the traffic on my network.
 
Thanks for the tip. It's just me in the house, and I have Malwarebytes and Kaspersky on my PC. I don't think I need more malware protection. Plus, most of my activities are on my iPhone and iPad, which I have Malwarebytes and Apple's Safari anti-malware settings.
on another note, be advised, kaspersky is russian. i'd consider an alternative.
 
So I just went to my laptop and configured it with NextDNS in the wireless adapter *and the browser* and got these results.

DNSSec with TLS 1.3 + Encrypted Client Hello.

Edited: I was using Brave Browser. Edge can do it if you launch it with specific command switches from what I've read
 

Attachments

  • Screenshot_20250217-012040.png
    Screenshot_20250217-012040.png
    57.6 KB · Views: 10

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Back
Top