What's new

Validating DNS over TLS

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

thebatfink

Occasional Visitor
Hi, most likely a very simple question but would like to confirm rather than blindly presume. I have been setting up DNS over TLS following the wiki guide. I used cloudflare DNS servers. After setting it up however all the test websites I tried say TLS is not being used (even when DNSSEC was off).

Anyhow I installed tcpdump and using the command in the wiki, watched and saw all the queries go to 1.1.1.1:853 and come back from 1.1.1.1:853.. but they all originate from ports like my.ip:60727. I guess I expected them to be from 853 also, does it look like TLS is being used??

Thanks
 
I guess I expected them to be from 853 also,
No, that is normal. The source port will be a random port, just like when you access a web site on port 443, the local port used by your browser will be a random one.

As long you are using remote port 853, then you are definitely using DNS-over-TLS.
 

Similar threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top