Apple Private Relay slowdown

Comments

4 comments

  • Avatar
    Support Team

    Firewalla will return NXDOMAIN to devices when the domain is blocked. You may try nslookup mask.icloud.com on one of your devices to check the response.

    0
    Comment actions Permalink
  • Avatar
    David Koppenhofer

    Ah, fantastic, thank you for pointing that out!

     

    I'll have to dig into what's happening with my wife's phone. Would the block of doh.dns.apple.com (or even the Apple Private Relay) servers cause issues - even with the NXDOMAIN response?

     

    Final question: my phone is in a group that's configured to use Unbound, and also DoH is configured for "all devices". The nslookup appears to be using 8.8.8.8 as its server.

    ~ $ nslookup doh.dns.apple.com

    Server: 8.8.8.8

    Address: 8.8.8.8#53

     

    ** server can't find doh.dns.apple.com: NXDOMAIN

    dnsleaktest.com correctly shows my external IP address. Am I misunderstanding the nslookup output?

     

    Thanks,

    David

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Nslookup requests will be forwarded to what ever DNS services you picked. So, if you setup unbound and your PC configured to be 8.8.8.8, it will use unbound, while your PC may still think it is 8.8.8.8

    0
    Comment actions Permalink
  • Avatar
    David Koppenhofer

    I found the reason the nslookup via Termux wasn't using the system settings, but /usr/etc/resolv.conf

    https://www.reddit.com/r/pihole/comments/iivdgq/psa_termux_on_android_does_not_use_system_dns/?utm_medium=android_app&utm_source=share

    Thanks again for the help!

    0
    Comment actions Permalink

Please sign in to leave a comment.