RUTX50 - DNS Over HTTPS (DOH)

Good afternoon y’all,

Does anyone know how to setup/enable/configure DNS Over HTTPS (DOH) on a RUTX50?

I’ve seen threads about using DNS over TLS (DOT) or NextDNS (both of which I do not want to use).

With how feature loaded this device is, I expected it to come ready to setup DNS Over HTTPS.

Thanks much!

Hello,

I’ve followed the configuration example provided here: [OpenWrt Wiki] DoH with Dnsmasq and https-dns-proxy
And got DoH working. Could you test it to check if it’s what you’re looking for?
Once the package is installed, it can be configured in the /etc/config/dhcp file, dnsmasq section.

Best regards,

Good morning,

I attempted to configure it via the link provided and I think I’m good to go but when I check my Windows machine, it shows “(Unencrypted)” for my DNS server addresses. I have an ASUS router at my house that’s setup for DoH and for that it shows “(Encrypted)”.

Do you know why it would still show unencrypted within Windows?

Thanks much!

Hello,

This may be because Windows still sees the router as the DNS resolver. To properly check if the dns traffic is encrypted, on the RUTX50 navigate to Services → Package Manager → Packages, and download the TCPdump package. Once installed, navigate to System → Administration → Troubleshoot, enable the TCPdump, and select the interface as qmimux0 (for mobile connection).
After that is done, on Windows machine via the CMD window run the command nslookup followed by a few less-used domains. This will send the DNS queries.
After that is done, go back to the RUTX50, and download the TCPdump file. In the downloaded archive, there will be a .pcap packet capture file. It can be opened and analyzed using an application like Wireshark. The DNS queries on the WAN interface should be encypted.
Let me know what you find!

Best regards,

This topic was automatically closed after 15 days. New replies are no longer allowed.