Hi guys

Anyone knows how to configure Unbound as doh server? At the moment I using recursive default option.

Will DoH give me more privacy?

Thx

  • vegetaaaaaaa@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 year ago

    I’m interested in the same thing (both query upstream DNS over HTTPS servers, and answer to DoH queries), but using dnsmasq. I haven’t had much time to look into this yet, but will definitely try to implement it later, so any recommendations would be appreciated. So far my research notes on this topic only contain:

    https://wiki.archlinux.org/index.php/Dnscrypt-proxy
    https://packages.debian.org/sid/main/nss-tlsd
    https://packages.debian.org/sid/main/tlslookup
    https://blitiri.com.ar/git/r/dnss/b/master/t/f=README.md.html
    
  • BlackEco@lemmy.blackeco.com
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 year ago

    Do you want Unbound to query DNS over HTTPS servers or do you want unbound to answer to DoH queries?

    For the latter unbound can be set to answer to DoH queries.

    I personally went for dnsproxy (which, as its name implies, proxies DNS queries) because there’s PiHole (which does not support either out of the box) in between my devices and unbound.

  • Decronym@lemmy.decronym.xyzB
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

    Fewer Letters More Letters
    DNS Domain Name Service/System
    Git Popular version control system, primarily for code
    HTTP Hypertext Transfer Protocol, the Web
    HTTPS HTTP over SSL
    PiHole Network-wide ad-blocker (DNS sinkhole)
    SSL Secure Sockets Layer, for transparent encryption

    [Thread #111 for this sub, first seen 6th Sep 2023, 05:45] [FAQ] [Full list] [Contact] [Source code]

  • foggenbooty@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    1 year ago

    Are you using the Unbound built into OPNsense, or something else? I ask because it’s easy to configure Unbound in OPNsense for DoT. If your ISP isn’t blocking DoT it will be just as secure.

    And yes, it will be much more private. Right now if you’re using neither DoT or DoH your ISP will be able to see all your DNS requests in the clear. With either of the above it will be encrypted and they will not be able to read them.