Block DoH and DoT dns on Android using banip

well apparently ... most of the posts/solutions here are nonsense... as it doesnt work ...

Don't let the door hit you in the back, on your way out...

2 Likes

well maybe i have something completely wrong ...
i tried to replicate almost everything written here ... with no success ... so no clue :frowning:

Blocking DoT is as simple as this. DoH is more complicated, but still can be blocked.

5 Likes

banIP already includes a blocklist for DoH (also referenced in @trendy post) ... you should start with it and not use an outdated ip list from 2020/2021.

2 Likes

they use other toop ipset something ... and i assume you are referring to the the list
"https://raw.githubusercontent.com/dibdot/DoH-IP-blocklists/master/doh-domains.txt"

i assume the easiest way would be hairpining which i am not able to setup correctly...

Nothing you've posted so far, actually proves it isn't working...

hello,
so i bought new phone samsung s22; and same issue as on old s10... i cant resolve these hosts... all works fine on iphone... just samsung doesnt work.

any idea? i am seriously desperate. :frowning:

someone discussed it here ... again without solution....
https://forum.openwrt.org/t/force-android-phone-to-use-local-dns-for-local-domain-name-resolving

nothing have changed, except for your client device.

Have you disabled the 'Private DNS' setting on your phone?

@krazeh sure, nothing happened.

@frollic so i dont get it ... what do u mean?
there are other threads regarding the same issue ... i cant find any thread with a working solution ...

You also haven't posted any configuration files from what you have tried so far to help you any further.

1 Like

If you use an app like Net Analyzer what does it show the DNS server on your phone is set to?

i think thats tcpdump

It'd really help if you answered the question that was asked...

@krazeh oh my fault ... yeah i am going to install it and provide results. thanks and sorry.

@krazeh
in dns section it shows>
Default gw ipv6 n/a
dns server ipv6 fddc:69d5:f391::1

is it possible to Disable ipv6 dns server? I dont know why ipv6... as i use ipv4 and also device has ipv4 address and ipv6 (no clue why ipv6...)
fe80::3fc1:....
fddc:69d5:....
fddc:69d5:...

thanks!

Could you just answer the question that was asked? What DNS server IP is your phone reporting it's using?

@krazeh
dns server ipv6 fddc:69d5:f391::1

  • thats directly from the app u recco.

Inside that app if i go to tools section and using Query / DNS
and when i provide the xxx.duckdns.org ; settings Any; Dns server: 10.0.1.1 (my openwrt)
it resolves the domain xxx.duckdns.org correctly

The problem here is apparently that phone is not using my dns server 10.0.1.1