Question on DNS hijacking

Good morning all.

I am going to implement to hijacking code detailed in this excellent guide -

before I do, an anyone confirm that it still works as stated when I have the Dns-over-Https proxy installed as at ?

Or do I need to make any changed?

another question of interest, the guide explains how to block potentially hostile clients using DoH or DoT. But if it is so easy, what is to stop my ISP doing this?

https-dns-proxy already has a force_dns option that should take care of DNS interception, so you don’t need to do it manually.


Oh cool, thanks.
But do i still need to manually block devices from using DoH or DoT? Or does the force option in the DNS proxy handle that too?

It will prevent DoT, but DoH will need the other solution.

Yes but only for Apple & Firefox. If you want to cover more DoH providers you can use lists such as this: