Just to confirm, your settings for Cloudflare Secure are correct. As dave14305 noted disable DNSSEC then run the Cloudflare help page again. It will tell you that you are connected to 1.1.1.1 and 1.0.0.1 but that is normal.I can't seem to get verification that DNS-over-TLS works. I've followed the wiki, and these are my settings:
View attachment 34916
However, both tenta.com and 1.1.1.1/help report that DNS-over-TLS is not working:
View attachment 34917
What am I doing wrong?
It's a flaw/bug/limitation with the test site.I ran the test again with DNSSEC disabled, and I am happy to report it worked:
View attachment 35033
I am interested to know why DNSSEC invalidates the test when it is enabled? Does that mean DNSSEC and DNS over TLS can't be on at the same time?
The cloudflare.com domain is DNSSEC signed, but the temporary hosts it creates on-the-fly for the test aren't properly signed, causing DNSSEC signature failure.I am interested to know why DNSSEC invalidates the test when it is enabled? Does that mean DNSSEC and DNS over TLS can't be on at the same time?
The cloudflare.com domain is DNSSEC signed, but the temporary hosts it creates on-the-fly for the test aren't properly signed, causing DNSSEC signature failure.
Cloudflare were advised years ago of this issue, they acknowledged it on their support forums, but never addressed it. Solution would be fairly simple - just dedicate a non-signed domain for these temporary DNS allocations, so they won't require DNSSEC validation.
Doubt it. To accurately test DoT, you need to be the provider of that server itself.Is there a better test site?
We use essential cookies to make this site work, and optional cookies to enhance your experience.