Question. Why not do the opposite? Keep all to YES to what I have and disable DOT. I already have Quad9 as the main DNS server. btw I do not have DNS director enabled.You can't have backup DNS servers this way and mixing filtered/unfiltered DNS servers doesn't make sense. Also doesn't make sense enabling DNSSEC to upstream trusted DNS provider already doing DNSSEC when the communication to/from you is encrypted. In your case I would keep all four options above "Prevent client auto DoH" to default No and set DoT to Quad9 only.
This is why I'm asking. You definitely know more than I do. Just trying to learn.You can do anything you want based on your needs, it’s your router. When not sure how something works keep it at default setting.
Set Prevent Auto Client DoH to yes
You may not be doing anything wrong. It has been said on this forum that the resolvers are used in round-robin style. Thus there is not fallback logic.I'm trying set up DOT and have Quad9 for 1st and 2nd. 3rd and 4th are set to be Cloudflare. When I run a DNS leak test, I get Cloudflare 1st. Does the order work? I like to have Quad9 for malware protection and Cloudflare for fallback. What am I doing wrong?
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!