Jack-Sparr0w
Senior Member
use-caps-for-id no Avoid NordVPN DNS query handling issues if unbound dns is pushed in vpn then set to yes
harden-referral-path no Improves DNS referral security no is best for vpn and cache hits (also is experimental not to much support)
harden-algo-downgrade yes Avoids DNSSEC algorithm enforcement no issues on cache hits no if vpn dns is pushed
harden-large-queries yes Protects against amplification attacks
harden-short-bufsize yes Defends against buffer overflow attacks
val-clean-additional yes Cleans unnecessary DNS response data
harden-dnssec-stripped no VPN DNS strips DNSSEC, so disable to prevent failures yes if unbound is pushed and no vpn dns push
qname-minimisation-strict no Enhances privacy; fallback to no if resolution issues no is probably best for cache hits with vpn, most VPN providers do not support strict mode so its best set to no leave qname-minimisation on if your not forwarding to dot/doh or dns
harden-unverified-glue yes Validates glue records to prevent cache poisoning
hide-http-user-agent no Prevents breaks in DNS over VPN communication yes if unbound is pushed in vpn
Piehole Forum this was seen
harden-referral-path no Improves DNS referral security no is best for vpn and cache hits (also is experimental not to much support)
harden-algo-downgrade yes Avoids DNSSEC algorithm enforcement no issues on cache hits no if vpn dns is pushed
harden-large-queries yes Protects against amplification attacks
harden-short-bufsize yes Defends against buffer overflow attacks
val-clean-additional yes Cleans unnecessary DNS response data
harden-dnssec-stripped no VPN DNS strips DNSSEC, so disable to prevent failures yes if unbound is pushed and no vpn dns push
qname-minimisation-strict no Enhances privacy; fallback to no if resolution issues no is probably best for cache hits with vpn, most VPN providers do not support strict mode so its best set to no leave qname-minimisation on if your not forwarding to dot/doh or dns
harden-unverified-glue yes Validates glue records to prevent cache poisoning
hide-http-user-agent no Prevents breaks in DNS over VPN communication yes if unbound is pushed in vpn
Piehole Forum this was seen
Last edited: