<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Support for DoT (DNS-over-tls)]]></title><description><![CDATA[<p dir="auto">According to <a href="https://forum.cloudron.io/topic/3865/adguard-home-package-updates/7">this thread</a> DoT support was added in v1.2.0 of the AdGuard package (with Cloudron 6.2).</p>
<p dir="auto">The Cloudron package documentation however still mentions that DoT is <a href="https://docs.cloudron.io/apps/adguard-home/" target="_blank" rel="noopener noreferrer nofollow ugc">"not yet supported"</a></p>
<p dir="auto">Therefore I decided to just try it out and after some fiddling with OpenWRT and stubby in particular I was able to get DoT working.</p>
<p dir="auto">So I guess Cloudron's AdGuard documentation can use some extra love regarding DNS configuration <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f609.png?v=af5271e93de" class="not-responsive emoji emoji-android emoji--wink" style="height:23px;width:auto;vertical-align:middle" title=";-)" alt="😉" /></p>
]]></description><link>https://forum.cloudron.io/topic/6760/support-for-dot-dns-over-tls</link><generator>RSS for Node</generator><lastBuildDate>Fri, 17 Jul 2026 11:17:17 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/6760.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 04 Apr 2022 13:22:15 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Support for DoT (DNS-over-tls) on Fri, 15 Jul 2022 06:57:05 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/khadanja" aria-label="Profile: khadanja">@<bdi>khadanja</bdi></a> Indeed, OpenVPN uses a custom port and does not run over http(s)</p>
]]></description><link>https://forum.cloudron.io/post/50874</link><guid isPermaLink="true">https://forum.cloudron.io/post/50874</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Fri, 15 Jul 2022 06:57:05 GMT</pubDate></item><item><title><![CDATA[Reply to Support for DoT (DNS-over-tls) on Thu, 14 Jul 2022 10:37:29 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> OpenVPN also doesn’t work with proxying. At the moment I have only AdGuard and OpenVPN installed and DNS server in OpenVPN is set to adguard’s private IP. Works without Cloudflare proxying but issues with proxy turned on.</p>
]]></description><link>https://forum.cloudron.io/post/50853</link><guid isPermaLink="true">https://forum.cloudron.io/post/50853</guid><dc:creator><![CDATA[khadanja]]></dc:creator><pubDate>Thu, 14 Jul 2022 10:37:29 GMT</pubDate></item><item><title><![CDATA[Reply to Support for DoT (DNS-over-tls) on Mon, 11 Jul 2022 21:50:54 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> Thanks As a workaround using DoH works with proxy enabled on Android rising Intra app and on iPhone using config profile but looks like Private DNS only supports tls.</p>
]]></description><link>https://forum.cloudron.io/post/50760</link><guid isPermaLink="true">https://forum.cloudron.io/post/50760</guid><dc:creator><![CDATA[khadanja]]></dc:creator><pubDate>Mon, 11 Jul 2022 21:50:54 GMT</pubDate></item><item><title><![CDATA[Reply to Support for DoT (DNS-over-tls) on Mon, 11 Jul 2022 13:32:33 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/khadanja" aria-label="Profile: khadanja">@<bdi>khadanja</bdi></a> It won't work with cloudflare proxying since cloudflare only proxies http and https.</p>
]]></description><link>https://forum.cloudron.io/post/50748</link><guid isPermaLink="true">https://forum.cloudron.io/post/50748</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Mon, 11 Jul 2022 13:32:33 GMT</pubDate></item><item><title><![CDATA[Reply to Support for DoT (DNS-over-tls) on Mon, 11 Jul 2022 11:45:05 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> <a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> Issue was DNS proxy option enabled in Cloudflare. Works if I set it to DNS only. Is there any way of making it work with proxy option enabled? I can access the admin interface with Cloudflare proxy enabled but Private DNS doesn’t work on devices.</p>
]]></description><link>https://forum.cloudron.io/post/50744</link><guid isPermaLink="true">https://forum.cloudron.io/post/50744</guid><dc:creator><![CDATA[khadanja]]></dc:creator><pubDate>Mon, 11 Jul 2022 11:45:05 GMT</pubDate></item><item><title><![CDATA[Reply to Support for DoT (DNS-over-tls) on Thu, 07 Jul 2022 14:55:47 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/khadanja" aria-label="Profile: khadanja">@<bdi>khadanja</bdi></a> said in <a href="/post/50564">Support for DoT (DNS-over-tls)</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> I'm having the same issue. My Cloudron instance is in the cloud. How to forward port 853 or open?</p>
</blockquote>
<p dir="auto">This is automatically opened on the server itself. Do you have a Cloud firewall or some security group in front of the server?</p>
<p dir="auto">It seems the cert is self-signed, are your certs OK on the browser?</p>
]]></description><link>https://forum.cloudron.io/post/50654</link><guid isPermaLink="true">https://forum.cloudron.io/post/50654</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Thu, 07 Jul 2022 14:55:47 GMT</pubDate></item><item><title><![CDATA[Reply to Support for DoT (DNS-over-tls) on Wed, 06 Jul 2022 03:38:35 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> I'm having the same issue. My Cloudron instance is in the cloud. How to forward port 853 or open?<br />
Also I see this in AdGuard Encryption settings and logs below.<br />
<img src="/assets/uploads/files/1657078696389-bf810372-b9cc-4379-9831-2ed393d12d9b-image.png" alt="bf810372-b9cc-4379-9831-2ed393d12d9b-image.png" class=" img-fluid img-markdown" /><br />
Jul 06 15:37:48 2022/07/06 03:37:48.610611 [error] handling tcp: reading msg: reading len: remote error: tls: unknown certificate authority</p>
]]></description><link>https://forum.cloudron.io/post/50564</link><guid isPermaLink="true">https://forum.cloudron.io/post/50564</guid><dc:creator><![CDATA[khadanja]]></dc:creator><pubDate>Wed, 06 Jul 2022 03:38:35 GMT</pubDate></item><item><title><![CDATA[Reply to Support for DoT (DNS-over-tls) on Thu, 21 Apr 2022 21:42:49 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> said in <a href="/post/46125">Support for DoT (DNS-over-tls)</a>:</p>
<blockquote>
<p dir="auto">If you are on a home sever, the firewall needs to port forward the above port (853 by default) to the Cloudron VM.</p>
</blockquote>
<p dir="auto">Aha! This is probably the reason it's not working. I wasn't aware of that setting. But now I do see it (and its enabled).</p>
<p dir="auto">I'll forward that port in my firewall. Thanks <a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a></p>
]]></description><link>https://forum.cloudron.io/post/46445</link><guid isPermaLink="true">https://forum.cloudron.io/post/46445</guid><dc:creator><![CDATA[ei8fdb]]></dc:creator><pubDate>Thu, 21 Apr 2022 21:42:49 GMT</pubDate></item><item><title><![CDATA[Reply to Support for DoT (DNS-over-tls) on Thu, 14 Apr 2022 00:02:50 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/dantheman" aria-label="Profile: DanTheMan">@<bdi>DanTheMan</bdi></a> said in <a href="/post/46135">Support for DoT (DNS-over-tls)</a>:</p>
<blockquote>
<p dir="auto">Do you restrict source ip addresses to port:853 in your firewall, from the outside in? Or do you restrict ip addresses in AdGuard?</p>
</blockquote>
<p dir="auto">It's best to restrict source IP in the firewall, if this is possible in your situation. To keep the IP range flexible, you can geo lock the IP range to your region. This does still make it slightly vulnerable. My router (synology) supports geolocking built-in.</p>
<blockquote>
<p dir="auto">For security reasons......<br />
Also does port:53 have to opened up as well in the firewall for this to work? Or only port:853?</p>
</blockquote>
<p dir="auto">Only port 853 is needed.</p>
<p dir="auto">Port 53 is needed if you use it as a DNS server, which AFAIK Android does not support setting anymore!.</p>
]]></description><link>https://forum.cloudron.io/post/46144</link><guid isPermaLink="true">https://forum.cloudron.io/post/46144</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Thu, 14 Apr 2022 00:02:50 GMT</pubDate></item><item><title><![CDATA[Reply to Support for DoT (DNS-over-tls) on Wed, 13 Apr 2022 18:51:33 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> Thanks Girish for your clear explanation.<br />
One question from my side.<br />
Do you restrict source ip addresses to port:853 in your firewall, from the outside in? Or do you restrict ip addresses in AdGuard?<br />
For security reasons......</p>
<p dir="auto">Also does port:53 have to opened up as well in the firewall for this to work? Or only port:853?</p>
]]></description><link>https://forum.cloudron.io/post/46135</link><guid isPermaLink="true">https://forum.cloudron.io/post/46135</guid><dc:creator><![CDATA[DanTheMan]]></dc:creator><pubDate>Wed, 13 Apr 2022 18:51:33 GMT</pubDate></item><item><title><![CDATA[Reply to Support for DoT (DNS-over-tls) on Wed, 13 Apr 2022 17:10:14 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/ei8fdb" aria-label="Profile: ei8fdb">@<bdi>ei8fdb</bdi></a> said in <a href="/post/45903">Support for DoT (DNS-over-tls)</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> Do you have any advice on setting this up on Android devices? I've been trying but no luck yet. Thanks.</p>
</blockquote>
<p dir="auto">So, all I had to do was Settings -&gt; Network &amp; Internet -&gt; Advanced -&gt; Private DNS. There in the<code>'Private DNS provider hostname</code>, I just enter my AdGuard installation hostname like <code>adguard.domain.com</code> . That's pretty much it. Note that you cannot put an IP address here since Android requires the cert name and the hostname to match.</p>
<p dir="auto">For the above to work:</p>
<ul>
<li>
<p dir="auto">In Cloudron dashboard -&gt; Adguard -&gt; Location section. Do you see <code>DNS over TLS (DoT) Port </code> enabled ?</p>
<p dir="auto"><img src="/assets/uploads/files/1649869775371-ae54f23a-c98e-408b-b1b4-1994c3eb94cd-image-resized.png" alt="ae54f23a-c98e-408b-b1b4-1994c3eb94cd-image.png" class=" img-fluid img-markdown" /></p>
</li>
<li>
<p dir="auto">If you are on a home sever, the firewall needs to port forward the above port (853 by default) to the Cloudron VM.</p>
</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/46125</link><guid isPermaLink="true">https://forum.cloudron.io/post/46125</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Wed, 13 Apr 2022 17:10:14 GMT</pubDate></item><item><title><![CDATA[Reply to Support for DoT (DNS-over-tls) on Wed, 13 Apr 2022 15:56:22 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/ei8fdb" aria-label="Profile: ei8fdb">@<bdi>ei8fdb</bdi></a> Firefox does take some extra configuration. You have to install a CA cert into the android store via the Adguard app, enable secret options on Firefox app (go to about Firefox and tap logo 5 times), enable use of third party certificates.</p>
<p dir="auto">For DoT on the Adguard Home side check encryption settings to configure domain names and certificates.</p>
]]></description><link>https://forum.cloudron.io/post/46116</link><guid isPermaLink="true">https://forum.cloudron.io/post/46116</guid><dc:creator><![CDATA[panthrosrevenge]]></dc:creator><pubDate>Wed, 13 Apr 2022 15:56:22 GMT</pubDate></item><item><title><![CDATA[Reply to Support for DoT (DNS-over-tls) on Tue, 12 Apr 2022 09:33:48 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/panthrosrevenge" aria-label="Profile: panthrosrevenge">@<bdi>panthrosrevenge</bdi></a> said in <a href="/post/45970">Support for DoT (DNS-over-tls)</a>:</p>
<blockquote>
<p dir="auto">In the latest release of Android there is an option to specify a private DNS resolver.</p>
</blockquote>
<p dir="auto">There is an option but when I try the domain name of my adguard server it won't accept it. Neither the IP I am trying.</p>
<blockquote>
<p dir="auto">If your device does not have that option available, the Adguard app acts as a VPN and can provide secure DNS lookups</p>
</blockquote>
<p dir="auto">I use Firefox which doesn't seem to be supported by the app yet.</p>
]]></description><link>https://forum.cloudron.io/post/46020</link><guid isPermaLink="true">https://forum.cloudron.io/post/46020</guid><dc:creator><![CDATA[ei8fdb]]></dc:creator><pubDate>Tue, 12 Apr 2022 09:33:48 GMT</pubDate></item><item><title><![CDATA[Reply to Support for DoT (DNS-over-tls) on Sun, 10 Apr 2022 18:52:50 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/ei8fdb" aria-label="Profile: ei8fdb">@<bdi>ei8fdb</bdi></a> In the latest release of Android there is an option to specify a private DNS resolver. If your device does not have that option available, the Adguard app acts as a VPN and can provide secure DNS lookups</p>
]]></description><link>https://forum.cloudron.io/post/45970</link><guid isPermaLink="true">https://forum.cloudron.io/post/45970</guid><dc:creator><![CDATA[panthrosrevenge]]></dc:creator><pubDate>Sun, 10 Apr 2022 18:52:50 GMT</pubDate></item><item><title><![CDATA[Reply to Support for DoT (DNS-over-tls) on Sat, 09 Apr 2022 12:54:58 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> said in <a href="/post/45681">Support for DoT (DNS-over-tls)</a>:</p>
<blockquote>
<p dir="auto">indeed DoT is supported for a while now. I use it everyday on Android.</p>
</blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> Do you have any advice on setting this up on Android devices? I've been trying but no luck yet. Thanks.</p>
]]></description><link>https://forum.cloudron.io/post/45903</link><guid isPermaLink="true">https://forum.cloudron.io/post/45903</guid><dc:creator><![CDATA[ei8fdb]]></dc:creator><pubDate>Sat, 09 Apr 2022 12:54:58 GMT</pubDate></item><item><title><![CDATA[Reply to Support for DoT (DNS-over-tls) on Mon, 04 Apr 2022 17:51:46 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> thanks for updating the docs.</p>
<p dir="auto">On my Android phone (Android 10) I can't get it working for the moment, I get "unable to connect".<br />
But it's definitely an issue on my end since I have it working on my router.<br />
Anyway, it's not a big deal since my phone is behind my router most of the time.</p>
]]></description><link>https://forum.cloudron.io/post/45688</link><guid isPermaLink="true">https://forum.cloudron.io/post/45688</guid><dc:creator><![CDATA[guyds]]></dc:creator><pubDate>Mon, 04 Apr 2022 17:51:46 GMT</pubDate></item><item><title><![CDATA[Reply to Support for DoT (DNS-over-tls) on Mon, 04 Apr 2022 16:22:55 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/guyds" aria-label="Profile: guyds">@<bdi>guyds</bdi></a> good catch, indeed DoT is supported for a while now. I use it everyday on Android. Fixed - <a href="https://docs.cloudron.io/apps/adguard-home/#dot" target="_blank" rel="noopener noreferrer nofollow ugc">https://docs.cloudron.io/apps/adguard-home/#dot</a> .</p>
]]></description><link>https://forum.cloudron.io/post/45681</link><guid isPermaLink="true">https://forum.cloudron.io/post/45681</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Mon, 04 Apr 2022 16:22:55 GMT</pubDate></item></channel></rss>