Encrypt your DNS queries on /e/OS system-wide

Just gotten the confirmation from the Dev of TrackerControl. TrackerControl can’t handle private DNS nor encrypted DNS requests.

TC is moste like Netguard, so I think (but don’t know for sure) that NG will also fail with this setup. So everyone have to decide: Blocking trackers or using private DNS encryption

2 Likes

It’s good you’re dealing with it, @harvey186 This information is valuable.

I appreciate the “Select private DNS mode” feature in /e/ OS 9-Pie and use it because with FOSS apps à la Simple Mobile Tools (/from F-Droid Store) and don’t need apps like the very attractive TrackerControl (TC).

That’s the best way, but for all other users which are using non-FOSS apps it a needed information that TC isn’t failing with private DNS and I have jus read (in german) that Netguard does have the same issue Blokada seems also onyl AFW+ with root not. But root is not the best for a device

I totally agree with you. As I wrote above: »This information is valuable.«

Please don’t recommend it, it has been shut down since 30.04.2020.

Where did you get this information?

On the website of dismail de are valid as of today:

fdns2.dismail.com | fdns1.dismail.com


dismail_dns

@GaelDuval Once more my question: what tracker blocker do you use ?? Or do you really only use FOSS aps ??

I quoted https://securedns.eu/ It has apparently shut down as per the notice on the homepage itself.

Aha, I’ve assumed that dismail.de | Host: fdns1.dismail.de | Server location: Germany and the accompanying picture.


Please note: TLS Hostname: dot.securedns.eu

SecureDNS has been shutdown since the 30th of April 2020. Please do not use SecureDNS anymore.

@harvey186 , please remember: 93 Smartphones are supported by /e/. Only 20 of them run with /e/ OS 9-Pie and the DNS over TLS (DoT) feature.

20 devices with /e/ OS 9-Pie

|Essential |Essential PH-1 |mata |pie|
|Fairphone |FP2 |FP2 |pie|
|Fairphone |FP3 |FP3 |pie|
|Google |Pixel |sailfish |pie|
|Google |Pixel XL |marlin |pie|
|OnePlus |6 |enchilada |pie|
|OnePlus |OnePlus 7 (beta) |guacamoleb |pie|
|OnePlus |6T |fajita |pie|
|OnePlus |7 Pro |guacamole |pie|
|Samsung |Galaxy A5 (2017) |a5y17lte |pie|
|Samsung |Galaxy A5 (2016) |a5xelte |pie|
|Samsung |Galaxy S8 (beta) |dreamlte |pie|
|Samsung |Galaxy S5 LTE International |klte |Pie|
|Samsung |Galaxy A7 (2017) |a7y17lte |pie|
|Xiaomi |Mi 8 |dipper |pie|
|Xiaomi |Mi 5s |capricorn |pie|
|Xiaomi |Poco F1 |beryllium |pie|
|Xiaomi |Mi A1 |tissot |pie|
|Xiaomi |Redmi Note 7 Pro |violet |pie|
|Xiaomi |Mi MIX 2 |chiron |pie|

Tracker Control & Co. are and remain an extremely useful tools.

But still wait for an answer from GAEL. He is promoting apps with trackers via apps store. So he should also showing a way to block them

Did you check the homepage of https://securedns.eu yet?

I don’t understand your question!

The quote with link here and here indicates that dot.securedns.eu should no longer be used.

I am only trying to tell, stop recommending SecureDNS any more. It is shut down officially even if it still works.

And I quote securedns.eu in two postings (here and here) saying “Please do not use SecureDNS anymore.” So that should take care of that point.Or what do you think is necessary in order to be able to consider the subject as clarified?

Okay then. You are a Guru! I am just a beginner. Sorry if I encroached my limits.

As far as I understand AFW+ can only block the whole internet connection for an app and not selected tracker connections. That is provided by the settings in app info also. Is that correct? If so, that may be the reason why it works, it does not need to read the DNS communication. It is a pity that private DNS and tracker blocking are not compatible.

Tha’t corect ---------

I’m kinda lost. Has anyone figured out why private DNS won’t work.

Setting 1:

  • Turn mobile data on
  • Using a private DNS server, e.g. dns.digitale-gesellschaft.ch
    Result: No connection “Private DNS server cannot be accessed”

Setting 2:

  • Turn mobile data on
  • Using private DNS option “Automatic”
    Result: Connection works fine

Setting 3:

  • Turn Wifi on and mobile data off
  • Using a private DNS server, e.g. dns.digitale-gesellschaft.ch
    Result: No connection “Private DNS server cannot be accessed”

Setting 4:

  • Turn Wifi on and mobile data off
  • Using the private DNS option “Automatic”
    Result: Connection works fine

Using /e/OS 1.5.1-s on my FP4.

I have a question : does Advanced Privacy (and its tracker blocker function) works with DoT ?

Edit : I’ve found an answer here (Advanced Privacy - know all about it) and it’s “no”. Advanced Privacy can’t block tracker when DoT is used.