Using DNSSEC
This is an unsupported configuration created by the community
A lot of the Exit Nodes configure their DNS Server to support DNSSEC. You can test here whether DNSSEC is enabled for your current DNS Servers. If you want to test again by refreshing the site, please be aware of the notes on the site:
To re-run the above test, you also need to:
- Flush the DNS cache of your OS (Windows:
ipconfig /flushdns
) -
Restart browser or clear browser cache
Note: Flushing Browser/DNS Cache here means restarting Pi-hole (DNS Server), restarting the browser and ideally opening the site in private/incognito mode.
Alternatives¶
- An alternative would be using DNSCrypt, but this leaves you in a position where you have to trust the DNSCrypt resolver since your IP is not anonymized - unless you configure DNSCrypt to route over Tor.
Last update: January 19, 2021