Skip to content

Failed on DNSSEC check, EDNS Client Subnet (ECS) problem #2741

Discussion options

You must be logged in to vote

ECS is the behavior of a DNS resolver, according the explanation from https://medium.com/nextdns/how-we-made-dns-both-fast-and-private-with-ecs-4970d70401e5 .

  1. That is the upstream server for dnscrypt-proxy, which you can not control. But, you can carefully choose which resolver/server to use. You can use the making a CHAOS query method to test it. For example, if you use "adguard-dns-unfiltered", it will have ECS.
  2. Use the following option brutally, If you even don't want to leak your IP subset.
    ## Add EDNS-client-subnet information to outgoing queries
    ##
    ## Multiple networks can be…

Replies: 3 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by NoRainfallDuckDog
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants