thanks for this!
Quote from: firewall on August 13, 2018, 02:50:15 pmthanks for this! Dear firewall,This was a labor of determined effort and ( somewhat ) love and I felt that it was best to share with as many as possible. I am a retired teacher.You are most welcome and I appreciate your expression of gratitude. God Bless You and Yours - AlwaysIn Peace,directnupe
Dear Nekromantik.Hello - you should check your DNS here : https://cmdns.dev.dns-oarc.net/ and see the features which are listed as being enabled on your resolver ( UNBOUND ). Look for TRANSPORT and you should see TCP which means that you are using DNS OVER TLS.I have found that the test you mention -: https://tenta.com/test/ is not the best way of testing your DNS attributes. I believe that https://tenta.com/test/ is set up to only fully approve of and verify ( and I guess test ) Tenta DNS and its' browser.Also, with qname-minimisation enabled your resolver ( UNBOUND ) is set up to minimise the amount of data sent from the DNS resolver to the authoritative name server and in addition with randomize_upstreams: 1 option set in STUBBY - then the DNS TLS Stub resolver aka STUBBY will instruct stubby to distribute queries across all available name servers - key word being available. So theoretically DNS name servers will respond in the fastest way possible - meaning that all the name servers may not be queried as qname-minimisation and qname-minimisation-strict limit the amount of data being sent and received between UNBOUND ( and STUBBY ) and the upstream DNS OVER TLS name servers you have configured in your /usr/local/etc/stubby/stubby.yml configuration file. Hope this helps.Peace,directnupe