• DNS over HTTPS (DoH): How to configure?

    From VanguardLH@3:633/10 to All on Tuesday, January 20, 2026 04:05:52
    I remember reading that there was some way in Android to configure your
    own DNS settings, and thereby specify DoH servers. I went to:

    Settings -> Connections -> More connection settings

    to find a:

    Private DNS

    setting. Under there I could select:

    Private DNS provider hostname

    to specify Cloudflare. But I got curious about another setting:

    Automatic (recommended)
    Uses recommended secure DNS servers.

    Whose secure DNS servers are those? Is "automatic" just Google's way of
    saying Google's servers get used?

    --- PyGate Linux v1.5.2
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From Jörg Lorenz@3:633/10 to All on Wednesday, January 21, 2026 09:36:36
    On 20.01.26 11:05, VanguardLH wrote:
    I remember reading that there was some way in Android to configure your
    own DNS settings, and thereby specify DoH servers. I went to:

    Settings -> Connections -> More connection settings

    to find a:

    Private DNS

    setting. Under there I could select:

    Private DNS provider hostname

    I use: dns.quad9.net
    European/Swiss server
    to specify Cloudflare.
    Which is considered to be very performant:
    IP: "1.1.1.1"

    The automatic setting is not documented in my Pixel but it seems very
    probable that it is the DOH-server of Google with the IP-address "8.8.8.8".

    --
    "Roma locuta, causa finita" (Augustinus)

    --- PyGate Linux v1.5.2
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From VanguardLH@3:633/10 to All on Wednesday, January 21, 2026 13:14:56
    VanguardLH <V@nguard.LH> wrote:

    I remember reading that there was some way in Android to configure your
    own DNS settings, and thereby specify DoH servers. I went to:

    Settings -> Connections -> More connection settings

    to find a:

    Private DNS

    setting. Under there I could select:

    Private DNS provider hostname

    to specify Cloudflare. But I got curious about another setting:

    Automatic (recommended)
    Uses recommended secure DNS servers.

    Whose secure DNS servers are those? Is "automatic" just Google's way of saying Google's servers get used?

    Found some more info. Apparently "automatic" means the phone will try
    to use encryption via port 443/HTTPS to connect to a nameserver, but
    fallback to unencrypted via port 53/DNS if the nameserver doesn't
    support DoH (DNS over HTTPS) or DoT (DNS over TLS). So, you might be
    using DoH or DoT for DNS lookups, or you might not. Flip a coin.

    Instead I chose to specify a DoH/DoT nameserver by selecting "Private
    DNS provider hostname" to enter one.one.one.one for Cloudflare. I then
    tested by visiting https://one.one.one.one/help/ to verify DoH or DoT
    were used by my phone.

    --- PyGate Linux v1.5.2
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)