• 0 Posts
  • 2 Comments
Joined 2Y ago
cake
Cake day: Jul 30, 2023

help-circle
rss

Yeah fair. I tried setting it up, but honestly probably not worth the effort in home networks. Problem is browsers don’t know that the other end of the unbound DNS server is DoH, so it won’t use ECH. Even once set up, most browsers need to be manually configured to use the local DoH server. Once there’s better OS support and auto config via DDR and/or DNR it’ll be more worth bothering with.


Do you have the local unbound server respond to DoH so that the browser also uses encrypted client hello?