Advice Request is Edge leaking DNS?

Please provide comments and solutions that are helpful to the author of this topic.

porkpiehat

Level 6
Thread author
Verified
Well-known
May 30, 2015
277
ok, I have DoH, and Quad9 selected in Edge settings, now, when I test my DNS with Web-based DNS Randomness Test | DNS-OARC it shows the Quad9 servers, and my ISP servers..... I have run this test with my other browsers, which are setup with similar configs, and they return results from their chosen DNS, with no sign of any ISP. I can only assume that the problem is with Edge... is there something that needs tweaking to solve this?
 

silversurfer

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,148
@porkpiehat Please try this check for DNS leaks: DNS Leak Test

Here on my device and running Edge, this test above shows only DNS servers by Quad9 👍

On your Edge, settings for DoH are the same than on my screenshot below ?

dohonedge.png
 

Amahl Farouk

Level 1
Jan 11, 2021
34
@porkpiehat It's by design. By default, the DoH implementation has failover.

There's group policy that you need to set up with the Edge .adm download from Edge for Business website.
Once installed the group policy file you can set it to "DoH without failover" and it will be forced to use only DoH.

It considers a "fail" certain query times, so it uses system DNS instead of DoH exclusively...good UX poor privacy, I guess.
 
Last edited:

silversurfer

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,148
It's by design. By default, the DoH implementation has failover.

There's group policy that you need to set up with the Edge .adm download from Edge for Business website.
Once installed the group policy file you can set it to "DoH without failover" and it will be forced to use only DoH.

It considers a "fail" certain query times, so it uses system DNS instead of DoH exclusively...good UX poor privacy, I guess.
1st: For me DoH works properly without DNS leaks on all my browsers, the same for Edge
2nd: Me and other Windows 10 Home users: access to group policy isn't a part of the OS
3rd: You should "quote" the OP @porkpiehat instead of me as I'm fine as said at 1st above
 

porkpiehat

Level 6
Thread author
Verified
Well-known
May 30, 2015
277
TBH, I don't think the problem is the browser... the DNS Randomness test appears to test both the system (network) DNS, and the browser based DNS... so, if your network is running Cloudflare, and your browser is set for DoH Quad9.... the test will show results for both.... 🤔
 

Amahl Farouk

Level 1
Jan 11, 2021
34
TBH, I don't think the problem is the browser... the DNS Randomness test appears to test both the system (network) DNS, and the browser based DNS... so, if your network is running Cloudflare, and your browser is set for DoH Quad9.... the test will show results for both.... 🤔
As I've explained, it's by design. I had the same problem with Edge's implementation of DoH and it was solved using the "DoH without failover" group policy. If you don't have Windows 10 Professional, I don't think there's another option but to use a system-level DoH setup.
 

porkpiehat

Level 6
Thread author
Verified
Well-known
May 30, 2015
277
As I've explained, it's by design. I had the same problem with Edge's implementation of DoH and it was solved using the "DoH without failover" group policy. If you don't have Windows 10 Professional, I don't think there's another option but to use a system-level DoH setup.
that may be so, but it also happens with Opera, and Firefox.. so, I guess you need to make sure that you have a trusted DNS setup in your network prefs, to avoid your ISP DNS.
 
Last edited:

Brahman

Level 17
Verified
Top Poster
Well-known
Aug 22, 2013
815
ok, I have DoH, and Quad9 selected in Edge settings, now, when I test my DNS with Web-based DNS Randomness Test | DNS-OARC it shows the Quad9 servers, and my ISP servers..... I have run this test with my other browsers, which are setup with similar configs, and they return results from their chosen DNS, with no sign of any ISP. I can only assume that the problem is with Edge... is there something that needs tweaking to solve this?
If you want to prevent dns leaks I suggest you to use DOH at the router level ( ddwrt, openwrt, routeros, pfsense, opnsense, edgeos etc support doh). That's the only way you can make sure all the port 53, port5353 traffic is being rerouted through port 443.
 

porkpiehat

Level 6
Thread author
Verified
Well-known
May 30, 2015
277
If you want to prevent dns leaks I suggest you to use DOH at the router level ( ddwrt, openwrt, routeros, pfsense, opnsense, edgeos etc support doh). That's the only way you can make sure all the port 53, port5353 traffic is being rerouted through port 443.
true, but my router is 'fixed' by my ISP... so, I can't adjust the settings.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top