AdguardTeam / dnsproxy

Simple DNS proxy with DoH, DoT, DoQ and DNSCrypt support
Apache License 2.0
2.37k stars 246 forks source link

很大的一个bug ,无法解析 https #193

Closed f4nff closed 2 years ago

f4nff commented 2 years ago

dnsproxy.exe -l "0.0.0.0" -p 53 -u tls://8.8.4.4:853 /edns /edns-addr:"28.88.88.88" /insecure /all-servers nslookup -qt=https e17437.dsct.akamaiedge.net

ghost commented 2 years ago

the 8.8.4.4 was known blocked by the Great FireWall, so it is not working.

Lanius-collaris commented 2 years ago

f4nff,你先检查一下你的nslookup是否支持HTTPS记录,cdnjs.cloudflare.com就有HTTPS记录。 user1@localhost ~/dns-adv$ RRTYPE=HTTPS ./dnslookup cdnjs.cloudflare.com 1.2.4.8 dnslookup v1.4.9 dnslookup result: ;; opcode: QUERY, status: NOERROR, id: 6386 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION: ;cdnjs.cloudflare.com. IN HTTPS ;; ANSWER SECTION: cdnjs.cloudflare.com. 255 IN HTTPS 1 . alpn="h3,h3-29,h3-28,h3-27,h2" ipv4hint="104.16.18.94,104.16.19.94" ipv6hint="2606:4700::6810:125e,2606:4700::6810:135e" 另外,别想着弄Domain fronting了,用其它服务器就好。DoQ和DNSCrypt我还没见过在中国被拦截的服务器,DoT和DoH服务器也还有能用的,为啥那么喜欢用google?

ameshkov commented 2 years ago

Does not seem to be a bug of dnsproxy