Closed APT-ZERO closed 1 month ago
TCP and UDP's 853, I recall, was to shield DoT, I think.
What is benefits of blocking DoT?
I was seeing that the official sing-box website has it in the examples. At that time I thought about the reason and I guessed that the possible reason was to be able to fully (and better) hijack Dns requests when using tun mode for example.
It's not mandatory to block it, so please comment based on your own results after thinking about it. If you want to further bottom why singbox has it, you can also go to its homepage and ask the author.
Translated with DeepL.com (free version)
Hello, You have blocked DNS over QUIC (853 UDP), but why you have blocked 853 TCP too? does DNS over QUIC use TCP too?