https://docs.pi-hole.net/...ile/#icloud_private_relayBLOCK_ICLOUD_PR=true|false (PR #1171)¶
Should Pi-hole always replies with NXDOMAIN to A and AAAA queries of mask.icloud.com and mask-h2.icloud.com to disable Apple's iCloud Private Relay to prevent Apple devices from bypassing Pi-hole? This is following the recommendation on https://developer.apple.c...-for-icloud-private-relay
pi@ph5b:~ $ dig +noall +comments +answer @localhost a mask.icloud.com ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 9286 ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 1232
Tov van Google @8.8.8.8 vragen:
pi@ph5b:~ $ dig +noall +comments +answer @8.8.8.8 a mask.icloud.com ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 18624 ;; flags: qr rd ra; QUERY: 1, ANSWER: 9, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 512 ;; ANSWER SECTION: mask.icloud.com. 2142 IN CNAME mask.apple-dns.net. mask.apple-dns.net. 60 IN A 17.248.176.71 mask.apple-dns.net. 60 IN A 17.248.176.5 mask.apple-dns.net. 60 IN A 17.248.176.72 mask.apple-dns.net. 60 IN A 17.248.176.7 mask.apple-dns.net. 60 IN A 17.248.176.73 mask.apple-dns.net. 60 IN A 17.248.176.6 mask.apple-dns.net. 60 IN A 17.248.176.70 mask.apple-dns.net. 60 IN A 17.248.176.4
[ Voor 50% gewijzigd door deHakkelaar op 24-05-2022 23:16 . Reden: dig voorbeeld toegevoegd ]
There are only 10 types of people in the world: those who understand binary, and those who don't
/f/image/HIocd84Dg2Znzr6mWyiGA9dK.png?f=fotoalbum_large)
/f/image/l0gCwjgL7IAxDLmdYc9tyKf8.png?f=fotoalbum_large)
/f/image/P3ZdclHdiJrnDkHE32frWn0p.png?f=fotoalbum_large)
/f/image/aLNqqftqSMSh44D7zO5HcLi9.png?f=fotoalbum_large)
/f/image/M9UfwYzciHhvne7EkAq5Lj6z.png?f=fotoalbum_large)
:strip_exif()/f/image/w5ZV5MKiP03lEoi2UfekrfeU.jpg?f=fotoalbum_small)
:strip_exif()/f/image/mtBh1ae460NVogSjdFfSNZU1.jpg?f=fotoalbum_small)