https://docs.pi-hole.net/...ile/#icloud_private_relayBLOCK_ICLOUD_PR=true|false (PR #1171)¶
Should Pi-hole always replies with NXDOMAIN to A and AAAA queries of mask.icloud.com and mask-h2.icloud.com to disable Apple's iCloud Private Relay to prevent Apple devices from bypassing Pi-hole? This is following the recommendation on https://developer.apple.c...-for-icloud-private-relay
pi@ph5b:~ $ dig +noall +comments +answer @localhost a mask.icloud.com ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 9286 ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 1232
Tov van Google @8.8.8.8 vragen:
pi@ph5b:~ $ dig +noall +comments +answer @8.8.8.8 a mask.icloud.com ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 18624 ;; flags: qr rd ra; QUERY: 1, ANSWER: 9, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 512 ;; ANSWER SECTION: mask.icloud.com. 2142 IN CNAME mask.apple-dns.net. mask.apple-dns.net. 60 IN A 17.248.176.71 mask.apple-dns.net. 60 IN A 17.248.176.5 mask.apple-dns.net. 60 IN A 17.248.176.72 mask.apple-dns.net. 60 IN A 17.248.176.7 mask.apple-dns.net. 60 IN A 17.248.176.73 mask.apple-dns.net. 60 IN A 17.248.176.6 mask.apple-dns.net. 60 IN A 17.248.176.70 mask.apple-dns.net. 60 IN A 17.248.176.4
[ Voor 50% gewijzigd door deHakkelaar op 24-05-2022 23:16 . Reden: dig voorbeeld toegevoegd ]
There are only 10 types of people in the world: those who understand binary, and those who don't