@markn6262 said in Dns rebind attack - Encrypted DNS?: Reply. I have the same issue in my logs. In my research, I determined that NextDNS is a DoH (DNS over HTTPS) service, used by the latest browsers from Firefox and Google for "privacy" in DNS requests. The "trr" stands for Trusted Recursive Resolver. Under DNSMasq, make sure DNSMasq, Local DNS, & No DNS Rebind are all set to Enable. Save and Apply Settings. Navigate to Services > VPN. Under OpenVPN Client, set Start

Within my registrar for the domain I setup a NS record for the subdomain rebind to point to the IP where this tool is hosted. ns A rebind NS The DNS server responds only to A queries in this format evcmxfm4g . 81-4-124-10 . 127-0-0-1

DD-WRT GUI Services-> DNSMasq section: enable "Local DNS" and disable "No DNS Rebind", go to Tunnels to enter local DNS IP (e.g. for Peer Tunnel DNS (repeat for every peer). Since Wireguard cannot be bridged, the wireguard interface or it's local IP needs specified in dnsmasq as an additional binding interface / listener (interface Sonicwall DNS Rebind Attack exclusions not working Feb 20, 2018 Google, Roku, Sonos To Fix DNS Rebinding Attack Vector

"No DNS Rebind" needs to be disabled in order for DNSMasq to work. Using the setting "rebind-domain-ok= " should allow "No DNS Rebind" to remain enabled (as it's a security feature). "Query DNS in Strict Order" should prevent any backup DNS servers from being queries unless the server before it in the queue is offline.

