# Can't get Pi-hole working, dns won't resolve

**URL:** <https://discourse.pi-hole.net/t/cant-get-pi-hole-working-dns-wont-resolve/33549>\
**Category:** Help\
**Created:** [May 28, 2020, 7:40pm UTC](https://discourse.pi-hole.net/t/cant-get-pi-hole-working-dns-wont-resolve/33549 "2020-05-28T19:40:56Z")\
**Posts on this page:** 1\
**Showing post:** 7

<div class="post-metadata">

**Author:** ![deHakkelaar](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dehakkelaar/32/674_2.png) [@deHakkelaar](https://discourse.pi-hole.net/u/deHakkelaar)\
**Post date:** [May 30, 2020, 1:49pm UTC](https://discourse.pi-hole.net/t/cant-get-pi-hole-working-dns-wont-resolve/33549/7 "2020-05-30T13:49:10Z")

</div>

> [@Techloid-g](#):
>
> That matches my output

If your `iptables` output matches mine, you wont need to alter with `iptables` because your rules already allow all.

Below is a good tool to test DNS from a **client** before you make alterations to your router settings.  
You can also run this one on Pi-hole itself to test:

`nslookup pi.hole 192.168.1.84`

First check if the `pihole-FTL` daemon is actually listening on DNS ports 53 UDP/TCP (and others used by Pi-hole) with below:

`sudo netstat -nltup | grep 'Proto\|:53 \|:67 \|:80 \|:547 \|:471[1-8] '`

If that checks out ok, check interface/IP configured for Pi-hole:

`grep 'PIHOLE_INTERFACE\|IPV[4,6]_ADDRESS\|DNSMASQ_LISTENING' /etc/pihole/setupVars.conf`

See if it matches with the actual interface that holds the `192.168.1.84` IP:

`ip -4 -br a`

If that checks out ok, it might be that your router is doing a thing called "DNS rebind protection":

> [@Why won't Pi-hole work with DNS rebind protection enabled?](https://discourse.pi-hole.net/t/why-wont-pi-hole-work-with-dns-rebind-protection-enabled/3142):
>
> What is DNS rebind protection? If your router has an option called DNS rebind protection enabled, you may run into issues when trying to use Pi-hole as your DNS server. The reasons for this are quite technical, but to summarize what this option does in one sentence: DNS rebind protection does not allow DNS queries to be answered with a local IP address. Why does this interfere with Pi-hole? DNS rebind is meant to be a [countermeasure to an attack on your network](http://www.techrepublic.com/blog/it-security/public-ip-dns-rebinding-another-reason-not-to-use-default-passwords/). So in many cases, it's actu…

EDIT: forgot to mention but sometimes AV software can mangle DNS lookups:

> [@Literally no ads being blocked](https://discourse.pi-hole.net/t/literally-no-ads-being-blocked/31600/36):
>
> That Windows machine you are using wouldn't run a virus scanner like AVAST? AVAST offers a feature called RealSite that will inject additional DNS queries to a "trusted" DNS server (run by AVAST) in case something goes wrong with normal DNS resolution, see [Hilfe: Windows löst Hostname auch ohne PiHole auf? - #26 by Chris80](https://discourse.pi-hole.net/t/hilfe-windows-lost-hostname-auch-ohne-pihole-auf/27892/26) (though German, it also contains a short solution description in English).

---

_[View the full topic](https://discourse.pi-hole.net/t/cant-get-pi-hole-working-dns-wont-resolve/33549)._
