# DNS resolve timeout outside of localhost

**URL:** <https://discourse.pi-hole.net/t/dns-resolve-timeout-outside-of-localhost/51531>\
**Category:** Help\
**Created:** [December 9, 2021, 2:43am UTC](https://discourse.pi-hole.net/t/dns-resolve-timeout-outside-of-localhost/51531 "2021-12-09T02:43:08Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rechigo](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/rechigo/32/28466_2.png) [@Rechigo](https://discourse.pi-hole.net/u/Rechigo)\
**Post date:** [December 9, 2021, 2:43am UTC](https://discourse.pi-hole.net/t/dns-resolve-timeout-outside-of-localhost/51531/1 "2021-12-09T02:43:08Z")

</div>

Whenever I try to make a DNS query on any device on my network that isn't the pihole server (localhost), the request ends up timing out. I'm not sure what the issue is here.

## What I've tried:

- Pinging pi-hole ip to confirm it works
- Toggled " **Listen on all interfaces, permit all origins**" in settings
- nmap scan to confirm port 53 is open both TCP & UDP \* Disabling ufw temporarily to confirm it's not a firewall issue
- Performed queries via multiple different computers via nslookup `nslookup <domain> <pi-hole server IP>`, all timed out
- Reconfiguring pi-hole `pihole -r`

## What works so far:

- Local DNS queries from the pi-hole server resolve fine

## Debug Token:

[https://tricorder.pi-hole.net/FVoINvA5/](https://tricorder.pi-hole.net/FVoINvA5/)

---

<div class="post-metadata">

**Author:** ![jfb](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jfb/32/4332_2.png) [@jfb](https://discourse.pi-hole.net/u/jfb)\
**Post date:** [December 9, 2021, 3:46am UTC](https://discourse.pi-hole.net/t/dns-resolve-timeout-outside-of-localhost/51531/2 "2021-12-09T03:46:51Z")

</div>

Something is interfering with port 53 traffic on your network:

```auto
*** [DIAGNOSING]: Name resolution (IPv4) using a random blocked domain and a known ad-serving domain
[✓] gjapplog.ucweb.com is 0.0.0.0 on lo (127.0.0.1)
[✗] Failed to resolve gjapplog.ucweb.com on enp1s0f0 (192.168.1.235)
[✓] gjapplog.ucweb.com is 0.0.0.0 on tun0 (10.8.0.1)
[✗] Failed to resolve gjapplog.ucweb.com on docker0 (172.17.0.1)
[✓] doubleclick.com is 142.250.72.142 via a remote, public DNS server (8.8.8.8)

*** [DIAGNOSING]: Setup variables
    PIHOLE_INTERFACE=enp1s0f0
    IPV4_ADDRESS=192.168.1.235/24

```

Additionally, your DHCP server is passing out a DNS other than Pi-hole, along with the Pi-hole IP. This will lead to some of your DNS traffic bypassing Pi-hole.

```auto
     DHCP options:
      Message type: DHCPOFFER (2)
      server-identifier: 192.168.1.1
      lease-time: 43200 ( 12h )
      renewal-time: 21600 ( 6h )
      rebinding-time: 37800 ( 10h 30m )
      netmask: 255.255.255.0
      broadcast: 192.168.1.255
      domain-name: "lan"
      dns-server: 192.168.1.235
      dns-server: 1.1.1.1
      router: 192.168.1.1
      --- end of options ---

```

> [@Why should Pi-hole be my only DNS server?](https://discourse.pi-hole.net/t/why-should-pi-hole-be-my-only-dns-server/3376):
>
> Reduced Ad Blocking Capability The main reason you should Pi-hole as your only DNS server is that you will see increased performance in the blocking of ads. If you have two DNS servers (Pi-hole and something else), your network clients may not always query Pi-hole for name resolution. If a query happens to be answered from a non-Pi-hole DNS server, your block lists will not apply (since that DNS server doesn't know about them). All Queries Need To Go Through Pi-hole First Since other DNS serv…

---

<div class="post-metadata">

**Author:** ![Rechigo](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/rechigo/32/28466_2.png) [@Rechigo](https://discourse.pi-hole.net/u/Rechigo)\
**Post date:** [December 9, 2021, 4:30am UTC](https://discourse.pi-hole.net/t/dns-resolve-timeout-outside-of-localhost/51531/3 "2021-12-09T04:30:49Z")

</div>

There is a Cloudflare DNS being given by the router because I assumed (incorrectly) that it would only be used as a secondary/fallback DNS server in the event that my pi-hole server went down.

As for what's interfering with traffic on port 53, I don't know, but I know it is something on my server. I tried running the same `nslookup <domain> <pi-hole server ip>` again on my computer, except this time I ran a `tcpdump -Q in port 53` on my pi-hole server to see whether or not my request was making it to the server, which it is:

![image](https://discourse.pi-hole.net/uploads/default/original/3X/0/3/03540bf30a266ef1b72873e38d92ef27f1f91a1a.png)

What things should I look for as possible causes now that I have verified that the requests are making it to my server?

---

<div class="post-metadata">

**Author:** ![system](https://discourse.pi-hole.net/uploads/default/original/3X/7/c/7c8792f649eeb921c5d2b4c41564ffa873d9a2b8.png) [@system](https://discourse.pi-hole.net/u/system)\
**Post date:** [December 30, 2021, 4:31am UTC](https://discourse.pi-hole.net/t/dns-resolve-timeout-outside-of-localhost/51531/4 "2021-12-30T04:31:06Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
