# DNSMASQ\_WARN	reducing DNS packet size

**URL:** <https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803>\
**Category:** Help\
**Created:** [December 23, 2021, 5:48am UTC](https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803 "2021-12-23T05:48:18Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Scepterus](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/scepterus/32/18912_2.png) [@Scepterus](https://discourse.pi-hole.net/u/Scepterus)\
**Post date:** [December 23, 2021, 5:48am UTC](https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803/1 "2021-12-23T05:48:18Z")

</div>

## Expected Behaviour:

No warnings

## Actual Behaviour:

I get a lot of warnings since the new update rolled out with the new ! at the top of the UI.  
Most of them are: reducing DNS packet size for nameserver 9.9.9.9 to 1280  
and some of them are about IPv6 that I saw someone else just post about, so I joined his post regarding those.  
Running on a Raspberry Pi 4, with the latest everything.

## Debug Token:

pT3n6Pf1

---

<div class="post-metadata">

**Author:** ![jfb](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jfb/32/4332_2.png) [@jfb](https://discourse.pi-hole.net/u/jfb)\
**Post date:** [December 23, 2021, 6:02am UTC](https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803/2 "2021-12-23T06:02:49Z")

</div>

[https://pi-hole.net/2021/12/22/pi-hole-ftl-v5-12-web-v5-9-and-core-v5-7-released#page](https://pi-hole.net/2021/12/22/pi-hole-ftl-v5-12-web-v5-9-and-core-v5-7-released#page) content

[https://github.com/pi-hole/FTL/pull/1243](https://github.com/pi-hole/FTL/pull/1243)

---

<div class="post-metadata">

**Author:** ![yubiuser](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/yubiuser/32/12100_2.png) [@yubiuser](https://discourse.pi-hole.net/u/yubiuser)\
**Post date:** [December 23, 2021, 6:04am UTC](https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803/3 "2021-12-23T06:04:08Z")

</div>

> **[dnsmasq warnings - Pi-hole documentation](https://docs.pi-hole.net/ftldns/dnsmasq_warn/)**

---

<div class="post-metadata">

**Author:** ![Scepterus](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/scepterus/32/18912_2.png) [@Scepterus](https://discourse.pi-hole.net/u/Scepterus)\
**Post date:** [December 23, 2021, 6:05am UTC](https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803/4 "2021-12-23T06:05:54Z")

</div>

OK, so the devs wanted these, so I'm reporting it. Just got the second post, it says it should do it only once and make that size permanent, that's not the case here, it does that a lot.

---

<div class="post-metadata">

**Author:** ![DL6ER](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dl6er/32/281_2.png) [@DL6ER](https://discourse.pi-hole.net/u/DL6ER)\
**Post date:** [December 23, 2021, 7:30am UTC](https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803/6 "2021-12-23T07:30:00Z")

</div>

> [@Scepterus](#):
>
> that's not the case here, it does that a lot

Always for the same server and with the same upper limit? If so, you have unveiled a probably long-standing `dnsmasq` bug.

---

<div class="post-metadata">

**Author:** ![Scepterus](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/scepterus/32/18912_2.png) [@Scepterus](https://discourse.pi-hole.net/u/Scepterus)\
**Post date:** [December 23, 2021, 7:35am UTC](https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803/8 "2021-12-23T07:35:31Z")

</div>

Well, it depends on what you define as a session. If the session is 2 hours, then every 2 hours each server is issuing this warning. If that's normal operations, would it be possible to have a way to ignore these warning and have them not show up on the dashboard?

Also, if someone could look into the IPv6 errors I'm getting, posted in another thread by someone else as well, that would clear up all my warnings.

---

<div class="post-metadata">

**Author:** ![DL6ER](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dl6er/32/281_2.png) [@DL6ER](https://discourse.pi-hole.net/u/DL6ER)\
**Post date:** [December 23, 2021, 8:39am UTC](https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803/9 "2021-12-23T08:39:16Z")

</div>

There is no documentation for `dnsmasq` warnings, hence, I wrote descriptions for every possible warnings I found in the source code. The documentation can clearly be improved as we see these warnings in the wild. A session is one minute by default, so what you are seeing doesn't look like a bug.

Actually, it is quite interesting that you see this only once per two hours (or whatever, but notably less than every minute). I tested quite a few servers and haven't seen such warnings a single time. The lack of reports on our support platforms suggests it is something special to your network.

What router and internet access do you use? Could you imagine anything that would cause this to happen?

Hypothesis: Your ISP is may be manipulating certain queries your Pi-hole is doing only once every two hours (TTL of 7200 seconds). Somehow this manipulation makes the DNS packets too big leading to truncation, triggering this warning.

You can get rid of the warning by adding a config file like `/etc/dnsmasq.d/99-edns.conf` and adding

```auto
edns-packet-max=1280

```

in there. Then run `pihole restartdns` and your Pi-hole will not even try with larger packet sizes (our default is 4096).

---

<div class="post-metadata">

**Author:** ![Scepterus](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/scepterus/32/18912_2.png) [@Scepterus](https://discourse.pi-hole.net/u/Scepterus)\
**Post date:** [December 23, 2021, 8:44am UTC](https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803/10 "2021-12-23T08:44:23Z")

</div>

Great reply, thanks for explaining it. But the 2 hours make some sense, because if I remember correctly from my other bug posts, 2 hours is roughly the TTL of the DNS cache on these systems, no?

And one last question, is me lowering it going to affect anything performance wise?

---

<div class="post-metadata">

**Author:** ![DL6ER](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dl6er/32/281_2.png) [@DL6ER](https://discourse.pi-hole.net/u/DL6ER)\
**Post date:** [December 23, 2021, 9:32am UTC](https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803/11 "2021-12-23T09:32:43Z")

</div>

> [@Scepterus](#):
>
> is me lowering it going to affect anything performance wise?

I don't think so. Some very large DNS replies will not fit into a single packet any more, however, this is likely already not working right now for you triggering exactly this warning. Truncated queries will be retried over TCP.

---

<div class="post-metadata">

**Author:** ![Scepterus](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/scepterus/32/18912_2.png) [@Scepterus](https://discourse.pi-hole.net/u/Scepterus)\
**Post date:** [December 23, 2021, 9:59am UTC](https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803/12 "2021-12-23T09:59:16Z")

</div>

OK, did that, will check later to see if it's solved.

---

<div class="post-metadata">

**Author:** ![cyanide77](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/cyanide77/32/28557_2.png) [@cyanide77](https://discourse.pi-hole.net/u/cyanide77)\
**Post date:** [December 23, 2021, 11:39am UTC](https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803/13 "2021-12-23T11:39:12Z")

</div>

updated my pihole without issues yesterday and had no issues until 2mins ago.., just seen this warning pop up (never seen it before)... doesn't seem to be causing any impacts, sites loading OK etc.  
I deleted the warnings, reloaded the same site again and it didnt happene again

 ![image](https://discourse.pi-hole.net/uploads/default/original/3X/4/b/4bfbe3af8e43a60a2836256bfc6b0cdb9438a31c.png)

---

<div class="post-metadata">

**Author:** ![DL6ER](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dl6er/32/281_2.png) [@DL6ER](https://discourse.pi-hole.net/u/DL6ER)\
**Post date:** [December 23, 2021, 12:12pm UTC](https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803/14 "2021-12-23T12:12:09Z")

</div>

Yeah, these warnings have always been there, we just made them a lot more visible now. Before, you had to dig them out between a lot of other stuff in `/var/log/pihole.log` where they can easily get lost.

---

<div class="post-metadata">

**Author:** ![cyanide77](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/cyanide77/32/28557_2.png) [@cyanide77](https://discourse.pi-hole.net/u/cyanide77)\
**Post date:** [December 23, 2021, 12:39pm UTC](https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803/15 "2021-12-23T12:39:06Z")

</div>

thanks!

---

<div class="post-metadata">

**Author:** ![Scepterus](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/scepterus/32/18912_2.png) [@Scepterus](https://discourse.pi-hole.net/u/Scepterus)\
**Post date:** [December 23, 2021, 4:24pm UTC](https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803/16 "2021-12-23T16:24:21Z")

</div>

It has been a few hours, no more warnings. thanks!

---

<div class="post-metadata">

**Author:** ![DarinMartin](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/d/3e96dc/32.png) [@DarinMartin](https://discourse.pi-hole.net/u/DarinMartin)\
**Post date:** [December 25, 2021, 2:23pm UTC](https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803/17 "2021-12-25T14:23:51Z")

</div>

Just a quick reply. Thanks for the fix. I will say that I'm running 2 recursive BIND servers on my network. One is BIND 9.16 running on FreeBSD 13.0. The other is BIND 9.11 on Rocky Linux 8.5. Only BIND 9.11 is giving this error. Don't know if that makes a difference in your hypothesis. My ISP isn't messing around with the queries. My Router is pfSense 2.5.2.  
The DNSMASQ error comes up immediately after restarting the Pihole process. It started this morning when I did my weekly udpates. The config file fix did stop the warnings though.  
Thanks!

---

<div class="post-metadata">

**Author:** ![DL6ER](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dl6er/32/281_2.png) [@DL6ER](https://discourse.pi-hole.net/u/DL6ER)\
**Post date:** [December 25, 2021, 2:48pm UTC](https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803/18 "2021-12-25T14:48:27Z")

</div>

> [@DarinMartin](#):
>
> Only BIND 9.11 is giving this error.

Yes, this makes me believe it is an `bind` issue. Either due to a misconfiguration (I guess you already ruled that out, though) or due to a bad default value for something you don't have configured at all. This would also make sense as you say that the latter `bind` version doesn't show this - the default value might have been adjusted as they realized this. Maybe the ISP's DNS servers are running the same "bad" `bind` version resulting in this seen by the other users.

---

<div class="post-metadata">

**Author:** ![LIGISTX](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/l/ea5d25/32.png) [@LIGISTX](https://discourse.pi-hole.net/u/LIGISTX)\
**Post date:** [December 27, 2021, 6:58am UTC](https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803/19 "2021-12-27T06:58:26Z")

</div>

I updated recently and looks like I am seeing something similar. Not sure exactly what this means though.

Version:

Docker Tag 2021.12  
Pi-hole [v5.7]  
FTL [v5.12]  
Web Interface [v5.9]

Image of the warnings I am seeing.

 ![image](https://discourse.pi-hole.net/uploads/default/original/3X/3/4/3413832461750ea07aae2d19446af6d475ae0103.png)

I run a pfsense router which is the IP I have masked out, if that info is helpful at all.

---

<div class="post-metadata">

**Author:** ![DL6ER](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dl6er/32/281_2.png) [@DL6ER](https://discourse.pi-hole.net/u/DL6ER)\
**Post date:** [December 27, 2021, 12:42pm UTC](https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803/20 "2021-12-27T12:42:23Z")

</div>

@LIGISTX as I said above, this comes either from a misconfiguration of a component in your network (most likely the DNS server, but it can also be a router) or a bad default. See [DNSMASQ\_WARN reducing DNS packet size - #9 by DL6ER](https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803/9) for a the solution. Note that setting a lower maximum packet size is _ **not** _ a workaround but a proper solution in this case.

---

<div class="post-metadata">

**Author:** ![Razvan\_Constantin](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/razvan_constantin/32/28730_2.png) [@Razvan\_Constantin](https://discourse.pi-hole.net/u/Razvan_Constantin)\
**Post date:** [December 27, 2021, 3:43pm UTC](https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803/21 "2021-12-27T15:43:05Z")

</div>

Not sure about this statement:

> setting a lower maximum packet size is _ **not** _ a workaround but a proper solution in this case

Others have stated that it has an inpact on performance: [https://www.linksysinfo.org/index.php?threads/reducing-dns-packet-size-for-nameserver-127-0-0-1-to-1280.75502/](https://www.linksysinfo.org/index.php?threads/reducing-dns-packet-size-for-nameserver-127-0-0-1-to-1280.75502/)

> it seems to have an impact on the webpages loading response time

As far as I understand, a bigger buffer than 1280 is needed sometimes to avoid truncation, which can lead to retry on tcp and fragmentation.

I am only a user, so please correct me if my conclusion is wrong.

---

<div class="post-metadata">

**Author:** ![DL6ER](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dl6er/32/281_2.png) [@DL6ER](https://discourse.pi-hole.net/u/DL6ER)\
**Post date:** [December 27, 2021, 8:48pm UTC](https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803/22 "2021-12-27T20:48:44Z")

</div>

I said _ **in this case** _ because it seems that larger packets cannot make it anyway to their target and have to be retired with smaller packets even over UDP. The performance is much worse as the second UDP attempt is only made when we never receive a reply from upstream due to a packet that never reached its target (due to size). In contrast to TCP, we don't get status information about UDP transmissions and cannot know if a packet reached its target _at all_.

Hence, when you see this warning, it means that you have hit at least one timeout on UDP already. If the packet has to be retransmitted over TCP, that's an altogether different question and comes even thereafter.

TL;DR: The situation is worse with too large packets. Reduces packet size will make everything faster due to not having to retry after a timeout.

[Next page](https://discourse.pi-hole.net/t/dnsmasq-warn-reducing-dns-packet-size/51803.md?page=2)
