Empty domain on Top Permitted Domains

Hi,

Expected Behaviour:

Display the domain

Actual Behaviour:

Empty domain hit 794 times in top permitted domains

Debug Token:

iv1lqq36un

I see a query for . in your log, but I don't see any error.
What is the output of these commands?

grep 'query\[.*\]  from' /var/log/pihole.log
grep 'query\[.*\] \. from' /var/log/pihole.log

Aug 20 21:35:03 dnsmasq[21366]: 2470 192.168.1.9/50728 query[A] . from 192.168.1.9
Aug 20 21:35:03 dnsmasq[21366]: 2471 192.168.1.9/50728 query[AAAA] . from 192.168.1.9

It seems a query from my Jeedom box strange. I still don't know what it means but thanks for the commands.

Did you get any output from the first command?

Yes from the second one and a lot of output ^^ :

Aug 24 12:50:03 dnsmasq[14623]: 31979 192.168.1.9/46196 query[AAAA] . from 192.168.1.9
Aug 24 12:55:02 dnsmasq[14623]: 32351 192.168.1.9/34312 query[A] . from 192.168.1.9
Aug 24 12:55:02 dnsmasq[14623]: 32352 192.168.1.9/34312 query[AAAA] . from 192.168.1.9
Aug 24 13:00:04 dnsmasq[14623]: 32770 192.168.1.9/54901 query[A] . from 192.168.1.9
Aug 24 13:00:04 dnsmasq[14623]: 32771 192.168.1.9/54901 query[AAAA] . from 192.168.1.9
Aug 24 13:04:15 dnsmasq[14623]: 33096 192.168.1.9/49587 query[A] . from 192.168.1.9
Aug 24 13:04:15 dnsmasq[14623]: 33097 192.168.1.9/49587 query[AAAA] . from 192.168.1.9
Aug 24 13:05:02 dnsmasq[14623]: 33156 192.168.1.9/57552 query[A] . from 192.168.1.9
Aug 24 13:05:02 dnsmasq[14623]: 33157 192.168.1.9/57552 query[AAAA] . from 192.168.1.9
Aug 24 13:10:02 dnsmasq[14623]: 33540 192.168.1.9/36735 query[A] . from 192.168.1.9
Aug 24 13:10:02 dnsmasq[14623]: 33541 192.168.1.9/36735 query[AAAA] . from 192.168.1.9
Aug 24 13:15:03 dnsmasq[14623]: 33651 192.168.1.9/36759 query[A] . from 192.168.1.9
Aug 24 13:15:03 dnsmasq[14623]: 33652 192.168.1.9/36759 query[AAAA] . from 192.168.1.9
Aug 24 13:20:02 dnsmasq[14623]: 33731 192.168.1.9/43030 query[A] . from 192.168.1.9
Aug 24 13:20:02 dnsmasq[14623]: 33732 192.168.1.9/43030 query[AAAA] . from 192.168.1.9
Aug 24 13:21:23 dnsmasq[14623]: 33753 192.168.1.9/38316 query[A] . from 192.168.1.9
Aug 24 13:21:23 dnsmasq[14623]: 33754 192.168.1.9/38316 query[AAAA] . from 192.168.1.9
Aug 24 13:25:03 dnsmasq[14623]: 33857 192.168.1.9/36403 query[A] . from 192.168.1.9
Aug 24 13:25:03 dnsmasq[14623]: 33858 192.168.1.9/36403 query[AAAA] . from 192.168.1.9
Aug 24 13:30:03 dnsmasq[14623]: 34011 192.168.1.9/33325 query[A] . from 192.168.1.9
Aug 24 13:30:03 dnsmasq[14623]: 34012 192.168.1.9/33325 query[AAAA] . from 192.168.1.9
Aug 24 13:34:10 dnsmasq[14623]: 34104 192.168.1.9/57016 query[A] . from 192.168.1.9
Aug 24 13:34:10 dnsmasq[14623]: 34105 192.168.1.9/57016 query[AAAA] . from 192.168.1.9
Aug 24 13:35:03 dnsmasq[14623]: 34123 192.168.1.9/55262 query[A] . from 192.168.1.9
Aug 24 13:35:03 dnsmasq[14623]: 34124 192.168.1.9/55262 query[AAAA] . from 192.168.1.9
Aug 24 13:40:03 dnsmasq[14623]: 34201 192.168.1.9/53268 query[A] . from 192.168.1.9
Aug 24 13:40:03 dnsmasq[14623]: 34202 192.168.1.9/53268 query[AAAA] . from 192.168.1.9
Aug 24 13:45:02 dnsmasq[14623]: 34312 192.168.1.9/51298 query[A] . from 192.168.1.9
Aug 24 13:45:02 dnsmasq[14623]: 34313 192.168.1.9/51298 query[AAAA] . from 192.168.1.9
Aug 24 13:49:06 dnsmasq[14623]: 34418 192.168.1.9/43581 query[A] . from 192.168.1.9
Aug 24 13:49:06 dnsmasq[14623]: 34419 192.168.1.9/43581 query[AAAA] . from 192.168.1.9
Aug 24 13:50:02 dnsmasq[14623]: 34452 192.168.1.9/55971 query[A] . from 192.168.1.9
Aug 24 13:50:02 dnsmasq[14623]: 34453 192.168.1.9/55971 query[AAAA] . from 192.168.1.9
Aug 24 13:55:02 dnsmasq[14623]: 34652 192.168.1.9/38995 query[A] . from 192.168.1.9
Aug 24 13:55:02 dnsmasq[14623]: 34653 192.168.1.9/38995 query[AAAA] . from 192.168.1.9
Aug 24 14:00:03 dnsmasq[14623]: 34885 192.168.1.9/53957 query[A] . from 192.168.1.9
Aug 24 14:00:03 dnsmasq[14623]: 34886 192.168.1.9/53957 query[AAAA] . from 192.168.1.9
Aug 24 14:04:10 dnsmasq[14623]: 35103 192.168.1.9/41810 query[A] . from 192.168.1.9
Aug 24 14:04:10 dnsmasq[14623]: 35104 192.168.1.9/41810 query[AAAA] . from 192.168.1.9
Aug 24 14:05:02 dnsmasq[14623]: 35125 192.168.1.9/42722 query[A] . from 192.168.1.9
Aug 24 14:05:02 dnsmasq[14623]: 35126 192.168.1.9/42722 query[AAAA] . from 192.168.1.9
Aug 24 14:10:02 dnsmasq[14623]: 35281 192.168.1.9/46071 query[A] . from 192.168.1.9
Aug 24 14:10:02 dnsmasq[14623]: 35282 192.168.1.9/46071 query[AAAA] . from 192.168.1.9
Aug 24 14:15:03 dnsmasq[14623]: 35422 192.168.1.9/59526 query[A] . from 192.168.1.9
Aug 24 14:15:03 dnsmasq[14623]: 35423 192.168.1.9/59526 query[AAAA] . from 192.168.1.9
Aug 24 14:19:42 dnsmasq[14623]: 35599 192.168.1.9/39964 query[A] . from 192.168.1.9
Aug 24 14:19:42 dnsmasq[14623]: 35600 192.168.1.9/39964 query[AAAA] . from 192.168.1.9
Aug 24 14:20:03 dnsmasq[14623]: 35609 192.168.1.9/39055 query[A] . from 192.168.1.9
Aug 24 14:20:03 dnsmasq[14623]: 35610 192.168.1.9/39055 query[AAAA] . from 192.168.1.9
Aug 24 14:25:03 dnsmasq[14623]: 35723 192.168.1.9/36294 query[A] . from 192.168.1.9
Aug 24 14:25:03 dnsmasq[14623]: 35724 192.168.1.9/36294 query[AAAA] . from 192.168.1.9
Aug 24 14:30:03 dnsmasq[14623]: 35975 192.168.1.9/45317 query[A] . from 192.168.1.9
Aug 24 14:30:03 dnsmasq[14623]: 35976 192.168.1.9/45317 query[AAAA] . from 192.168.1.9
Aug 24 14:34:04 dnsmasq[14623]: 36773 192.168.1.9/59624 query[A] . from 192.168.1.9
Aug 24 14:34:04 dnsmasq[14623]: 36774 192.168.1.9/59624 query[AAAA] . from 192.168.1.9
Aug 24 14:35:03 dnsmasq[14623]: 36851 192.168.1.9/58609 query[A] . from 192.168.1.9
Aug 24 14:35:03 dnsmasq[14623]: 36852 192.168.1.9/58609 query[AAAA] . from 192.168.1.9

Okay, so there is a client requesting the domain . quite frequently. This is not a Pi-hole issue. However, what is a Pi-hole issue is that Pi-hole shows an empty domain (instead of .) as Top Lists entry.

Tracing this through FTLDNS, I see that an incoming query . is processed as an empty name:

dnsmasq: 68913 192.168.2.209/46702 query[A] . from 192.168.2.209
[2018-08-24 16:32:58.914] **** new UDP query[A] "" from 192.168.2.209 (ID 68913)

It is just a cosmetic issue and nothing to worry about.

2 Likes

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.