# iCloud Private Relay

**URL:** <https://discourse.pi-hole.net/t/icloud-private-relay/49811>\
**Category:** Help\
**Created:** [September 21, 2021, 7:57am UTC](https://discourse.pi-hole.net/t/icloud-private-relay/49811 "2021-09-21T07:57:19Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![jpgpi250](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jpgpi250/32/286_2.png) [@jpgpi250](https://discourse.pi-hole.net/u/jpgpi250)\
**Post date:** [September 21, 2021, 9:10am UTC](https://discourse.pi-hole.net/t/icloud-private-relay/49811/4 "2021-09-21T09:10:57Z")

</div>

I just have been reading [this](https://matduggan.com/how-does-apple-private-relay-work/) and [this](https://developer.apple.com/support/prepare-your-network-for-icloud-private-relay) article.

It looks like you can inform the apple device NOT to use the private relay by creating 2 specific DNS entries for the domains

```auto
mask.icloud.com
mask-h2.icloud.com

```

I currently don't have a MAC available to test this, but if somebody is willing to test this...

create a file /etc/dnsmasq.d/xx-NXDOMAIN.conf, (replace xx with an unused number), content:

```auto
server=/mask.icloud.com/
server=/mask-h2.icloud.com/

```

and restart pihole-FTL (sudo service pihole-FTL restart)  
This will ensure the reply to dig mask.icloud.com is NXDOMAIN. According to the earlier mentioned docs, this dig is used to find geografically localized relay addresses, if there are no addresses in the reply, the apple device will not use any relays (feature disabled).

Again, I haven't been able to test this, so any feedback would be usefull.

---

_[View the full topic](https://discourse.pi-hole.net/t/icloud-private-relay/49811)._
