Insecure notation re: dns

Please follow the below template, it will help us to help you!

Expected Behaviour:

pihole to show secure

Actual Behaviour:

phiole showing insecure for sites that have dnssec setup.

What does it mean "insecure" when a user has ticked on Use DNSSEC?

I'm noticing log entries that state "insecure" when I'm going to sites that I would figure would have DNSSEC setup like google, microsoft, etc.

gdfg

Debug Token:

[Replace this text with the debug token provided from running pihole -d (or running the debug script through the web interface]

There is an entry in the FAQ

That's a good question and I'm also interested in feedback.

1 Like

@jeffschips There are multiple possibilities, but to answer accurately, I need to get some more info:

  • which version of dnsmasq do you use (or do you use FTLDNS?)?
  • which upstream resolvers do you use?
  • does the DNSSEC test on the settings page give a positive result for you (I guess yes)?

Having said that, I just put pop.gmail.com into the DNSSEC validator and found out that they don't have it set up properly! If you have more specific domains, I'd be happy to analyze them with you as well.

Screenshot%20at%202018-04-04%2018-46-34
Screenshot%20at%202018-04-04%2018-55-11

Visit https://posteo.de and have a look at the Query Log, they have DNSSEC enabled. Or https://mailbox.org.

I was just about to suggest trying verisignlabs.com, but posteo.de is fine as well.

@mibere Excellent choice for the mail provider, they host my private mail as well :wink:

Yes it replies as secure. Now what? I guess that means dnssec is working on my end and the reason places like google and microsft show insecure is because they haven't tweaked their settings?

when I visit dns.watch pi shows insecure.

Most companies, even the big ones, don't use DNSSEC.

Thank you for your quick response.

How do I find out which version of dnsmasq I'm using (even if I'm using) and if I'm using ftldns instead?

The dnssec resolver test show secure for the http://dnssec.vs.uni-due.de/ check.

The systems settings page in the admin console says I'm using FTL Version 3.0

You should be able to query the version of your current DNS resolver using

dig chaos txt version.bind +short

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.