# IPv6 stuff - is this normal?

**URL:** https://discourse.pi-hole.net/t/ipv6-stuff-is-this-normal/38158
**Category:** General
**Created:** [September 8, 2020, 10:31pm UTC](https://discourse.pi-hole.net/t/ipv6-stuff-is-this-normal/38158 "2020-09-08T22:31:28Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![shykitten55](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/shykitten55/32/18504_2.png) [@shykitten55](https://discourse.pi-hole.net/u/shykitten55)
#### Post date: [September 8, 2020, 10:31pm UTC](https://discourse.pi-hole.net/t/ipv6-stuff-is-this-normal/38158/1 "2020-09-08T22:31:29Z")

</div>

This is when looking at the dashboard.

I have some blacklists set up and all is going along nicely.

But then I see this:

 ![Screenshot from 2020-09-09 08-24-15](https://discourse.pi-hole.net/uploads/default/original/3X/4/b/4b11b260207dfb066251d6e2d1b55d8947e3c6e2.png)

(I saw the reference to another thread, but it was closed and wasn't helpful.)

That is a lot of IPv6 traffic. And considering all my stuff is IPv4......  
Is this _normal_ to see?  
(though: what is normal?)

---

<div class="post-metadata">

### Author: ![yubiuser](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/yubiuser/32/12100_2.png) [@yubiuser](https://discourse.pi-hole.net/u/yubiuser)
#### Post date: [September 9, 2020, 5:00am UTC](https://discourse.pi-hole.net/t/ipv6-stuff-is-this-normal/38158/2 "2020-09-09T05:00:08Z")

</div>

Yes, it **can** be normal. Some of your devices requested specifically an `AAAA` DNS record (which can be send and received over IPv4 and IPv6), not knowing that they might be unable to connect to the (IPv6) address returned in the `AAAA` record.

For my IPv4 only network i get ~20% of `AAAA` requests.

---

<div class="post-metadata">

### Author: ![shykitten55](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/shykitten55/32/18504_2.png) [@shykitten55](https://discourse.pi-hole.net/u/shykitten55)
#### Post date: [September 9, 2020, 8:46am UTC](https://discourse.pi-hole.net/t/ipv6-stuff-is-this-normal/38158/3 "2020-09-09T08:46:44Z")

</div>

Thanks.

To the best of my knowledge I have IPv6 disabled on all devices - including the router/modem.

---

<div class="post-metadata">

### Author: ![Coro](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/coro/32/15424_2.png) [@Coro](https://discourse.pi-hole.net/u/Coro)
#### Post date: [September 9, 2020, 9:31am UTC](https://discourse.pi-hole.net/t/ipv6-stuff-is-this-normal/38158/4 "2020-09-09T09:31:09Z")

</div>

It is entirely expected. The IPv6 Internet has a lot of benefits and, accordingly, the Internet standards mandate to prefer IPv6 over IPv4 is both are available. When you clients don't have IPv6 connectivity, they shouldn't ask for IPv6 records. However, the vast majority of clients is not intelligent enough so they always ask for both.

> [@yubiuser](#):
>
> For my IPv4 only network i get ~20% of `AAAA` requests.

I find this unusual. Are your queries dominated by internal names or by special applications which do `A`-only requests? On the normal "browsing", I'd almost always expect a 1:1 share between `A` and `AAAA`.

---

<div class="post-metadata">

### Author: ![yubiuser](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/yubiuser/32/12100_2.png) [@yubiuser](https://discourse.pi-hole.net/u/yubiuser)
#### Post date: [September 10, 2020, 4:52am UTC](https://discourse.pi-hole.net/t/ipv6-stuff-is-this-normal/38158/5 "2020-09-10T04:52:29Z")

</div>

> [@Coro](#):
>
> Are your queries dominated by internal names or by special applications which do `A` -only requests?

It's the [chromecasts pushing teh `AAAA` up](https://discourse.pi-hole.net/t/option-to-block-not-forward-all-aaaa-queries/34837/3). Without I'm around 6%.
