Allow login.live.com to pass through pihole without getting blocked, since it is in the whitelist and not on the blacklist.
Actual Behaviour:
login.live.com is my top blocked domain. I tried to whitelist again from web interface (which I realize is broken, but that is another issue...) as well as the command line. No matter what I try, my devices can't log into live accounts.
Have you whitelisted all of Microsoft's domains? At least for Xbox, they contacted us directly to provide some of the domains that need to be whitelisted. You can find them here:
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;login.live.com. IN A
;; ANSWER SECTION:
login.live.com. 3119 IN CNAME login.msa.akadns6.net.
login.msa.akadns6.net. 125 IN CNAME ipv4.login.msa.akadns6.net.
ipv4.login.msa.akadns6.net. 125 IN A 131.253.61.102
ipv4.login.msa.akadns6.net. 125 IN A 131.253.61.100
ipv4.login.msa.akadns6.net. 125 IN A 131.253.61.98
It seems to be passing login.live.com now, however last night it was being blocked and it still my top blocked domain in the last 24 hours:
Top Blocked Domains
Domain Hits Frequency
login.live.com 3081
device-metrics-us.amazon.com 2659
watson.telemetry.microsoft.com 2413
v10.vortex-win.data.microsoft.com 1796
Jacob, I believe I have all those microsoft domains on my whitelist (as is login.live.com). The issue is that pihole seems to, at times, ignore the whitelist and block it anyway.
Run pihole -d for a new debug token. I was on vacation for awhile, and the rest of the team has also been busy working on getting the next update out the door.
Also run pihole -q login.live.com when it is blocked and not blocked and compare the outputs.