Hello @specterzz,
thanks for your help. Unfortunately I have to say that it doesn't work for me.
When I comment "proxy_bind $remote_addr transparent;" DoT works great but with localhost in log.
When I uncomment there is no dns resolve entry in pihole log. I think I have a firewall / route problem.
troubleshoot
root@DNS:~# ip6tables -t mangle -S
-P PREROUTING ACCEPT
-P INPUT ACCEPT
-P FORWARD ACCEPT
-P OUTPUT ACCEPT
-P POSTROUTING ACCEPT
-A OUTPUT -p tcp -m tcp --sport 53 -j MARK --set-xmark 0x7/0xffffffff
root@DNS:~# iptables -t mangle -S
-P PREROUTING ACCEPT
-P INPUT ACCEPT
-P FORWARD ACCEPT
-P OUTPUT ACCEPT
-P POSTROUTING ACCEPT
-A OUTPUT -p tcp -m tcp --sport 53 -j MARK --set-xmark 0x7/0xffffffff
netstat -tulpane
tcp 0 0 0.0.0.0:443 0.0.0.0:* LISTEN 0 45182636 3581/nginx: master
tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN 0 45182638 3581/nginx: master
tcp 0 0 0.0.0.0:853 0.0.0.0:* LISTEN 0 45182634 3581/nginx: master
tcp 0 0 0.0.0.0:53 0.0.0.0:* LISTEN 998 45085420 18695/pihole-FTL
tcp 0 0 127.0.0.1:8053 0.0.0.0:* LISTEN 64707 21903662 23544/stubby
tcpdump
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on any, link-type LINUX_SLL (Linux cooked), capture size 262144 bytes
14:55:45.882545 IP external-clientr-IP.30567 > external-server-IP.853: Flags [S], seq 2939463429, win 65535, options [mss 1400,sackOK,TS val 1129368 ecr 0,nop,wscale 9,tfo cookiereq,nop,nop], length 0
14:55:45.882712 IP external-server-IP.853 > external-clientr-IP.30567: Flags [S.], seq 3817759696, ack 2939463430, win 28960, options [mss 1460,sackOK,TS val 950262223 ecr 1129368,nop,wscale 7], length 0
14:55:45.970164 IP external-clientr-IP.30567 > external-server-IP.853: Flags [.], ack 1, win 172, options [nop,nop,TS val 1129387 ecr 950262223], length 0
14:55:45.970470 IP external-clientr-IP.30567 > external-server-IP.853: Flags [P.], seq 1:518, ack 1, win 172, options [nop,nop,TS val 1129387 ecr 950262223], length 517
14:55:45.970514 IP external-server-IP.853 > external-clientr-IP.30567: Flags [.], ack 518, win 235, options [nop,nop,TS val 950262311 ecr 1129387], length 0
14:55:45.984321 IP external-server-IP.853 > external-clientr-IP.30567: Flags [.], seq 1:2777, ack 518, win 235, options [nop,nop,TS val 950262325 ecr 1129387], length 2776
14:55:45.984363 IP external-server-IP.853 > external-clientr-IP.30567: Flags [P.], seq 2777:3456, ack 518, win 235, options [nop,nop,TS val 950262325 ecr 1129387], length 679
14:55:46.012121 IP external-clientr-IP.30567 > external-server-IP.853: Flags [.], ack 1389, win 177, options [nop,nop,TS val 1129392 ecr 950262325], length 0
14:55:46.019810 IP external-clientr-IP.30567 > external-server-IP.853: Flags [.], ack 2777, win 182, options [nop,nop,TS val 1129393 ecr 950262325], length 0
14:55:46.034546 IP external-clientr-IP.30567 > external-server-IP.853: Flags [.], ack 3456, win 188, options [nop,nop,TS val 1129393 ecr 950262325], length 0
14:55:46.037556 IP external-clientr-IP.30567 > external-server-IP.853: Flags [P.], seq 518:611, ack 3456, win 188, options [nop,nop,TS val 1129393 ecr 950262325], length 93
14:55:46.037934 IP external-server-IP.853 > external-clientr-IP.30567: Flags [P.], seq 3456:3714, ack 611, win 235, options [nop,nop,TS val 950262379 ecr 1129393], length 258
14:55:46.038113 IP external-server-IP.853 > external-clientr-IP.30567: Flags [P.], seq 3714:3745, ack 611, win 235, options [nop,nop,TS val 950262379 ecr 1129393], length 31
14:55:46.038149 IP external-server-IP.853 > external-clientr-IP.30567: Flags [F.], seq 3745, ack 611, win 235, options [nop,nop,TS val 950262379 ecr 1129393], length 0
14:55:46.077625 IP external-clientr-IP.30567 > external-server-IP.853: Flags [P.], seq 611:1088, ack 3714, win 193, options [nop,nop,TS val 1129397 ecr 950262379], length 477
14:55:46.077686 IP external-server-IP.853 > external-clientr-IP.30567: Flags [R], seq 3817763410, win 0, length 0
14:55:46.080911 IP external-clientr-IP.30567 > external-server-IP.853: Flags [FP.], seq 1088:1119, ack 3746, win 193, options [nop,nop,TS val 1129399 ecr 950262379], length 31
14:55:46.080954 IP external-server-IP.853 > external-clientr-IP.30567: Flags [R], seq 3817763442, win 0, length 0
14:55:46.082974 IP external-clientr-IP.15785 > external-server-IP.853: Flags [S], seq 3777039265, win 65535, options [mss 1400,sackOK,TS val 1129399 ecr 0,nop,wscale 9,tfo cookiereq,nop,nop], length 0
14:55:46.083047 IP external-server-IP.853 > external-clientr-IP.15785: Flags [S.], seq 4194415647, ack 3777039266, win 28960, options [mss 1460,sackOK,TS val 950262424 ecr 1129399,nop,wscale 7], length 0