Problem with Beta 5.0:
I've seen cases where even though a domain is explicitly on my whitelist, I see in the query log and on my devices when they try to access said domain that it is blocked due to deep CNAME inspection. The example I'll give is of "steamcdn-a.akamaihd.net". This domain was under a exact whitelist entry for the past 24 hours (i.e. from my understanding, for all the times in the screenshot, it should have been allowed, despite linking to a blocked CNAME). This doesn't even happen 100% of the time - sometimes the domain will be allowed and then a little while later it will be blocked again, as shown in the screenshot.
If I run "pihole restartdns" the domains seem to be correctly allowed for a little while.
Log snippet from allowed:
/var/log/pihole.log
11953 Jan 26 07:57:46 dnsmasq[765]: query[A] steamcdn-a.akamaihd.net from 192.168.1.10
11954 Jan 26 07:57:46 dnsmasq[765]: forwarded steamcdn-a.akamaihd.net to 127.0.0.1
11955 Jan 26 07:57:46 dnsmasq[765]: reply steamcdn-a.akamaihd.net is <CNAME>
11956 Jan 26 07:57:46 dnsmasq[765]: reply steamcdn-a.akamaihd.net.edgesuite.net is <CNAME>
11957 Jan 26 07:57:46 dnsmasq[765]: reply a1843.g1.akamai.net is 23.200.236.194
11958 Jan 26 07:57:46 dnsmasq[765]: reply a1843.g1.akamai.net is 23.200.236.201
Log snippet from (erroneously) blocked:
/var/log/pihole.log
13897 Jan 26 09:00:30 dnsmasq[765]: query[A] steamcdn-a.akamaihd.net from 192.168.1.10
13898 Jan 26 09:00:30 dnsmasq[765]: forwarded steamcdn-a.akamaihd.net to 127.0.0.1
13899 Jan 26 09:00:30 dnsmasq[765]: reply steamcdn-a.akamaihd.net is <CNAME>
13900 Jan 26 09:00:30 dnsmasq[765]: reply steamcdn-a.akamaihd.net.edgesuite.net is <CNAME>
/var/log/pihole-FTL.log (I think this part may be relevant?)
222 [2020-01-26 09:00:08.095 765] Regex blacklist (ID 98) ".*\.g[0-9]+\..*" matches "a1843.g1.akamai.net"
Debug Token:
https://tricorder.pi-hole.net/rhwdkd8wzn