# Why won't Pi-hole work with DNS rebind protection enabled?

**URL:** <https://discourse.pi-hole.net/t/why-wont-pi-hole-work-with-dns-rebind-protection-enabled/3142>\
**Category:** FAQs\
**Created:** [May 14, 2017, 4:08am UTC](https://discourse.pi-hole.net/t/why-wont-pi-hole-work-with-dns-rebind-protection-enabled/3142 "2017-05-14T04:08:37Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![jacob.salmela](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jacob.salmela/32/8_2.png) [@jacob.salmela](https://discourse.pi-hole.net/u/jacob.salmela)\
**Post date:** [May 14, 2017, 4:08am UTC](https://discourse.pi-hole.net/t/why-wont-pi-hole-work-with-dns-rebind-protection-enabled/3142/1 "2017-05-14T04:08:38Z")

</div>

# What is DNS rebind protection?

If your router has an option called _DNS rebind protection_ enabled, you may run into issues when trying to use Pi-hole as your DNS server. The reasons for this are quite technical, but to summarize what this option does in one sentence:

> **DNS rebind protection does not allow DNS queries to be answered with a local IP address**.

# Why does this interfere with Pi-hole?

DNS rebind is meant to be a [countermeasure to an attack on your network](http://www.techrepublic.com/blog/it-security/public-ip-dns-rebinding-another-reason-not-to-use-default-passwords/). So in many cases, it's actually [a good thing](https://discourse.pi-hole.net/t/solved-dd-wrt-dns-issue/2669/6) by preventing your DNS queries from being compromised by not allowing DNS queries to be handled by a server with a [non-routable (private) IP address](https://tools.ietf.org/html/rfc1918#section-3). But in the case of Pi-hole, it's set up on _your private network_ (but not in every case) so _you_ are in control of _your own_ private DNS server.

 ![](https://discourse.pi-hole.net/uploads/default/original/3X/5/3/53cb25bbaa4a46bb1164039cf961b731d6f199f2.png)

Knowing that, DNS rebind protection is a **direct contradiction** to [how Pi-hole functions](https://discourse.pi-hole.net/t/how-does-pi-hole-work/3141) to block ads for your entire network. Pi-hole is a _local_ (a.k.a. private) DNS server as opposed to using a **public** one [like Google's](https://developers.google.com/speed/public-dns/docs/using).

With rebind protection enabled, your router thinks Pi-hole is something malicious since it is acting as a DNS server within the private IP address space. You may see something like this in your log files:

```auto
Sun Apr 30 15:30:08 2017 daemon.warn dnsmasq[3408]: possible DNS-rebind attack detected: pi.hole

```

But notice how is says _possible_ attack detected. Private DNS servers are not uncommon and perfectly legitimate, which is also why you can enable and disable rebind protection.

# Specific problems and examples of DNS rebind protection interfering with Pi-hole's operation

## OpenWRT

You can [disable it](https://github.com/pi-hole/pi-hole/issues/292#issuecomment-181795918) in [/etc/config/dhcp](https://wiki.openwrt.org/doc/uci/dhcp) by setting this to `0`:

```auto
option rebind_protection 0

```

## DD-WRT

DD-WRT has a [similar option you can set](https://github.com/pi-hole/pi-hole/issues/292#issuecomment-186124004) for specific domains:

```auto
rebind-domain-ok=/plex.direct/
rebind-domain-ok=/pi.hole/

```

## Fritz!Box

[Several users](https://github.com/pi-hole/pi-hole/issues/1271#issuecomment-282295061) have [run into issues](https://github.com/pi-hole/pi-hole/issues/1271#issuecomment-282295061) with these model routers as it's often [enabled by default](https://en.avm.de/service/fritzbox/fritzbox-7390/knowledge-base/publication/show/663_No-DNS-resolution-of-private-IP-addresses/). In addition, it has been reported that the option for DNS rebind isn't even available until a [certain version of firmware](https://github.com/pi-hole/pi-hole/issues/292#issuecomment-269061197) is installed.

# I'm still having trouble resolving domains after disabling rebind protection

You are likely running into caching issues. [Flush your cache](https://discourse.pi-hole.net/t/how-do-i-flush-my-pi-hole-cache/3020) and try again.

## What else can I do if nothing else works?

Pi-hole now ships with a built in DHCP server. You can disable DHCP on your router and use Pi-hole to handle DHCP (and DNS).

 ![](https://discourse.pi-hole.net/uploads/default/original/3X/a/8/a83179d02abbddab799b0ab1e00da9eda80d1dbb.png)

* * *

> _This FAQ attempts to condense and clarifies the data dump found [here](https://github.com/pi-hole/pi-hole/issues/292) as well as other forums and posts across pi-hole.net._
