Enable DoT & DoH
With TLS enabled, dnsdist-acme gets a certificate from Let’s Encrypt, renews it automatically, and serves DNS-over-TLS on port 853 and DNS-over-HTTPS on port 443. The query logs page is also served over HTTPS on port 8443.
Requirements
Section titled “Requirements”- The server has a public IP address.
- A domain name, such as
dns1.example.com, with anArecord (andAAAAfor IPv6) pointing at it. - Port 80 reachable from the internet. Let’s Encrypt validates the certificate over HTTP on port 80 only.
- Ports 443 and 853 reachable for DoH and DoT.
Turn it on
Section titled “Turn it on”-
Edit
EXAMPLES/default/.env:.env TLS_ENABLED=trueTLS_DOMAIN=dns1.example.comTLS_EMAIL=you@example.com -
Restart:
Terminal window ./start.sh -
Watch the certificate being issued:
Terminal window docker compose logs -f dnsdist -
Test it with
dig(BIND 9.18 or newer):Terminal window dig +tls @dns1.example.com zedo.com # DNS-over-TLSdig +https @dns1.example.com zedo.com # DNS-over-HTTPSBoth should answer
0.0.0.0.Or set it as the Private DNS hostname on an Android phone. See Android.
TLS_ENABLED is only for dnsdist-acme. The Compose file forces it off for the
dns container, which must not request its own certificate.