Skip to content

Enable DoT & DoH

With TLS enabled, dnsdist-acme gets a certificate from Let’s Encrypt, renews it automatically, and serves DNS-over-TLS on port 853 and DNS-over-HTTPS on port 443. The query logs page is also served over HTTPS on port 8443.

  • The server has a public IP address.
  • A domain name, such as dns1.example.com, with an A record (and AAAA for IPv6) pointing at it.
  • Port 80 reachable from the internet. Let’s Encrypt validates the certificate over HTTP on port 80 only.
  • Ports 443 and 853 reachable for DoH and DoT.
  1. Edit EXAMPLES/default/.env:

    .env
    TLS_ENABLED=true
    TLS_DOMAIN=dns1.example.com
    TLS_EMAIL=you@example.com
  2. Restart:

    Terminal window
    ./start.sh
  3. Watch the certificate being issued:

    Terminal window
    docker compose logs -f dnsdist
  4. Test it with dig (BIND 9.18 or newer):

    Terminal window
    dig +tls @dns1.example.com zedo.com # DNS-over-TLS
    dig +https @dns1.example.com zedo.com # DNS-over-HTTPS

    Both should answer 0.0.0.0.

    Or set it as the Private DNS hostname on an Android phone. See Android.

TLS_ENABLED is only for dnsdist-acme. The Compose file forces it off for the dns container, which must not request its own certificate.