Hostnames visible in parental controls with DNS over TLS

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Hostnames visible in parental controls with DNS over TLS

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Hostnames visible in parental controls with DNS over TLS
Hostnames visible in parental controls with DNS over TLS
2024-11-28 17:30:33 - last edited 2024-12-19 10:02:02
Model: Archer C6  
Hardware Version: V3
Firmware Version: 1.0.16 Build 20230828 rel.44667

I have configured DOT by android secure DNS feature. But I can still see every hostname in my Archer C6 router parental controls. How this is possible? Is router using reverse DNS or something like that?

  0      
  0      
#1
Options
1 Accepted Solution
Re:Hostnames visible in parental controls with DNS over TLS-Solution
2024-12-02 09:26:58 - last edited 2024-12-19 10:02:02

Hi  @ZainUlAbdin ,

DNS resolution is encrypted, and normally the router cannot see the records. If there are records, it means that Android's DNS encryption is not in place. You may need to check the settings on Android and consult technical support to confirm the correct steps for the settings.

Nice to Meet You in Our TP-Link Community. Check Out the Latest Posts: △Pre-release Firmware for Archer AX50 Introduces New Parental Control Features and Enhancements △Introducing AI QoS: Elevate Your Gaming Experience on the Archer GE800 Gaming Router △Connect TP-Link Archer BE550 to Germany's DS-Lite (Dual Stack Lite) Internet via WAN △Tether KidShield Test Recruitment - Safeguarding Children's Online Experience If you found the post or response helpful, please click Helpful. If an answer solves your problem, click "Recommended Solution" so that others can benefit from it.
Recommended Solution
  2  
  2  
#4
Options
3 Reply
Re:Hostnames visible in parental controls with DNS over TLS
2024-11-29 09:50:27

  Hi@ZainUlAbdin 

 

The router does not obtain the device name through DNS. DoT DNS query is mainly for LAN query. In addition, DoT is set on the router instead of the device, so the situation you mentioned is normal.

If you have other feedback, please feel free to contact us.

Nice to Meet You in Our TP-Link Community. Check Out the Latest Posts: △Pre-release Firmware for Archer AX50 Introduces New Parental Control Features and Enhancements △Introducing AI QoS: Elevate Your Gaming Experience on the Archer GE800 Gaming Router △Connect TP-Link Archer BE550 to Germany's DS-Lite (Dual Stack Lite) Internet via WAN △Tether KidShield Test Recruitment - Safeguarding Children's Online Experience If you found the post or response helpful, please click Helpful. If an answer solves your problem, click "Recommended Solution" so that others can benefit from it.
  0  
  0  
#2
Options
Re:Hostnames visible in parental controls with DNS over TLS
2024-11-29 10:05:22

Hi  @Joseph-TP 

 

Thanks for the reply. To clarify my question, the router does not have DOT/DOH. the phone is resolving DNS queries using the android Private DNS feature (using DOT). My question is, if the phone is resolving DNS queries, then how is the router's parental control feature showing me every URL that i am visiting? Because DNS queries are encrypted and the router is not resolving them. Router should only know the IP addresses, but still, the router knows every URL.

  0  
  0  
#3
Options
Re:Hostnames visible in parental controls with DNS over TLS-Solution
2024-12-02 09:26:58 - last edited 2024-12-19 10:02:02

Hi  @ZainUlAbdin ,

DNS resolution is encrypted, and normally the router cannot see the records. If there are records, it means that Android's DNS encryption is not in place. You may need to check the settings on Android and consult technical support to confirm the correct steps for the settings.

Nice to Meet You in Our TP-Link Community. Check Out the Latest Posts: △Pre-release Firmware for Archer AX50 Introduces New Parental Control Features and Enhancements △Introducing AI QoS: Elevate Your Gaming Experience on the Archer GE800 Gaming Router △Connect TP-Link Archer BE550 to Germany's DS-Lite (Dual Stack Lite) Internet via WAN △Tether KidShield Test Recruitment - Safeguarding Children's Online Experience If you found the post or response helpful, please click Helpful. If an answer solves your problem, click "Recommended Solution" so that others can benefit from it.
Recommended Solution
  2  
  2  
#4
Options