Skip to content

Disable DNS over TLS for NordVPN compatibility#48

Draft
Copilot wants to merge 2 commits intomainfrom
copilot/fix-47
Draft

Disable DNS over TLS for NordVPN compatibility#48
Copilot wants to merge 2 commits intomainfrom
copilot/fix-47

Conversation

Copy link

Copilot AI commented Sep 19, 2025

DNS over TLS (DoT) in the Cloudflare for Families configuration is incompatible with NordVPN, causing name resolution failures when the VPN is active. This change disables DoT while maintaining DNS filtering protection.

Changes Made

  • Changed DNSOverTLS=yes to DNSOverTLS=no in the systemd-resolved configuration
  • Updated changelog with security rationale and threat model assessment

Impact

This change ensures reliable DNS resolution when using NordVPN while preserving the security benefits:

  • Maintains DNS Filtering: Cloudflare for Families DNS servers (1.1.1.3/1.0.0.3) continue to provide malware and adult content blocking
  • Ensures VPN Compatibility: Name resolution works properly when NordVPN is connected
  • Preserves Security: Users still benefit from NordVPN's threat protection and encrypted DNS through the VPN tunnel

The trade-off is acceptable since the DNS encryption is handled by NordVPN when connected, and the filtering protection remains active.

Fixes #47.


💬 Share your feedback on Copilot coding agent for the chance to win a $200 gift card! Click here to start the survey.

Copy link
Author

Copilot AI commented Sep 19, 2025

@brabster 👋 This repository doesn't have Copilot instructions. With Copilot instructions, I can understand the repository better, work faster and produce higher quality PRs.

I can generate a .github/copilot-instructions.md file for you automatically. Click here to open a pre-filled issue and assign it to me. I'll write the instructions, and then tag you for review.

Co-authored-by: brabster <38702+brabster@users.noreply.github.com>
Copilot AI changed the title [WIP] Unable to resolve names when using DoT and NordVPN Disable DNS over TLS for NordVPN compatibility Sep 19, 2025
Copilot AI requested a review from brabster September 19, 2025 11:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Unable to resolve names when using DoT and NordVPN

2 participants