use DNS with DoT (dns over tls) or DoH (dns over https)
This is critical because the most people use a DNS with their own ISP.
The DNS can leak their true location.
Your vpn solution is not complete without DNS encryption.
And please don't forget Linux not just Windows, Apple or Google.
Thanks
-
Sergii Novosad commented
It's critical without a doubt. Not only does it limit us to primarily public DNS resolvers, it also limits us to only have unencrypted traffic, unless we use netshield. You can either implement DoT and DoH, or let us use system DNS (I refer to windows custom DNS, android custom dns config, iPhone .mobileconfig file, etc. ) I have to tear myself between using proton VPN and AdGuard DNS that supports DOH and DOT, but instead I have to use their public DNS, which is not bad, but I miss out on all logging for my DNS and precise ad blockers that I select myself, instead of AdGuard.) That is just an example of it being used with your vpn, but instead we have to rely on public ipv4 that doesn't provide the authentication that we need to truly stay anonymous online. Using your netshield shouldn't be the only option to secure our DNS traffic.
-
Elucidor Bramwell
commented
Wow, this feature request has not been implemented for 2 years now. This should be implemented already.
-
DOS SANTOS
commented
on windows, that doesn’t allow a DoT for VPN , I have to use yogaDNS to get over this problem.
-
Keith Austin commented
DoH or DoT support would be very helpful for those of us that want to use Proton for the VPN and a separate provider for DNS. Right now I can't use ControlD in combination with ProtonVPN without turning on legacy support in ControlD. This is unencrypted DNS and is more vulnerable. However, I want to have very fine control over my DNS requests. This is the only thing I am really, really missing from Proton!
-
Leeprzy
commented
DNS Queries Must have end to end encryption using dot or doh. I'm currently using protonvpn because its dns and vpn endpoints are in Switzerland. that's huge because the 14 eyes act. but I'm still concerned my data can be man in the middle attacked and be seen by someone.
wont dot or doh solve this? providing end to end encryption to your authorities dns servers? anyways your doing better then anyone else out there cant wait for doh or dot for fullproof privacy and security. Thanks -
Notme
commented
I think this would also make sense for users who use proton VPN on their router and would like to use a locally hosted DNS server like adguard or Pi hole with DoT or DoH for the upstreams.
Currently this isn't an option and leads to DNS leaks -
COSYOS
commented
ProtonVPN's DNS is used, so the ISP's DNS is not used. However, it makes sense to be able to specify DoT or DoH (services of other companies such as NextDNS or AdguardDNS).
-
ohoh
commented
If people use a DNS with their own ISP and ProtonVPN they will just use Proton's DNS as soon as they use the VPN and that doesn't leak, since all traffic is protected.
It is a different story when you set a custom DNS server for ProtonVPN and the DNS traffic is forwarded to that custom DNS server. Here DoH or DoT would have to be used to avoid a leak, but tbh. even that DNS leak should just point to your VPN location (not an expert though, so not sure).