diff --git a/app/src/pages/legal/FAQ.tsx b/app/src/pages/legal/FAQ.tsx index cbb70163..a0814f41 100644 --- a/app/src/pages/legal/FAQ.tsx +++ b/app/src/pages/legal/FAQ.tsx @@ -111,7 +111,7 @@ function FAQSection({ title, children, globalToggleSignal, globalToggleState }: ); } -const FAQ_LAST_UPDATED = 'September 9, 2026'; +const FAQ_LAST_UPDATED = 'September 25, 2026'; const CODE_CLASS = "text-[var(--shadcn-ui-app-foreground)] px-2 py-0.5 rounded text-sm font-mono border border-[var(--shadcn-ui-app-border)]"; const TABLE_CELL_CLASS = "border border-[var(--shadcn-ui-app-border)] px-3 py-2 text-left align-top"; @@ -176,11 +176,14 @@ export default function FAQ(): JSX.Element { }; const supportedProtocols = ( - +
+ +

We do not offer unencrypted DNS on port 53. The modDNS address answers encrypted queries only, so it cannot serve as a bootstrap or fallback resolver in AdGuard Home, routers or similar clients; use any plain resolver for that role.

+
); const howToCreateProfile = ( @@ -522,6 +525,30 @@ export default function FAQ(): JSX.Element { ); + const localResolversWithModDNS = ( +
+

Yes, both. Put the local resolver in front of modDNS and let it forward every query it does not answer itself.

+ +

Your profile id is shown on the Setup page. To see the resolver as a named device in your query logs, generate the stamp with a device label (see "Can I generate a per-device DNS Stamp?").

+

Filter in one place only: a domain blocked by AdGuard Home or Pi-hole never reaches modDNS and is missing from your modDNS logs and statistics, so turn off the local blocklists and manage blocking in your modDNS profile.

+
+ ); + + const adGuardHomeCannotResolveUpstream = ( +
+

AdGuard Home looks up the modDNS hostname through its own Bootstrap DNS servers setting, not through your system resolver. By default it asks Quad9. If your network only allows DNS to one resolver, that lookup never gets an answer and Test upstreams reports "couldn't communicate with upstream" with "resolving hostname" in the message, even though the modDNS server is reachable.

+

The most common case is a VPN client with a firewall or kill switch, such as the IVPN app, which only allows DNS to IVPN's own resolver. Two fixes, either one is enough:

+ +

AdGuard Home caches the result of the bootstrap lookup. If a setup that worked stops working after you turn a VPN on, restart AdGuard Home after changing the bootstrap, or switch to a stamp.

+
+ ); + const renderFAQContent = () => (
@@ -784,6 +811,10 @@ export default function FAQ(): JSX.Element { question="Which clients can I use a DNS Stamp with?" answer={dnsStampsCompatibleClients} /> + +