diff --git a/app/src/pages/legal/FAQ.tsx b/app/src/pages/legal/FAQ.tsx index cbb70163..a0814f41 100644 --- a/app/src/pages/legal/FAQ.tsx +++ b/app/src/pages/legal/FAQ.tsx @@ -111,7 +111,7 @@ function FAQSection({ title, children, globalToggleSignal, globalToggleState }: ); } -const FAQ_LAST_UPDATED = 'September 9, 2026'; +const FAQ_LAST_UPDATED = 'September 25, 2026'; const CODE_CLASS = "text-[var(--shadcn-ui-app-foreground)] px-2 py-0.5 rounded text-sm font-mono border border-[var(--shadcn-ui-app-border)]"; const TABLE_CELL_CLASS = "border border-[var(--shadcn-ui-app-border)] px-3 py-2 text-left align-top"; @@ -176,11 +176,14 @@ export default function FAQ(): JSX.Element { }; const supportedProtocols = ( -
We do not offer unencrypted DNS on port 53. The modDNS address answers encrypted queries only, so it cannot serve as a bootstrap or fallback resolver in AdGuard Home, routers or similar clients; use any plain resolver for that role.
+Yes, both. Put the local resolver in front of modDNS and let it forward every query it does not answer itself.
+https://dns.moddns.net/dns-query/<profile id>, tls://<profile id>.dns.moddns.net or quic://<profile id>.dns.moddns.net:853 as an upstream, or paste one of your DNS Stamps. Click Test upstreams to confirm.dnscrypt-proxy next to it. Configure dnscrypt-proxy with your DoH stamp (the ready-made dnscrypt-proxy.toml snippet is on the DNS Stamps tab under Setup) and set Pi-hole's upstream to the address dnscrypt-proxy listens on, for example 127.0.0.1#5053 when listen_addresses in dnscrypt-proxy.toml is 127.0.0.1:5053; the two must match. Pi-hole's guide covers the installation: docs.pi-hole.net/guides/dns/dnscrypt-proxy.Your profile id is shown on the Setup page. To see the resolver as a named device in your query logs, generate the stamp with a device label (see "Can I generate a per-device DNS Stamp?").
+Filter in one place only: a domain blocked by AdGuard Home or Pi-hole never reaches modDNS and is missing from your modDNS logs and statistics, so turn off the local blocklists and manage blocking in your modDNS profile.
+AdGuard Home looks up the modDNS hostname through its own Bootstrap DNS servers setting, not through your system resolver. By default it asks Quad9. If your network only allows DNS to one resolver, that lookup never gets an answer and Test upstreams reports "couldn't communicate with upstream" with "resolving hostname" in the message, even though the modDNS server is reachable.
+The most common case is a VPN client with a firewall or kill switch, such as the IVPN app, which only allows DNS to IVPN's own resolver. Two fixes, either one is enough:
+What is the IP address of your DNS servers?. This only works while the VPN is connected.AdGuard Home caches the result of the bootstrap lookup. If a setup that worked stops working after you turn a VPN on, restart AdGuard Home after changing the bootstrap, or switch to a stamp.
+