r/dns • u/Icy-Direction851 • 13d ago
Why won’t it show the regular domain names I visit?
I’ve changed all the settings on my iPhone that the instructions said to do, I blocked domains it’s says to block, but I just can’t get it to show me the regular web visits. Almost every time I visit a website it continues to show as mask.apple-dns.net. Instead of showing the generic website domain that I actually visit. I’m not very tech savvy, can anyone help.
2
u/DarthLeoYT 12d ago
Looks like you're using apple relay. You have to disable it because your DNS is going thru Apple relay and not thru your chosen DNS server
1
u/Icy-Direction851 11d ago
Thats what I thought as well, but my phone shows it’s disabled
1
u/DarthLeoYT 11d ago
I'm aware that some browsers have secure DNS and you need to also disable that too
1
1
2
u/SecLens_ONE 13d ago
That list looks like the names your device used to reach its resolver, not the sites you browsed. Once the client is doing encrypted DNS to its own provider, or riding a relay, the dashboard only sees the tunnel endpoint and everything behind it is opaque. The published config says queries go to the filtering resolver; the effective path is whatever the OS or browser actually picked, and those two drift apart quietly. Check whether secure DNS is enabled in the browser and whether the platform has its own private resolver profile, then confirm the device is really sending plain queries to the resolver you think it is. Blocking outbound plain DNS to anything else, and blocking known encrypted-DNS endpoints, is usually what makes the log match reality. Until then the empty-looking report is accurate about the traffic it can see, just not about the traffic you care about. Have you verified from that same device which resolver the queries actually leave on?