4

DNS leak test showing USA cloudflare addresses instead of local NextDNS?

Hi there, I have been using the service for about a week now and have been enjoying the local fast queries and speeds. When I first got my service up and running I had 2 local dns servers powered by nextdns. Now when I am testing for dns leaks I am seeing entries for Cloudflare addresses back to USA - 172.70.37.108

Being in Aus this creates a noticable difference going from <10ms to ~330ms ping response times. Is this a cause of a setting ticked under the performance section in the settings? Again just seeking some clarity about what is causing this. Thanks.

Edit: I have just performed another leak test, no neither NextDNS servers are showing and am getting multiple Cloudflare addresses. I run a PiHole setup and force all traffic through it using the 2x servers provided under my https://my.nextdns.io/ page.

119 replies

null
    • losnad
    • 3 yrs ago
    • Reported - view

    I think that this service is used by hundreds of thousands of people and the few that have problems with it are thinking that the service is broken, it doesn't work. Isn't it funny?
    Maybe some are expecting NextDNS to come to their house and fix it for them.

    They are offering instructions, apps, tools, recommendations... If you want to go your way, you should own it, you should know what you are doing.

      • NextDNs
      • 3 yrs ago
      • Reported - view

      Myth0ne none of those settings and nothing on NextDNS server side could explain those leaks. A DNS leak is a client side issue.

      • Myth0ne
      • 3 yrs ago
      • Reported - view

      NextDNS Thanks running DoH seems to be looking pretty good about now. So do I lose the EDNS functionality and other browsing speed performance tweaks if my queries are over 300k for the month?

      • NextDNs
      • 3 yrs ago
      • Reported - view

      Myth0ne when over 300k your configuration is no longer used. It is like using NextDNS with no configuration : 0 filtering, 0 logging, no EDNS, no CNAME folding and so on. It is like running unbound with default settings sort of.

      • Myth0ne
      • 3 yrs ago
      • Reported - view

      NextDNS Great to know!
      One last thing, even going into my config and going back to past 30 days, even 3 months says I only used ~120k queries although I have a message saying I have surpassed 250k queries and nearing the limit?

       

      Also have set up DOH as explained. Says only about 93% of queries are DOH. Is there a way to also see what request perhaps are not using DOH? Cheers!

      • NextDNs
      • 3 yrs ago
      • Reported - view

      Myth0ne the number of queries is in your account (upper right) and it includes all the configurations of your account. There are no ways for now to filter logs per protocol.

      • Pro subscriber ✓
      • DynamicNotSlow
      • 3 yrs ago
      • Reported - view

      Myth0ne scroll 2 Posts up. 
       

      „when over 300k your configuration is no longer used. It is like using NextDNS with no configuration : 0 filtering, 0 logging, no EDNS, no CNAME folding and so on. It is like running unbound with default settings sort of.“

      • Myth0ne
      • 3 yrs ago
      • Reported - view

      DynamicNotSlow Didn't know if EDNS and ECS were the same or not. Thanks for verifying.

      • NextDNs
      • 3 yrs ago
      • Reported - view

      Myth0ne EDNS0 defines a DNS record (OPT) used to help designing extensions for the DNS protocol. ECS is one of those extensions, it stands for EDNS0 Client Subnet. DNSSEC is another example of extension partially relying on EDNS0.

    • cameron_bell
    • 3 yrs ago
    • Reported - view

    I'm facing the same issue.

    I have run tests on 3 different computers, all the results showed Ashburn Cloudflare as DNS provider.

    Just let you know, I always block outgoing 53 port .

    This is really weird, isn't it?  Why do I get the same Ashburn results as  @myth0ne

    • yellow_carriage
    • 3 yrs ago
    • Reported - view

    The same thing happens to me when using NextDNS DoT on my router. Every once in a while it just hits cloudflare. But most of the time it doesn't. I am also using this on an ASUS router with Merlin firmware.

    • yellow_carriage
    • 3 yrs ago
    • Reported - view
    "status": "ok",
    "protocol": "DOT",
    "destIP": "45.90.28.247",
    "anycast": true,
    "server": "vultr-lax-1",
    "clientName": "unknown-dot"
    
    • Luci_Morn
    • 3 yrs ago
    • Reported - view

     

    I also got the Ashburn result. Perhaps this issue is on @dnsleaktest side.

    client: apple-profile

      • losnad
      • 3 yrs ago
      • Reported - view

      You also got Ashburn but yours is from

      - 208.69.32.0 - 208.69.39.255
      City Ashburn ISP Cisco OpenDNS, LLC

      The others are from

      - 172.64.0.0 - 172.71.255.255
      City Ashburn ISP Cloudflare, Inc.

      Dnsleaktest.com is
      23.239.16.110
      Hostname li685-110.members.linode.com

      23.239.0.0 - 23.239.31.255
      City Atlanta ISP Linode, LLC

      It's interesting how people from different places get Ashburn like it's some kind of center of the internet.

      Maybe might be a better option to try https://browserleaks.com/dns
      It has many more useful tools.

    • nbxas
    • 3 yrs ago
    • Reported - view

    Same problem. Android on 4g with private dns is giving me leaks. Tried different apps, all showing the same. 

    I have paid account.

    test.nextdns.io returned

    {
    "status": "ok",
    "protocol": "DOT",
    "configuration": "fpef9e64ccdabf8a56",
    "client": "82.132.230.210",
    "destIP": "209.250.226.191",
    "anycast": false,
    "server": "vultr-lon-1",
    "clientName": "unknown-dot"
    }
      • nbxas
      • 3 yrs ago
      • Reported - view

      juliank if you mean Block Bypass Methods, then it is turned on

      • nbxas
      • 3 yrs ago
      • Reported - view

      nbxas I've tried using cloudflare as private dns for phone, then only one cloudflare server comes up on dnsleak test. As soon as switch to nextdns as private dns, multiple dns servers appears on dnsleak. Mainly Cisco Opendns, and sometimes even Google dns appears. It looks like this is something to do with NextDNS

    • Ruby_Balloon
    • 3 yrs ago
    • Reported - view

    Most of these leaks posted are showing different countries, Are most in this thread using a vpn? 

    • NextDNs
    • 3 yrs ago
    • Reported - view

    For everybody in this thread reproducing the issue, could you please try with another DNS leak test service than dnsleaktest.com and report on if you can reproduce the issue or not?

    The fact all leaks to different DNS providers are located in ashburn is highly suspicious and suggests a bug on dnsleaktest.com itself. The reason why it would only happen with us is a mystery though.

    • yellow_carriage
    • 3 yrs ago
    • Reported - view

    I don’t currently have NextDNS setup on my router anymore as it was causing issues for someone else’s device in the house. But, I will say browserleaks also showed odd behavior. It showed about a dozen google dns addresses as well as Cloudflare. I’ve never seen this happen with any other DNS. I don’t actually know what to make of these results as this shouldn’t be possible. Just wanted to report the odd results.

      • NextDNs
      • 3 yrs ago
      • Reported - view

      NA if possible, could you please share a screenshot and provide details about your setup?

    • Shadow_Colossus
    • 3 yrs ago
    • Reported - view

    I came here to say that the same thing happens on https://browserleaks.com/dns (My IPv6 is disabled and I followed the entire tutorial step by step, but this problem happens even with everything ok.):

    • Ruby_Balloon
    • 3 yrs ago
    • Reported - view

    very odd, I do random ping & dnsleak tests but never had a problem using http://dnsleaktest.com/

    • Chris.6
    • 3 yrs ago
    • Reported - view

    I'm seeing similar “leaks“. 

    I use Safari on Big Sur (latest) with the NextDNS app.

    I haven't seen this behavior on https://dnsleaktest.com, but sometimes on https://browserleaks.com/ip, and always on https://www.dns-oarc.net/oarc/services/dnsentropy.

    Those other IPs from the DNS Oarc page are from Cloudflare somehow. 

    Test:

    "status": "ok",
    "protocol": "DOH",

    … … … "anycast": false, … … … … …

    • Chris.6
    • 3 yrs ago
    • Reported - view

    And for https://cmdns.dev.dns-oarc.net, I get a C result (while getting an A without NextDNS enabled).

Content aside

  • 4 Likes
  • 3 yrs agoLast active
  • 119Replies
  • 6271Views
  • 17 Following