0

DNS-over-TLS fails: TCP/853 connects but TLS handshake times out on Android 11

DNS-over-TLS does not work on my Android 11 device. My NextDNS profile hostname is f4eaae.dns.nextdns.io.

When connecting to NextDNS on TCP port 853, the TCP connection succeeds, but the TLS handshake does not complete and eventually times out. The same behavior occurs with Google Public DNS (8.8.8.8 and 8.8.4.4) and Cloudflare (1.1.1.1), so the issue does not appear to be specific to NextDNS.

For example, 8.8.8.8:853 returns CONNECTED with OpenSSL, but no ServerHello or certificate is received. kdig +tls also reports that the TLS peer takes too long to respond.

Normal HTTPS works correctly. TLS 1.3 connections to dns.google and cloudflare.com on port 443 succeed normally.

On Android 11, enabling Private DNS with f4eaae.dns.nextdns.io causes DNS resolution to fail and Android reports that the Private DNS server cannot be reached. When Private DNS is disabled, DNS and Internet access work normally.

The issue occurs on both Wi-Fi and mobile data. Interestingly, DNS-over-TLS worked when I first started using the ISP, but the problem appeared later.

Could you please check whether there is anything on the NextDNS side, such as routing, endpoint selection, or network-related issues, that could explain the TLS handshake timeout on TCP/853?

2 replies

null
    • Mirli
    • 18 hrs ago
    • Reported - view

     

    • NextDNs
    • 3 hrs ago
    • Reported - view

    Please provide a https://nextdns.io/diag

Content aside

  • 3 hrs agoLast active
  • 2Replies
  • 5Views
  • 2 Following