Hacker News new | ask | show | jobs
by jlgaddis 2182 days ago
Actually, in that case, adding the canary domain to your existing Microsoft DNS servers probably IS the most ideal way to disable Firefox's DoH support.

Alternatively, you can roll out a Group Policy or use Mozilla's "Enterprise" policies to do it.

Hopefully you're also blocking 53/TCP and 53/UDP outbound (except from your internal DNS servers).