|
|
|
|
|
by ignoramous
505 days ago
|
|
> The most that a network administrator can do to prevent this is configure firewall IP blocklists of known DoH servers ... A firewall (which must also host a resolver) can choose to block requests to IPs it hasn't resolved domain names for. This is something I implemented for an Android firewall app I co-develop; it works nicely enough. |
|