In this blog post I will describe the easiest installation of a DoH/DoT VM for personal Try DNS Leak Test to verify that your local ISP is NOT your firefox DNS.

We support DNSCrypt, DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT) protocols. What is DNSCrypt? Instead of a regular client-server interaction protocol, AdGuard DNS allows you to use a specific encrypted protocol — DNSCrypt. Thanks to it, all DNS requests are being encrypted, which protects you from possible request interception and subsequent eavesdropping and/or alteration. What are DoH … offers a simple test to determine if you DNS requests are being leaked which may represent a critical privacy threat. The test takes only a few seconds and we show you how you can simply fix the problem.

Additionally I have also blocked DNS over TLS (DoT) by dropping port 853. However, the one I'm having difficulty with is DNS over HTTPS (DoH). I have read in a few places the only way to stop DoH is to block the IP's at port 443 (SSL). With this in mind I have made an entire list of public DNS over HTTPS servers such as Google, Adguard and Cloudflare. I have put the IP's into an ipset and