• DynamoSunshirtSandals@possumpat.io
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 days ago

    I do exactly this as well. Works great! Dynamic DNS is kind of a hilarious hack.

    Quick question: since I use wireguard, do I need to use DNS-over-HTTPS for security? My assumption is that my entire session is already encrypted with my wireguard keys, so it doesn’t matter. But I figured I should double check.

    • mac@lemm.ee
      link
      fedilink
      English
      arrow-up
      1
      ·
      13 days ago

      Depends, do you have pihole/unbound setup to only recursively resolve? Or do you forward requests to an upstream (either as a fallback or just as a primary). If that’s the case, and depending on your threat model, you’ll want to set up DoH or DoT as your DNS requests will be forwarded in plaintext