Wireshark, DNS Over HTTPS, and NextDNS

asked 2023-08-17 13:00:10 +0000

Patrick Dark

updated 2023-08-17 13:26:35 +0000

Is there any way to get Wireshark to make direct DNS lookups using DNS Over HTTPS (DOH)? If not, is there any plan to support this? This seems like a strange omission for a major network security tool.

I can configure browsers like Firefox to do this with a Trusted Recursive Resolver (TRR) URL like[NextDNS ID for macOS Device]/Firefox/ in about:config so that DNS lookups are listed as coming from not only my macOS device, but Firefox on that device specifically, but there doesn’t seem to be any way to do this in Wireshark or to even have it use DNS Over HTTPS at all unless it’s using the default OS resolver.

answered 2023-08-17 13:24:32 +0000

grahamb

Wireshark isn't really a network security tool, it's a packet inspection tool, and as such I would expect folks using it would like to see the contents of DNS requests and responses without having to configure decryption (if at all possible).

Name resolution by Wireshark itself can be disabled by configuration.

An enhancement request can be raised at the Wireshark GitLab instance.

Make sure to mention to change from c-ares to unbound.

Jaap ( 2023-08-17 15:24:40 +0000 )

Asked: 2023-08-17 13:00:10 +0000

Last updated: Aug 17 '23