Hello,
I'm quite new in DoT, DoH but familiar with DNS in general.
I setup my personal DoT, mostly to get a proper filtering (AdBlock) without root on phone.
I've only one Graphene OS on my setup for now, Pixel8a. After setup DoT (Nginx + pihole + unbound) I configured the phone to use it and it works well. This setup is not the main DNS resolver of my local domain. It can't resolve internal/LAN hosts.
After some time, got random messages about loss of connectivity, which is untrue, connectivity is functional.
I quickly read Graphene doco about those checks, understood about the DNS check, and I can see them in logs.
However I also found some like this one below.
<rdm_string>-dnsotls-ds.dnscheck.grapheneos.org.MY.DOMAIN.COM (not in caps, just to highlight)
Phone is connected on Wifi, part of 'MY.DOMAIN.COM'. But the dot is accessible, and used from public internet.
Someone could explain me why this DNS request contain my local domain ? Maybe something is wrong in my setup...
Any idea about those message of loss of connectivity ? When it happens, I can see those DNS request in logs. With 'other' graphene dns request .
<rdm_string>-dnsotls-ds.dnscheck.grapheneos.org
FYI I'm quite far from Graphene's DNS servers, and un-cached requests can take up to 800ms
Cheers,