Is Charter blocking OpenDNS?

Comments

14 comments

  • Avatar
    rotblitz

    "Can anyone else confirm this?"

    Yes, you by yourself.  Execute the following command:

         nslookup -type=txt which.opendns.com. 208.67.220.220

    and if this comes back with "I am not an OpenDNS resolver", then your ISP redirects your DNS lookups to their own service, else not.

    0
    Comment actions Permalink
  • Avatar
    tuckerdogavl

    When to Utilities>Terminal on my Mac. Cut and paste the above and I get this back:

    Non-authoritative answer:
    which.opendns.com    text = "3.ash"

    Authoritative answers can be found from:

    Mac-mini:~ [computername]

    0
    Comment actions Permalink
  • Avatar
    rotblitz

    Fine, then your DNS queries are not being redirected, and you can use OpenDNS.

    0
    Comment actions Permalink
  • Avatar
    tuckerdogavl

    WIsh I could figure out why Apple Mail and Charter do not play nice. I can get the Charter mail; I just have to close and reopen the app. I"ve had Open DNS up for some time and I've set it thru the Router. Also, I did OpenDNS's check up the other day and the check mark showed. So, I guess I'll continue working on the issue from another angle. Thanks for the update.

    0
    Comment actions Permalink
  • Avatar
    rotblitz

    You may want to check your blocked domains stat to find domain names related to Apple or Charter.  You had to remove the block via category or you had to whitelist them.
    https://dashboard.opendns.com/stats/all/blockeddomains

    0
    Comment actions Permalink
  • Avatar
    guiguy

    OK. I ran the test proposed by rotblitz. And, sure enough, Charter is redirecting. Is there ANY way to get around this and use OpenDNS?

    0
    Comment actions Permalink
  • Avatar
    rotblitz

    You'll have to talk to your ISP.

    0
    Comment actions Permalink
  • Avatar
    guiguy

    I talked to them and they say that I MUST use their DNS. "It's part of the T&C." In other words, they won't do anything to help me. When I asked if this was an impossibility due to policy or technology, the answer was POLICY. I HATE them, but they're the only game in town.

    Again, Is there ANY way to get around this and use OpenDNS?

     

    0
    Comment actions Permalink
  • Avatar
    rotblitz

    Yes, there is possibly a way around.  Try with running that dnscrypt-proxy from http://dnscrypt.org/
    Most redirecting ISPs do not recognize the DNS queries any longer, so they cannot redirect them.

    You can also run a pre-test to possibly see already if the dnscrypt-proxy can help:

       nslookup -type=txt -port=443 which.opendns.com. 208.67.220.220

       nslookup -type=txt -port=443 -vc which.opendns.com. 208.67.220.220

    And even if these return "I am not an OpenDNS resolver", there are still chances that the dnscrypt-proxy does it.

    0
    Comment actions Permalink
  • Avatar
    tuckerdogavl

    Odd. I simply went into my DNS settings (Apple: Open Network Perferences>Advanced>DNS> and added 208.67 etc. Rebooted and then ran the test and got "Yes, you're running OPEN DNS." However, I am running my own Netgear Router and extender, not theirs.

    0
    Comment actions Permalink
  • Avatar
    rotblitz

    Well, then you did something wrong the last time.  And your ISP doesn't redirect your DNS queries either...

    "they say that I MUST use their DNS... the answer was POLICY"

    LOL, this missing expertise is typical for many front-line / first level supports...

    0
    Comment actions Permalink
  • Avatar
    guiguy

    Actually "they say that I MUST use their DNS... the answer was POLICY" was from a SUPERVISOR! I had escalated the call because I never trust first level support.

    Anyway, I ran the above pre-tests and got, respectively "3.sea" and "11.sea" Unfortunately, I have no clue what those responses mean.

    Rotblitz, can you decipher for me? I still want to use OpenDNS, but Charter seems to keep putting their big fat bazoo into the mix.

    0
    Comment actions Permalink
  • Avatar
    maintenance

    This means you are receiving responses from OpenDNS resolvers in the Seattle area. The important bit is that the response isn't "I am not an OpenDNS resolver". :)

    So you may use dnscrypt on computers or on your router if it has installed (or can have installed, and it is something you would care to do) an open source firmware.

     

    0
    Comment actions Permalink
  • Avatar
    rotblitz

    @guiguy
    You even don't need the dnscrypt-proxy, because your ISP does not interfere with your DNS traffic.  I would think you just didn't configure the OpenDNS resolver addresses correctly, or your router has a problem to ignore the configuration.

    Further, reviewing the whole thread again, it is now evident that Charter does not block OpenDNS.  All cases turned out to be false reports.  It was always the user's error, never Charter.

    0
    Comment actions Permalink

Please sign in to leave a comment.