This site will have limited functionality while we undergo maintenance to improve your experience. If an article doesn't solve your issue and you want to ask a question, we have our support community waiting to help you at @FirefoxSupport on Twitter and/r/firefox on Reddit.

Search Support

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More

DNS over HTTPS stopped working (along with eSNI), in Chrome - it works fine

  • 12 replies
  • 1 has this problem
  • 24 views
  • Last reply by Owyn

more options

Tried with google dns too - same result, on cloudflare forum I discovered it was a browser problem cuz with Chrome DNS over HTTPS works just fine - see screens

thread on cloudflare: https://community.cloudflare.com/t/help-me-debug-fix-dns-pass-security-check-test-in-firefox-sdns-esni-issue/161822/

Tried with google dns too - same result, on cloudflare forum I discovered it was a browser problem cuz with Chrome DNS over HTTPS works just fine - see screens thread on cloudflare: https://community.cloudflare.com/t/help-me-debug-fix-dns-pass-security-check-test-in-firefox-sdns-esni-issue/161822/
Attached screenshots

All Replies (12)

more options

I'm green across the board, here (w/ESNI)

Double-check your configuration.

more options

RobertJ said

I'm green across the board, here (w/ESNI) Double-check your configuration.

Any suggestions on how should I double-check my clean profile configuration?

more options

Enter about:config in the address bar and press enter select "Accept the Risk and Continue" in the search bar at the top enter network.trr.mode double-click on the line and set the value to 2 then, enter network.security.esni.enabled in the search bar double-click on the line to set the value to True

Restart Firefox.

Check your Test again.

more options

Just a little bit of research will tell you that ESNI only works with sites that are participating with Cloudflare in the ESNI project.

more options

RobertJ said

Enter about:config in the address bar and press enter select "Accept the Risk and Continue" in the search bar at the top enter network.trr.mode double-click on the line and set the value to 2 then, enter network.security.esni.enabled in the search bar double-click on the line to set the value to True Restart Firefox. Check your Test again.

Those settings are already set that way, just checked. - same result - sDNS and eSNI aren't shown working by the test in Firefox (in chrome sDNS is shown working fine)

Just a little bit of research will tell you that ESNI only works with sites that are participating with Cloudflare in the ESNI project.
Pretty sure the site which is supposed to check whenever eSNI works or not - supports eSNI
more options

You might have an extension which is interfering with DoH and/or ESNI.

Disable any extensions that could be suspect and restart Firefox. Then, try your Cloudflare Test again.

more options

RobertJ said

You might have an extension which is interfering with DoH and/or ESNI. Disable any extensions that could be suspect and restart Firefox. Then, try your Cloudflare Test again.

There aren't any extensions on the clean profile I created for the test.

and the internet cable is connected directly to the PC without any kind of routers

Modified by Owyn

more options

Go to: 3-bar Menu button -> Options -> General page scroll all the way down to the bottom click on the Network Settings - Settings button and in the Connection settings window check that Use Provider is set to Cloudflare (Default)

more options

RobertJ said

Go to: 3-bar Menu button -> Options -> General page scroll all the way down to the bottom click on the Network Settings - Settings button and in the Connection settings window check that Use Provider is set to Cloudflare (Default)

Yes, it's set that way.

more options

Owyn, I'm out of ideas. I'll ask for help and maybe someone else can help, also.

more options

You can create a new profile as a quick test to see if your current profile is causing the problem.

See "Creating a profile":

If the new profile works then you can transfer files from a previously used profile to the new profile, but be cautious not to copy corrupted files to avoid carrying over problems.


Boot the computer in Windows Safe mode with network support to see if that has effect in case security software is causing problems.

more options

Yes, I was testing it all out with a clean profile

And apparently now Windows 10 safe mode with networking doesn't support... networking:

so I can't test it that way

I have no security software running (or loaded) or even any network filters like WinDivert, only windows firewall (because it's a required component for internet sharing (with my notebook) to work)

but isn't it weird if something is preventing sDNS (and eSNI) from working on my Firefox but not on my Chrome (sDNS is shown working fine there after I enable it there), is it implemented differently in browsers? can it even be implemented differently hmm?

Modified by Owyn