Skip to content
DnsLister Forum

Where domain hunters compare notes

Why would one block secure DNS on a public Wi-Fi network? UCSFguest Wi-Fi not working, disabling secure DNS resolves the issue.

Why would one block secure DNS on a public Wi-Fi network?

UCSFguest Wi-Fi not working, disabling secure DNS resolves the issue.

That's pretty much it. It seems they are blocking it, across multiple/all? sites. I wonder why. UCSFguest is a large enterprise public Wi-Fi network at dozens of large sites in San Francisco.

I tried switching between secure DNS providers and none worked.

Secure DNS (DNS-over-HTTPS) is enabled by default in major browsers including Google Chrome, Mozilla Firefox, and Brave.

I got some good answers at https://www.reddit.com/r/networking/comments/1vz7j9u but then they decided to lock the thread and hide the OP. (I'd say it is not OT, as UCSFguest is a large enterprise public Wi-Fi network, but not interested in arguing with the mods.)

Diagnostics:

curl -v -H 'accept: application/dns-json' 'https://cloudflare-dns.com' 

output:

* Host cloudflare-dns.com:443 was resolved.

* IPv6: (none)

* IPv4: 104.16.248.249, 104.16.249.249

* Trying 104.16.248.249:443...

* Connected to cloudflare-dns.com (104.16.248.249) port 443

* ALPN: curl offers h2,http/1.1

* (304) (OUT), TLS handshake, Client hello (1):

* CAfile: /etc/ssl/cert.pem

* CApath: none

* Recv failure: Connection reset by peer

* LibreSSL/3.3.6: error:02FFF036:system library:func(4095):Connection reset by peer

* Closing connection

curl: (35) Recv failure: Connection reset by peer

curl -v -H 'accept: application/dns-json' 'https://dns.google'

* Host dns.google:443 was resolved.

* IPv6: (none)

* IPv4: 8.8.8.8, 8.8.4.4

* Trying 8.8.8.8:443...

* Connected to dns.google (8.8.8.8) port 443

* ALPN: curl offers h2,http/1.1

* (304) (OUT), TLS handshake, Client hello (1):

* CAfile: /etc/ssl/cert.pem

* CApath: none

* Recv failure: Connection reset by peer

* LibreSSL/3.3.6: error:02FFF036:system library:func(4095):Connection reset by peer

* Closing connection

curl: (35) Recv failure: Connection reset by peer

Also:

wget -S --spider https://cloudflare-dns.com/dns-query

Spider mode enabled. Check if remote file exists.

--2026-08-26 12:38:55-- https://cloudflare-dns.com/dns-query

Resolving cloudflare-dns.com (cloudflare-dns.com)... 104.16.248.249, 104.16.249.249

Connecting to cloudflare-dns.com (cloudflare-dns.com)|104.16.248.249|:443... connected.

Unable to establish SSL connection.

Source: r/techsupport · by /u/MrElvey

Leave a Reply

Your email address will not be published. Required fields are marked *