could anyone chime in as to why my local DNS queries appear to be answered by these two IP-addresses? A quick search revealed that they seem to be related to DNSwatch, which I've never selected. All outbound DNS traffic (to port 53 and 853) except to one DNS resolver is blocked by a router firewall rule and DoH as well as DoT Servers are blocked by a blacklist.
I've configured a VPN service as my DNS resolver that is unrelated to DNSwatch. Pihole has been working great, ads are blocked and a DNS leak test confirms my VPN provider as sole DNS service.

Any help is greatly appreciated. cheers!


    How are you identifying this?
    Firewall logs or ????
    And for the record, what Fireware version are you running?

    james.carsonjames.carson Moderator, WatchGuard Representative

    @Bruce_Briggs I don't believe this was a legitimate issue due to all of this user's posts having spam links in them.

    The user has been removed.

    -James Carson
    WatchGuard Customer Support

