I decided that all my DoT traffic should happen over a commercial WireGuard double-hop VPN on my home router, so that not only can the ISP not see my DNS queries, they can’t even see which resolver I’m using.
For my personal end devices using Tailscale and various VPN tunnels I found another Swiss-hosted DNS resolver and added it to my Blocky configuration. Blocky was suffering because one of my resolver’s servers wasn’t working so I learned to configure Blocky to be more resilient.
Just two small things this week: