DNS connections and caching
DoH and DoT verify server certificates. Requests are distributed across servers by weight and retried on failure. Responses are cached for their TTL; clear the cache in Settings.
Mudfish servers and proxies
The legacy Mudfish UDP/TCP protocols are also supported, without server authentication. A SOCKS5 proxy can be used for DoH, DoT, TCP DNS and web connections, but cannot be combined with UDP upstreams.
Web protection coverage
On Windows/Linux, web protection splits HTTP Host and HTTPS TLS SNI data on TCP ports 80/443. It does not cover HTTP/3, QUIC or domains inside ECH. Results depend on the network; reopen existing connections after applying settings.
DNS protection coverage
Requests may use plaintext if you explicitly allow plaintext DNS servers or exclude domains on Windows/Linux. Already encrypted DNS requests, such as an app's own DoH, are not intercepted.