Skip to content

iOS encrypted DNS guide: iCloud Private Relay & Little Snitch notes appear incorrect/outdated #14

@MineGene

Description

@MineGene

Referenced Document

When using iCloud Private Relay, most VPN clients, or Little Snitch, it will not utilize/respect this DNS profile.

Summary

The section titled "VPNs, iCloud Private Relay, Little Snitch” appears to contain two issues specific to iOS:

  1. The statement about iCloud Private Relay not respecting DNS profiles is inaccurate when custom encrypted DNS (DoH / DoT) is used
  2. Little Snitch is mentioned in an iOS‑only guide, but Little Snitch is not available on iOS

iCloud Private Relay clarification

The document currently states:

“Apple private relay will use its own DNS servers at the system level, with no way to override it.”

However, Apple’s own iCloud Private Relay Overview documentation states:

If a user has configured custom‑encrypted DNS settings using a profile or an app, the DNS server specified will be used instead of ODoH.

Source (Apple):
https://www.apple.com/privacy/docs/iCloud_Private_Relay_Overview_Dec2021.PDF
(“Custom DNS settings” section)

Based on Apple’s documentation:

  • Encrypted DNS (DoH / DoT) configured via profile or app is respected by iCloud Private Relay
  • Unencrypted DNS (manual Wi‑Fi DNS / DHCP DNS) is not used for iCloud Private Relay traffic

Little Snitch mention

The heading and warning include Little Snitch, however:

  • Little Snitch does not exist on iOS

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions