I have Cloudflare WARP set up purely as a DNS-over-TLS resolver in macOS, and I’m confused by some of the network traffic it is producing.
I’ve been able to intercept and examine some of it using an HTTPS proxy, but most of it seems to avoid proxies entirely. Little Snitch still catches it, however. I don’t want to let that traffic through without knowing what it is for, especially since it is intended to run constantly.
Here are my questions:
- Are there specific IP addresses I should expect Cloudflare WARP to use for DoT?
- Why does it sometimes send traffic using unencrypted DNS, despite claiming to be using DoT for every logged query?
- Why does it make HTTPS connections to the following hostnames?
If you wanted to preempt questions like this, you could implement support for Little Snitch’s Internet Access Policy: it’s basically a machine-readable list of network traffic, complete with explanations and issues that can occur if you block it.
Little Snitch is quite popular among security-minded macOS users, but that’s hardly a massive audience: I wouldn’t blame you for choosing not to add a file to your app just for that. ↩︎
That is, TCP over port 853. ↩︎
That is, UDP over port 53. ↩︎
That is, TCP over port 443. ↩︎
I’m fairly sure this one is for checking whether the API key being used has WARP+, but I might as well get confirmation while I’m asking. ↩︎