hope that you can help me. I am using my Raspberry Pi 4 as a pi-hole and DNS resolver. Pi-hole works great, by itself works great too but I would like to get the whole nine yards and use DNSSEC and Secure DNS with it too.

DNSSEC is working but it looks Iike I cannot get Secure DNS to work, as the test always shows You may not be using secure DNS.

I have Cloudflare running on of my Raspberry on port 5053, the DNS resolver gets forwarded from 53 to 5053 for the proxy set-up according to cloudflared (DoH) - Pi-hole documentation and test done on Safari on MacOS Big Sur:

dig @ -p 5053

; <<>> DiG 9.11.5-P4-5.1+deb10u3-Raspbian <<>> @ -p 5053
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 49075
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

; EDNS: version: 0, flags:; udp: 4096
; IN A


;; Query time: 13 msec
;; WHEN: Tue Mar 23 18:55:35 CET 2021
;; MSG SIZE rcvd: 65#

curl -H ‘accept: application/dns-json’ '


