Docs › LAN resolution

dnsmasq on OpenWrt: allow private answers

dnsmasq calls the behaviour rebind protection and takes an allowlist of domains permitted to return private addresses. Version 2.92 added the 100.64.0.0/10 range to the filter, and current OpenWrt ships 2.93, so overlay names that worked on an older release stop working after an upgrade.

Confirm this is the problem

Run both from the machine that cannot resolve the name.

diagnose
dig +short nas.alice.home.network @1.1.1.1
dig +short nas.alice.home.network
ResultMeaning
First returns the address, second returns nothing Your resolver is stripping the answer. Apply the fix below.
Both return nothing The record is missing or wrong. Nothing on the router will help.

Check the status, not only the output. A stripped answer comes back NOERROR with ANSWER: 0, never NXDOMAIN. NXDOMAIN means the record does not exist. Querying @ns1.home.network proves only that the record exists, since it bypasses both resolvers and cannot tell the two cases apart.

The fix

Network ▸ DNS ▸ Filter ▸ Domain whitelist, or the command line
uci add_list dhcp.@dnsmasq[0].rebind_domain='alice.home.network'
uci commit dhcp
service dnsmasq restart
rebind_domain is a list rather than an option, so use add_list and not set. One entry covers RFC 1918 and the overlay range together, because the same check handles both. Matching is on a label boundary, so the parent domain covers everything beneath it and no wildcard exists. A restart is required. In LuCI the field moved: 24.10 has it under Network ▸ DHCP and DNS ▸ Filter, and 25.12 under Network ▸ DNS ▸ Filter.

Substitute your own label for alice. The exception covers every name beneath it, so it is added once rather than per device.

Why this happens

Rebind protection exists to stop a hostile public name resolving to an address inside your network. Pointing your own names at your own machines is the same shape as that attack and cannot be distinguished automatically, so resolvers take an allowlist instead. Naming one domain you control is the narrowest possible exception.

← All documentation